CVEs (42)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Veeam 1Veeam Backup & Replication Jun 17, 2026 Mar 12, 2026 N/A· v4 9.9 CRITICAL· v3 N/A· v2 A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user. |
1Veeam 1Veeam Backup & Replication Jun 17, 2026 Mar 12, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication. |
A vulnerability allowing a low-privileged user to extract saved SSH credentials. |
1Veeam 1Veeam Backup & Replication Jun 17, 2026 Mar 12, 2026 N/A· v4 9.9 CRITICAL· v3 N/A· v2 A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. |
A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository. |
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. |
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. |
1Veeam 1Veeam Backup & Replication Jun 17, 2026 Jan 8, 2026 N/A· v4 9.0 CRITICAL· v3 N/A· v2 This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter. |
1Veeam 1Veeam Backup & Replication Jun 17, 2026 Jan 8, 2026 N/A· v4 9.0 CRITICAL· v3 N/A· v2 This vulnerability allows a Backup or Tape Operator to write files as root. |
1Veeam 1Veeam Backup & Replication Jun 17, 2026 Jan 8, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a
malicious password parameter. |
1Veeam 1Veeam Backup & Replication Jun 17, 2026 Jan 8, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious
backup configuration file. |
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. |
1Veeam 1Veeam Backup & Replication Jun 17, 2026 Oct 31, 2025 N/A· v4 9.9 CRITICAL· v3 N/A· v2 A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user. |
A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code. |
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user |
A vulnerability allowing remote code execution (RCE) for domain users. |
A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves using retrieved credentials to expose sen...Show more |
A vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by leveraging a combination of methods in a remote management interface. This can be achieved using a ses...Show more |
A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates critical configuration settings, such as modifying the trusted client certificate...Show more |
A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by sending a serialized temporary file collection. This exploit allows the a...Show more |