Veeam
veeam
71 CVEs • 14 products
Products (14)
Click to collapseToggle
Products (14)
Click to collapse
CVEs (71)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Veeam 1Veeam Backup & Replication Jun 17, 2026 Mar 12, 2026 N/A· v4 9.9 CRITICAL· v3 N/A· v2 A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user. |
1Veeam 1Veeam Backup & Replication Jun 17, 2026 Mar 12, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication. |
A vulnerability allowing a low-privileged user to extract saved SSH credentials. |
1Veeam 1Veeam Backup & Replication Jun 17, 2026 Mar 12, 2026 N/A· v4 9.9 CRITICAL· v3 N/A· v2 A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. |
A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository. |
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. |
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. |
1Veeam 1Veeam Backup & Replication Jun 17, 2026 Jan 8, 2026 N/A· v4 9.0 CRITICAL· v3 N/A· v2 This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter. |
1Veeam 1Veeam Backup & Replication Jun 17, 2026 Jan 8, 2026 N/A· v4 9.0 CRITICAL· v3 N/A· v2 This vulnerability allows a Backup or Tape Operator to write files as root. |
1Veeam 1Veeam Backup & Replication Jun 17, 2026 Jan 8, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a
malicious password parameter. |
1Veeam 1Veeam Backup & Replication Jun 17, 2026 Jan 8, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious
backup configuration file. |
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. |
1Veeam 1Veeam Backup & Replication Jun 17, 2026 Oct 31, 2025 N/A· v4 9.9 CRITICAL· v3 N/A· v2 A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user. |
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious file. |
A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code. |
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user |
A vulnerability allowing remote code execution (RCE) for domain users. |
Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration o...Show more |
DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searches these directories for necessary DLLs. If an attacker places a malicious DLL i...Show more |
1Veeam 1Veeam Service Provider Console Jun 17, 2026 Dec 4, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources. |