Veeam kayıtları
veeam üreticisine ait 78 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 4 · %5,1
- Silahlaştırılmış
- 6 · %7,7
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %19,2
- Yayından KEV’e ortanca
- 218 gün
Tekrar eden sınıflar
- CWE-502 Deserialization of Untrusted Data7
- CWE-94 Improper Control of Generation of Code ('Code Injection')7
- CWE-284 Improper Access Control6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor6
- CWE-306 Missing Authentication for Critical Function5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
78 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
96Hemen | CVE-2024-40711Silahlaştırılmış | A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).veeam · veeam backup \& replication · CWE-502 | Kritik9,8 | KEV | %90,4 | 7 Eyl 2024 |
84Hemen | CVE-2023-27532Silahlaştırılmış | Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained.veeam · veeam backup \& replication · CWE-306 | Yüksek7,5 | KEV | %81,3 | 10 Mar 2023 |
70Bu hafta | CVE-2022-26501Silahlaştırılmış | Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).veeam · veeam backup \& replication · CWE-306 | Kritik9,8 | KEV | %4,1 | 17 Mar 2022 |
67Bu hafta | CVE-2022-26500Silahlaştırılmış | Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to inteveeam · veeam backup \& replication · CWE-22 | Yüksek8,8 | KEV | %5,8 | 17 Mar 2022 |
65Bu hafta | CVE-2020-10915Silahlaştırılmış | This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587.veeam · one · CWE-502 | Kritik9,8 | — | %86,6 | 22 Nis 2020 |
53Planlayın | CVE-2020-10914Silahlaştırılmış | This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587.veeam · one · CWE-502 | Kritik9,8 | — | %47,9 | 22 Nis 2020 |
51Planlayın | CVE-2024-29849Kavram kanıtı | Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.veeam · veeam backup \& replication · CWE-287 | Kritik9,8 | — | %38,4 | 22 May 2024 |
48Planlayın | CVE-2020-15419İstismar yok | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415.veeam · one firmware · CWE-611 | Yüksek7,5 | — | %59,8 | 28 Tem 2020 |
45Planlayın | CVE-2023-38547İstismar yok | A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access itsveeam · one · CWE-200 | Kritik9,8 | — | %18,9 | 7 Kas 2023 |
42Planlayın | CVE-2025-23121İstismar yok | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain userveeam · veeam backup \& replication · CWE-94 | Yüksek8,8 | — | %24,2 | 18 Haz 2025 |
42Planlayın | CVE-2025-23120İstismar yok | A vulnerability allowing remote code execution (RCE) for domain users.veeam · veeam backup \& replication · CWE-502 | Yüksek8,8 | — | %24,0 | 20 Mar 2025 |
42Planlayın | CVE-2024-29855Kavram kanıtı | Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestratorveeam · recovery orchestrator · CWE-798 | Kritik9,0 | — | %21,6 | 11 Haz 2024 |
39İzleyin | CVE-2024-29212İstismar yok | Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agveeam · veeam service provider console · CWE-502 | Kritik9,9 | — | %1,6 | 14 May 2024 |
39İzleyin | CVE-2021-35971İstismar yok | Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserialization during Microsoft veeam · veeam backup \& replication · CWE-502 | Kritik9,8 | — | %1,2 | 30 Haz 2021 |
39İzleyin | CVE-2024-39714İstismar yok | A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to remote code execution veeam · veeam service provider console · CWE-94 | Kritik9,9 | — | %1,2 | 7 Eyl 2024 |
39İzleyin | CVE-2026-21669İstismar yok | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.veeam · veeam backup \& replication · CWE-94 | Kritik9,9 | — | %1,2 | 12 Mar 2026 |
39İzleyin | CVE-2026-21708İstismar yok | A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.veeam · veeam backup \& replication · CWE-89 | Kritik9,9 | — | %1,1 | 12 Mar 2026 |
39İzleyin | CVE-2025-55125İstismar yok | This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuraveeam · veeam backup \& replication · CWE-77 | Kritik9,8 | — | %0,9 | 8 Oca 2026 |
39İzleyin | CVE-2024-38650İstismar yok | An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on the VSPC server.veeam · veeam service provider console · CWE-200 | Kritik9,9 | — | %0,9 | 7 Eyl 2024 |
39İzleyin | CVE-2025-48983İstismar yok | A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructurveeam · veeam backup \& replication · CWE-284 | Kritik9,9 | — | %0,8 | 30 Eki 2025 |
39İzleyin | CVE-2022-43549İstismar yok | Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms.veeam · veeam backup for google cloud · CWE-287 | Kritik9,8 | — | %0,7 | 5 Ara 2022 |
37İzleyin | CVE-2024-42455İstismar yok | A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserializatveeam · veeam backup \& replication · CWE-306 | Yüksek8,1 | — | %15,2 | 3 Ara 2024 |
36İzleyin | CVE-2022-26504İstismar yok | Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine veeam · veeam backup \& replication · CWE-287 | Yüksek8,8 | — | %2,4 | 17 Mar 2022 |
36İzleyin | CVE-2019-11569Kavram kanıtı | Veeam ONE Reporter 9.5.0.3201 allows CSRF.veeam · one reporter · CWE-352 | Yüksek8,8 | — | %2,3 | 6 May 2019 |
36İzleyin | CVE-2025-59470Kavram kanıtı | This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or oveeam · veeam backup \& replication · CWE-77 | Kritik9,0 | — | %1,6 | 8 Oca 2026 |
- CVE-2024-4071196Hemen
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %90veeam · veeam backup \& replication7 Eyl 2024
- CVE-2023-2753284Hemen
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained.
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %81veeam · veeam backup \& replication10 Mar 2023
- CVE-2022-2650170Bu hafta
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %4veeam · veeam backup \& replication17 Mar 2022
- CVE-2022-2650067Bu hafta
Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to inte
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %6veeam · veeam backup \& replication17 Mar 2022
- CVE-2020-1091565Bu hafta
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587.
KritikCVSS 9,8SilahlaştırılmışEPSS %87veeam · one22 Nis 2020
- CVE-2020-1091453Planlayın
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587.
KritikCVSS 9,8SilahlaştırılmışEPSS %48veeam · one22 Nis 2020
- CVE-2024-2984951Planlayın
Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.
KritikCVSS 9,8Kavram kanıtıEPSS %38veeam · veeam backup \& replication22 May 2024
- CVE-2020-1541948Planlayın
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415.
YüksekCVSS 7,5İstismar yokEPSS %60veeam · one firmware28 Tem 2020
- CVE-2023-3854745Planlayın
A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its
KritikCVSS 9,8İstismar yokEPSS %19veeam · one7 Kas 2023
- CVE-2025-2312142Planlayın
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user
YüksekCVSS 8,8İstismar yokEPSS %24veeam · veeam backup \& replication18 Haz 2025
- CVE-2025-2312042Planlayın
A vulnerability allowing remote code execution (RCE) for domain users.
YüksekCVSS 8,8İstismar yokEPSS %24veeam · veeam backup \& replication20 Mar 2025
- CVE-2024-2985542Planlayın
Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator
KritikCVSS 9,0Kavram kanıtıEPSS %22veeam · recovery orchestrator11 Haz 2024
- CVE-2024-2921239İzleyin
Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management ag
KritikCVSS 9,9İstismar yokEPSS %2veeam · veeam service provider console14 May 2024
- CVE-2021-3597139İzleyin
Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserialization during Microsoft
KritikCVSS 9,8İstismar yokEPSS %1veeam · veeam backup \& replication30 Haz 2021
- CVE-2024-3971439İzleyin
A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to remote code execution
KritikCVSS 9,9İstismar yokEPSS %1veeam · veeam service provider console7 Eyl 2024
- CVE-2026-2166939İzleyin
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
KritikCVSS 9,9İstismar yokEPSS %1veeam · veeam backup \& replication12 Mar 2026
- CVE-2026-2170839İzleyin
A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.
KritikCVSS 9,9İstismar yokEPSS %1veeam · veeam backup \& replication12 Mar 2026
- CVE-2025-5512539İzleyin
This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configura
KritikCVSS 9,8İstismar yokEPSS %1veeam · veeam backup \& replication8 Oca 2026
- CVE-2024-3865039İzleyin
An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on the VSPC server.
KritikCVSS 9,9İstismar yokEPSS %1veeam · veeam service provider console7 Eyl 2024
- CVE-2025-4898339İzleyin
A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructur
KritikCVSS 9,9İstismar yokEPSS %1veeam · veeam backup \& replication30 Eki 2025
- CVE-2022-4354939İzleyin
Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms.
KritikCVSS 9,8İstismar yokEPSS %1veeam · veeam backup for google cloud5 Ara 2022
- CVE-2024-4245537İzleyin
A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserializat
YüksekCVSS 8,1İstismar yokEPSS %15veeam · veeam backup \& replication3 Ara 2024
- CVE-2022-2650436İzleyin
Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine
YüksekCVSS 8,8İstismar yokEPSS %2veeam · veeam backup \& replication17 Mar 2022
- CVE-2019-1156936İzleyin
Veeam ONE Reporter 9.5.0.3201 allows CSRF.
YüksekCVSS 8,8Kavram kanıtıEPSS %2veeam · one reporter6 May 2019
- CVE-2025-5947036İzleyin
This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or o
KritikCVSS 9,0Kavram kanıtıEPSS %2veeam · veeam backup \& replication8 Oca 2026