VYPR
Vendor

Veeam

Products
30
CVEs
93
Across products
136
Status
Private

Products

30

Recent CVEs

93
View all 93 CVEs →
  • CVE-2024-40711CriKEVSep 7, 2024
    risk 0.89cvss 9.8epss 0.90

    A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

  • CVE-2022-26501CriKEVMar 17, 2022
    risk 0.82cvss 9.8epss 0.04

    Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).

  • CVE-2022-26500HigKEVMar 17, 2022
    risk 0.76cvss 8.8epss 0.06

    Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.

  • CVE-2020-10915CriApr 22, 2020
    risk 0.74cvss 9.8epss 0.87

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HandshakeResult method. The issue results from the lack…

  • CVE-2023-27532HigKEVMar 10, 2023
    risk 0.73cvss 7.5epss 0.78

    Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.

  • CVE-2020-10914CriApr 22, 2020
    risk 0.70cvss 9.8epss 0.47

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specific flaw exists within the PerformHandshake method. The issue results from the…

  • CVE-2026-64633CriAug 4, 2026
    risk 0.65cvss epss 0.00

    A vulnerability allowing remote unauthenticated code execution on the agent host.

  • CVE-2024-29849CriMay 22, 2024
    risk 0.65cvss 9.8epss 0.17

    Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.

  • CVE-2023-38547CriNov 7, 2023
    risk 0.65cvss 9.8epss 0.19

    A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database. This may lead to remote code execution on the SQL server hosting the Veeam ONE configuration database.

  • CVE-2026-21708CriMar 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.

  • CVE-2026-21669CriMar 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

  • CVE-2026-21667CriMar 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

  • CVE-2026-21666CriMar 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

  • CVE-2025-48983CriOct 31, 2025
    risk 0.64cvss 9.9epss 0.01

    A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.

  • CVE-2024-39714CriSep 7, 2024
    risk 0.64cvss 9.9epss 0.01

    A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to remote code execution on VSPC server.

  • CVE-2024-38650CriSep 7, 2024
    risk 0.64cvss 9.9epss 0.01

    An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on the VSPC server.

  • CVE-2024-29212CriMay 14, 2024
    risk 0.64cvss 9.9epss 0.02

    Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

  • CVE-2022-43549CriDec 5, 2022
    risk 0.64cvss 9.8epss 0.01

    Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms.

  • CVE-2021-35971CriJun 30, 2021
    risk 0.64cvss 9.8epss 0.01

    Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserialization during Microsoft .NET remoting.

  • CVE-2026-58073CriAug 4, 2026
    risk 0.62cvss epss 0.00

    A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.