VYPR

Vendor CVEs

Veeam

All CVEs

93 total · sorted by risk
  • CVE-2024-40711CriKEVSep 7, 2024
    risk 0.89cvss 9.8epss 0.90

    A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

  • CVE-2022-26501CriKEVMar 17, 2022
    risk 0.82cvss 9.8epss 0.04

    Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).

  • CVE-2022-26500HigKEVMar 17, 2022
    risk 0.76cvss 8.8epss 0.06

    Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.

  • CVE-2020-10915CriApr 22, 2020
    risk 0.74cvss 9.8epss 0.87

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HandshakeResult method. The issue results from the lack…

  • CVE-2023-27532HigKEVMar 10, 2023
    risk 0.73cvss 7.5epss 0.78

    Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.

  • CVE-2020-10914CriApr 22, 2020
    risk 0.70cvss 9.8epss 0.47

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specific flaw exists within the PerformHandshake method. The issue results from the…

  • CVE-2026-64633CriAug 4, 2026
    risk 0.65cvss epss 0.00

    A vulnerability allowing remote unauthenticated code execution on the agent host.

  • CVE-2024-29849CriMay 22, 2024
    risk 0.65cvss 9.8epss 0.17

    Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.

  • CVE-2023-38547CriNov 7, 2023
    risk 0.65cvss 9.8epss 0.19

    A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database. This may lead to remote code execution on the SQL server hosting the Veeam ONE configuration database.

  • CVE-2026-21708CriMar 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.

  • CVE-2026-21669CriMar 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

  • CVE-2026-21667CriMar 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

  • CVE-2026-21666CriMar 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

  • CVE-2025-48983CriOct 31, 2025
    risk 0.64cvss 9.9epss 0.01

    A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.

  • CVE-2024-39714CriSep 7, 2024
    risk 0.64cvss 9.9epss 0.01

    A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to remote code execution on VSPC server.

  • CVE-2024-38650CriSep 7, 2024
    risk 0.64cvss 9.9epss 0.01

    An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on the VSPC server.

  • CVE-2024-29212CriMay 14, 2024
    risk 0.64cvss 9.9epss 0.02

    Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

  • CVE-2022-43549CriDec 5, 2022
    risk 0.64cvss 9.8epss 0.01

    Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms.

  • CVE-2021-35971CriJun 30, 2021
    risk 0.64cvss 9.8epss 0.01

    Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserialization during Microsoft .NET remoting.

  • CVE-2026-58073CriAug 4, 2026
    risk 0.62cvss epss 0.00

    A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.

  • CVE-2026-44963CriJun 9, 2026
    risk 0.61cvss epss 0.02

    A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.

  • CVE-2026-32998CriMay 28, 2026
    risk 0.61cvss epss 0.00

    This vulnerability in Veeam Service Provider Console allows for remote code execution.

  • CVE-2024-29855CriJun 11, 2024
    risk 0.60cvss 9.0epss 0.22

    Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator

  • CVE-2019-11569HigMay 6, 2019
    risk 0.60cvss 8.8epss 0.02

    Veeam ONE Reporter 9.5.0.3201 allows CSRF.

  • CVE-2026-58072CriAug 4, 2026
    risk 0.59cvss epss 0.00

    A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution.

  • CVE-2026-21671CriMar 12, 2026
    risk 0.59cvss 9.1epss 0.01

    A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.

  • CVE-2025-59470CriJan 8, 2026
    risk 0.59cvss 9.0epss 0.02

    This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.

  • CVE-2025-59469CriJan 8, 2026
    risk 0.59cvss 9.0epss 0.01

    This vulnerability allows a Backup or Tape Operator to write files as root.

  • CVE-2025-59468CriJan 8, 2026
    risk 0.59cvss 9.0epss 0.01

    This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.

  • CVE-2025-23120HigMar 20, 2025
    risk 0.59cvss 8.8epss 0.22

    A vulnerability allowing remote code execution (RCE) for domain users.

  • CVE-2025-23114CriFeb 5, 2025
    risk 0.59cvss 9.0epss 0.01

    A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected server. This issue occurs due to a failure to properly validate TLS certificate.

  • CVE-2025-23121HigJun 19, 2025
    risk 0.58cvss 8.8epss 0.18

    A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user

  • CVE-2026-21672HigMar 12, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.

  • CVE-2026-21668HigMar 12, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.

  • CVE-2025-48984HigOct 31, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.

  • CVE-2024-42456HigDec 4, 2024
    risk 0.57cvss 8.8epss 0.00

    A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates critical configuration settings, such as modifying the trusted client certificate used for authentication on a specific port. This can result…

  • CVE-2024-42452HigDec 4, 2024
    risk 0.57cvss 8.8epss 0.00

    A vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and obtain credentials, effectively escalating privileges to system-level access. This allows the attacker to upload files to the server with elevated privileges.…

  • CVE-2024-40717HigDec 4, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be configured to run pre- and post-scripts, which can be located on a network share and are executed…

  • CVE-2024-42024HigSep 7, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the machine where the Veeam ONE Agent is installed.

  • CVE-2024-42023HigSep 7, 2024
    risk 0.57cvss 8.8epss 0.00

    An improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remotely.

  • CVE-2024-40718HigSep 7, 2024
    risk 0.57cvss 8.8epss 0.00

    A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vulnerability.

  • CVE-2024-40710HigSep 7, 2024
    risk 0.57cvss 8.8epss 0.01

    A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcredentials and passwords). Exploiting these vulnerabilities requires a user who has been assigned a…

  • CVE-2024-29850HigMay 22, 2024
    risk 0.57cvss 8.8epss 0.01

    Veeam Backup Enterprise Manager allows account takeover via NTLM relay.

  • CVE-2024-22022HigFeb 7, 2024
    risk 0.57cvss 8.8epss 0.01

    Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to access the NTLM hash of the service account used by the Veeam Orchestrator Server Service.

  • CVE-2022-26504HigMar 17, 2022
    risk 0.57cvss 8.8epss 0.03

    Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (SCVMM) allows attackers execute arbitrary code via Veeam.Backup.PSManager.exe

  • CVE-2020-15518HigJul 3, 2020
    risk 0.57cvss 8.8epss 0.01

    VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged users to achieve total control over filesystem I/O requests.

  • CVE-2026-58074HigAug 4, 2026
    risk 0.56cvss epss 0.00

    A vulnerability allowing a high-privileged user to execute arbitrary code on the server.

  • CVE-2026-32997HigMay 28, 2026
    risk 0.56cvss epss 0.01

    A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication server.

  • CVE-2026-64634HigAug 4, 2026
    risk 0.55cvss epss 0.00

    A vulnerability allowing local privilege escalation to the Reporter service context.

  • CVE-2024-38651HigSep 7, 2024
    risk 0.55cvss 8.5epss 0.01

    A code injection vulnerability can allow a low-privileged user to overwrite files on that VSPC server, which can lead to remote code execution on VSPC server.

Page 1 of 2