VYPR

Vendor CVEs

Acronis

All CVEs

218 total · sorted by risk
  • CVE-2026-28726MedMar 6, 2026
    risk 0.28cvss 4.3epss 0.00

    Sensitive information disclosure due to improper access control. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

  • CVE-2026-28724MedMar 6, 2026
    risk 0.28cvss 4.3epss 0.00

    Unauthorized data access due to insufficient access control validation. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

  • CVE-2026-28723MedMar 6, 2026
    risk 0.28cvss 4.3epss 0.00

    Unauthorized report deletion due to insufficient access control. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

  • CVE-2026-28720MedMar 6, 2026
    risk 0.28cvss 4.3epss 0.00

    Unauthorized modification of settings due to insufficient authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

  • CVE-2026-28719MedMar 6, 2026
    risk 0.28cvss 4.3epss 0.00

    Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

  • CVE-2026-28709MedMar 6, 2026
    risk 0.28cvss 4.3epss 0.00

    Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

  • CVE-2025-48962MedJun 4, 2025
    risk 0.28cvss 4.3epss 0.00

    Sensitive information disclosure due to SSRF. The following products are affected: Acronis Cyber Protect 16 (Windows, Linux) before build 39938.

  • CVE-2024-49384MedOct 15, 2024
    risk 0.28cvss 4.3epss 0.00

    Excessive attack surface in acep-collector service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.

  • CVE-2024-49383MedOct 15, 2024
    risk 0.28cvss 4.3epss 0.00

    Excessive attack surface in acep-importer service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.

  • CVE-2024-49382MedOct 15, 2024
    risk 0.28cvss 4.3epss 0.00

    Excessive attack surface in archive-server service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.

  • CVE-2024-55538MedJan 2, 2025
    risk 0.26cvss 4.0epss 0.00

    Sensitive information disclosure due to missing authentication. The following products are affected: Acronis True Image (macOS) before build 41725, Acronis True Image (Windows) before build 41736, Acronis True Image OEM (macOS) before build 42571, Acronis True Image OEM…

  • CVE-2024-34015LowNov 11, 2024
    risk 0.21cvss 3.3epss 0.00

    Sensitive information disclosure during file browsing due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.3.818, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892.

  • CVE-2024-55539LowDec 23, 2024
    risk 0.16cvss 2.5epss 0.00

    Weak algorithm used to sign RPM package. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux) before build 39185, Acronis Cyber Protect 16 (Linux) before build 39938.

  • CVE-2008-1411Mar 20, 2008
    risk 0.04cvss epss 0.08

    The PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to cause a denial of service (crash) via an incomplete TFTP request, which triggers a NULL pointer dereference.

  • CVE-2008-1410Mar 20, 2008
    risk 0.03cvss epss 0.06

    Directory traversal vulnerability in the PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to read arbitrary files via directory traversal sequences to the TFTP service.

  • CVE-2008-3671Aug 13, 2008
    risk 0.00cvss epss 0.02

    Acronis True Image Echo Server 9.x build 8072 on Linux does not properly encrypt backups to an FTP server, which allows remote attackers to obtain sensitive information. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…

  • CVE-2008-1280Mar 10, 2008
    risk 0.00cvss epss 0.02

    Acronis True Image Windows Agent 1.0.0.54 and earlier, included in Acronis True Image Enterprise Server 9.5.0.8072 and the other True Image packages, allows remote attackers to cause a denial of service (crash) via a malformed packet to port 9876, which triggers a NULL pointer…

  • CVE-2008-1279Mar 10, 2008
    risk 0.00cvss epss 0.02

    Acronis True Image Group Server 1.5.19.191 and earlier, included in Acronis True Image Enterprise Server 9.5.0.8072 and the other True Image packages, allows remote attackers to cause a denial of service (crash) via a packet with an invalid length field, which causes an…

Page 5 of 5