VYPR

Vendor CVEs

Acronis

All CVEs

218 total · sorted by risk
  • CVE-2023-48681MedFeb 27, 2024
    risk 0.40cvss 6.1epss 0.00

    Self cross-site scripting (XSS) vulnerability in storage nodes search field. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.

  • CVE-2022-30992MedMay 18, 2022
    risk 0.40cvss 6.1epss 0.01

    Open redirect via user-controlled query parameter. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240

  • CVE-2022-30991MedMay 18, 2022
    risk 0.40cvss 6.1epss 0.01

    HTML injection via report name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240

  • CVE-2021-44201MedNov 29, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) was possible in notification pop-ups. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035

  • CVE-2021-38087MedAug 12, 2021
    risk 0.40cvss 6.1epss 0.01

    Reflected cross-site scripting (XSS) was possible on the login page in Acronis Cyber Protect 15 prior to build 27009.

  • CVE-2020-35664MedFeb 22, 2021
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. There is cross-site scripting (XSS) in the console.

  • CVE-2025-48960MedJun 4, 2025
    risk 0.38cvss 5.9epss 0.00

    Weak server key used for TLS encryption. The following products are affected: Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39938.

  • CVE-2024-49386MedOct 17, 2024
    risk 0.37cvss 5.7epss 0.00

    Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.

  • CVE-2026-28725MedMar 6, 2026
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to improper configuration of a headless browser. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

  • CVE-2025-30409MedApr 24, 2025
    risk 0.36cvss 5.5epss 0.00

    Denial of service due to allocation of resources without limits. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39904, Acronis Cyber Protect 17 (Windows) before build 41186.

  • CVE-2025-24832MedFeb 27, 2025
    risk 0.36cvss 5.5epss 0.00

    Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.4.866, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892,…

  • CVE-2024-56414MedJan 2, 2025
    risk 0.36cvss 5.5epss 0.00

    Web installer integrity check used weak hash algorithm. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.

  • CVE-2024-49385MedJan 2, 2025
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 41736, Acronis True Image OEM (Windows) before build 42575.

  • CVE-2024-34014MedNov 11, 2024
    risk 0.36cvss 5.5epss 0.00

    Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.3.818, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup…

  • CVE-2024-34018MedAug 29, 2024
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 4569.

  • CVE-2023-48680MedFeb 27, 2024
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Cyber Protect 16 (macOS, Windows) before build 37391.

  • CVE-2023-48678MedFeb 27, 2024
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.

  • CVE-2023-45245MedOct 6, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 36119.

  • CVE-2023-45243MedOct 5, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 35739, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186.

  • CVE-2023-45242MedOct 5, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 35739, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186.

  • CVE-2023-45241MedOct 5, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 35739, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 37391.

  • CVE-2023-45240MedOct 5, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 35739.

  • CVE-2023-44214MedOct 5, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 35739.

  • CVE-2023-44213MedOct 5, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 35739, Acronis Cyber Protect 16 (Windows) before build 37391.

  • CVE-2023-44210MedOct 4, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 29258, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186.

  • CVE-2023-4688MedAug 31, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information leak through log files. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 35433.

  • CVE-2023-41751MedAug 31, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to improper token expiration validation. The following products are affected: Acronis Agent (Windows) before build 32047.

  • CVE-2023-41750MedAug 31, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 32047.

  • CVE-2023-41745MedAug 31, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30991, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.

  • CVE-2023-2782MedMay 18, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.3.1-38.

  • CVE-2022-44746MedNov 7, 2022
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107.

  • CVE-2022-44745MedNov 7, 2022
    risk 0.36cvss 5.5epss 0.00

    Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107.

  • CVE-2021-44199MedNov 29, 2021
    risk 0.36cvss 5.5epss 0.00

    DLL hijacking could lead to denial of service. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27305, Acronis Cyber Protect Home Office (Windows) before build 39612

  • CVE-2020-9451MedMay 25, 2021
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe keeps a log in a folder where unprivileged users have write permissions. The logs are generated in a predictable pattern, allowing an unprivileged user to create a hardlink from a (not yet…

  • CVE-2023-48682MedFeb 27, 2024
    risk 0.35cvss 5.4epss 0.00

    Stored cross-site scripting (XSS) vulnerability in unit name. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.

  • CVE-2023-48679MedFeb 27, 2024
    risk 0.35cvss 5.4epss 0.00

    Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.

  • CVE-2023-44207MedSep 27, 2023
    risk 0.35cvss 5.4epss 0.01

    Stored cross-site scripting (XSS) vulnerability in protection plan name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.

  • CVE-2021-44203MedNov 29, 2021
    risk 0.35cvss 5.4epss 0.00

    Stored cross-site scripting (XSS) was possible in protection plan details. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035

  • CVE-2021-44202MedNov 29, 2021
    risk 0.35cvss 5.4epss 0.00

    Stored cross-site scripting (XSS) was possible in activity details. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035

  • CVE-2021-44200MedNov 29, 2021
    risk 0.35cvss 5.4epss 0.00

    Self cross-site scripting (XSS) was possible on devices page. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035

  • CVE-2023-44205MedSep 27, 2023
    risk 0.34cvss 5.3epss 0.01

    Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.

  • CVE-2026-28717MedMar 6, 2026
    risk 0.33cvss 5.0epss 0.00

    Local privilege escalation due to improper directory permissions. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.

  • CVE-2026-28714MedMar 6, 2026
    risk 0.31cvss 4.8epss 0.00

    Unnecessary transmission of sensitive cryptographic material. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

  • CVE-2024-49392MedOct 17, 2024
    risk 0.31cvss 4.8epss 0.00

    Stored cross-site scripting (XSS) vulnerability on enrollment invitation page. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.

  • CVE-2024-8903MedSep 23, 2024
    risk 0.31cvss 4.7epss 0.00

    Local active protection service settings manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows, macOS) before build 38565.

  • CVE-2026-28716MedMar 6, 2026
    risk 0.29cvss 4.4epss 0.00

    Information disclosure and manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

  • CVE-2025-30413MedMar 6, 2026
    risk 0.29cvss 4.4epss 0.00

    Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 40497, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186.

  • CVE-2025-11790MedMar 6, 2026
    risk 0.29cvss 4.4epss 0.00

    Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 41124.

  • CVE-2024-55542MedJan 2, 2025
    risk 0.29cvss 4.4epss 0.00

    Local privilege escalation due to excessive permissions assigned to Tray Monitor service. The following products are affected: Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39169, Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 35895.

  • CVE-2024-34012MedJun 14, 2024
    risk 0.29cvss 4.4epss 0.00

    Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.24135.272.

Page 4 of 5