VYPR

Veeam

by Veeam

CVEs (12)

  • CVE-2026-65641CriAug 26, 2026
    risk 0.60cvss epss 0.01

    A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.

  • CVE-2026-58075HigAug 4, 2026
    risk 0.57cvss epss 0.00

    A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.

  • CVE-2024-40718HigSep 7, 2024
    risk 0.57cvss 8.8epss 0.00

    A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vulnerability.

  • CVE-2026-64631HigAug 4, 2026
    risk 0.56cvss epss 0.00

    A vulnerability allowing a low-privileged user to inject SQL and extract database contents.

  • CVE-2024-39718HigSep 7, 2024
    risk 0.53cvss 8.1epss 0.01

    An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account.

  • CVE-2024-40712HigSep 7, 2024
    risk 0.51cvss 7.8epss 0.00

    A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE).

  • CVE-2022-26503HigMar 17, 2022
    risk 0.51cvss 7.8epss 0.01

    Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to run arbitrary code with local system privileges.

  • CVE-2026-58070MedAug 26, 2026
    risk 0.44cvss epss 0.00

    A vulnerability that records guest OS processing credentials in cleartext in a support log on the guest, allowing a user with read access to that log to recover privileged account credentials.

  • CVE-2024-42021MedSep 7, 2024
    risk 0.42cvss 6.5epss 0.00

    An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.

  • CVE-2025-24287MedJun 19, 2025
    risk 0.40cvss 6.1epss 0.00

    A vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the local system with elevated permissions.

  • CVE-2024-42022MedSep 7, 2024
    risk 0.34cvss 5.3epss 0.00

    An incorrect permission assignment vulnerability allows an attacker to modify product configuration files.

  • CVE-2024-45204MedDec 4, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves using retrieved credentials to expose sensitive NTLM hashes, impacting systems beyond the initial…