Vendor CVEs
Veeam
All CVEs
93 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-42455 | Hig | 0.54 | 8.1 | 0.15 | Dec 4, 2024 | A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by sending a serialized temporary file collection. This exploit allows the attacker to delete any file on the system with service… | ||
| CVE-2024-40714 | Hig | 0.54 | 8.3 | 0.00 | Sep 7, 2024 | An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations. | ||
| CVE-2020-15419 | Hig | 0.54 | 7.5 | 0.61 | Jul 28, 2020 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Reporter_ImportLicense class. Due to the… | ||
| CVE-2024-42453 | Hig | 0.53 | 8.1 | 0.00 | Dec 4, 2024 | A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to power off virtual machines, delete files in storage, and make configuration changes, potentially… | ||
| CVE-2024-39718 | Hig | 0.53 | 8.1 | 0.01 | Sep 7, 2024 | An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account. | ||
| CVE-2024-42019 | Hig | 0.52 | 8.0 | 0.01 | Sep 7, 2024 | A vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This attack requires user interaction and data collected from Veeam Backup & Replication. | ||
| CVE-2025-55125 | Hig | 0.51 | 7.8 | 0.01 | Jan 8, 2026 | This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file. | ||
| CVE-2025-48982 | Hig | 0.51 | 7.8 | 0.00 | Oct 31, 2025 | This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious file. | ||
| CVE-2024-40713 | Hig | 0.51 | 7.8 | 0.00 | Sep 7, 2024 | A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA. | ||
| CVE-2024-40712 | Hig | 0.51 | 7.8 | 0.00 | Sep 7, 2024 | A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE). | ||
| CVE-2024-29853 | Hig | 0.51 | 7.8 | 0.00 | May 22, 2024 | An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation. | ||
| CVE-2022-26503 | Hig | 0.51 | 7.8 | 0.01 | Mar 17, 2022 | Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to run arbitrary code with local system privileges. | ||
| CVE-2026-21670 | Hig | 0.50 | 7.7 | 0.00 | Mar 12, 2026 | A vulnerability allowing a low-privileged user to extract saved SSH credentials. | ||
| CVE-2024-40715 | Hig | 0.50 | 7.7 | 0.01 | Nov 7, 2024 | A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypass. Attackers must be able to perform Man-in-the-Middle (MITM) attack to exploit this vulnerability. | ||
| CVE-2020-15418 | Hig | 0.50 | 7.5 | 0.09 | Jul 28, 2020 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSRSReport class. Due to the improper… | ||
| CVE-2025-24286 | Hig | 0.48 | 7.2 | 0.12 | Jun 19, 2025 | A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code. | ||
| CVE-2026-32996 | Hig | 0.47 | — | 0.00 | May 28, 2026 | This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation. | ||
| CVE-2025-23082 | Hig | 0.47 | 7.2 | 0.00 | Jan 14, 2025 | Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | ||
| CVE-2024-42449 | Hig | 0.47 | 7.1 | 0.06 | Dec 4, 2024 | From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to remove arbitrary files on the VSPC server machine. | ||
| CVE-2024-29851 | Hig | 0.47 | 7.2 | 0.01 | May 22, 2024 | Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account. | ||
| CVE-2024-45207 | Hig | 0.46 | 7.0 | 0.00 | Dec 4, 2024 | DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searches these directories for necessary DLLs. If an attacker places a malicious DLL in one of these directories, the Veeam Agent might load it… | ||
| CVE-2024-45206 | Med | 0.42 | 6.5 | 0.00 | Dec 4, 2024 | A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources. | ||
| CVE-2024-42457 | Med | 0.42 | 6.5 | 0.00 | Dec 4, 2024 | A vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by leveraging a combination of methods in a remote management interface. This can be achieved using a session object that allows for credential enumeration and… | ||
| CVE-2024-42451 | Med | 0.42 | 6.5 | 0.00 | Dec 4, 2024 | A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by calling a series of methods over an external protocol, ultimately retrieving the credentials using a malicious setup on the attacker's side.… | ||
| CVE-2024-42021 | Med | 0.42 | 6.5 | 0.00 | Sep 7, 2024 | An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials. | ||
| CVE-2025-24287 | Med | 0.40 | 6.1 | 0.00 | Jun 19, 2025 | A vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the local system with elevated permissions. | ||
| CVE-2022-32225 | Med | 0.40 | 6.1 | 0.01 | Jul 14, 2022 | A reflected DOM-Based XSS vulnerability has been discovered in the Help directory of Veeam Management Pack for Microsoft System Center 8.0. This vulnerability could be exploited by an attacker by convincing a legitimate user to visit a crafted URL on a Veeam Management Pack for… | ||
| CVE-2023-38549 | Med | 0.37 | 5.4 | 0.19 | Nov 7, 2023 | A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service. Note: The criticality of this vulnerability is reduced as it requires interaction by a… | ||
| CVE-2024-42020 | Med | 0.35 | 5.4 | 0.00 | Sep 7, 2024 | A Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection. | ||
| CVE-2019-14298 | Med | 0.35 | 5.4 | 0.01 | Jul 27, 2019 | Veeam ONE Reporter 9.5.0.3201 allows XSS via a crafted Description(config) field to addDashboard or editDashboard in CommonDataHandlerReadOnly.ashx. | ||
| CVE-2019-14297 | Med | 0.35 | 5.4 | 0.01 | Jul 27, 2019 | Veeam ONE Reporter 9.5.0.3201 allows XSS via the Add/Edit Widget with a crafted Caption field to setDashboardWidget in CommonDataHandlerReadOnly.ashx. | ||
| CVE-2024-42022 | Med | 0.34 | 5.3 | 0.00 | Sep 7, 2024 | An incorrect permission assignment vulnerability allows an attacker to modify product configuration files. | ||
| CVE-2023-41723 | Med | 0.29 | 4.3 | 0.12 | Nov 7, 2023 | A vulnerability in Veeam ONE allows a user with the Veeam ONE Read-Only User role to view the Dashboard Schedule. Note: The criticality of this vulnerability is reduced because the user with the Read-Only role is only able to view the schedule and cannot make changes. | ||
| CVE-2023-38548 | Med | 0.29 | 4.3 | 0.12 | Nov 7, 2023 | A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service. | ||
| CVE-2024-45204 | Med | 0.28 | 4.3 | 0.00 | Dec 4, 2024 | A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves using retrieved credentials to expose sensitive NTLM hashes, impacting systems beyond the initial… | ||
| CVE-2024-22021 | Med | 0.28 | 4.3 | 0.00 | Feb 7, 2024 | Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retrieve plans from a Scope other than the one they are assigned to. | ||
| CVE-2024-29852 | Low | 0.18 | 2.7 | 0.01 | May 22, 2024 | Veeam Backup Enterprise Manager allows high-privileged users to read backup session logs. | ||
| CVE-2026-64631 | Hig | 0.00 | — | 0.00 | Aug 4, 2026 | A vulnerability allowing a low-privileged user to inject SQL and extract database contents. | ||
| CVE-2026-64630 | Med | 0.00 | — | 0.00 | Aug 4, 2026 | A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link. | ||
| CVE-2026-58071 | Hig | 0.00 | — | 0.00 | Aug 4, 2026 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins. | ||
| CVE-2026-58067 | Hig | 0.00 | — | 0.00 | Aug 4, 2026 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service. | ||
| CVE-2026-64635 | Med | 0.00 | 5.3 | 0.00 | Jul 30, 2026 | Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset link. When the targeted user clicks the link delivered by email, the reset code… | ||
| CVE-2015-5742 | 0.00 | — | 0.01 | Oct 16, 2015 | VeeamVixProxy in Veeam Backup & Replication (B&R) before 8.0 update 3 stores local administrator credentials in log files with world-readable permissions, which allows local users to obtain sensitive information by reading the files. |
- risk 0.54cvss 8.1epss 0.15
A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by sending a serialized temporary file collection. This exploit allows the attacker to delete any file on the system with service…
- risk 0.54cvss 8.3epss 0.00
An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations.
- risk 0.54cvss 7.5epss 0.61
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Reporter_ImportLicense class. Due to the…
- risk 0.53cvss 8.1epss 0.00
A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to power off virtual machines, delete files in storage, and make configuration changes, potentially…
- risk 0.53cvss 8.1epss 0.01
An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account.
- risk 0.52cvss 8.0epss 0.01
A vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This attack requires user interaction and data collected from Veeam Backup & Replication.
- risk 0.51cvss 7.8epss 0.01
This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.
- risk 0.51cvss 7.8epss 0.00
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious file.
- risk 0.51cvss 7.8epss 0.00
A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA.
- risk 0.51cvss 7.8epss 0.00
A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE).
- risk 0.51cvss 7.8epss 0.00
An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation.
- risk 0.51cvss 7.8epss 0.01
Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to run arbitrary code with local system privileges.
- risk 0.50cvss 7.7epss 0.00
A vulnerability allowing a low-privileged user to extract saved SSH credentials.
- risk 0.50cvss 7.7epss 0.01
A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypass. Attackers must be able to perform Man-in-the-Middle (MITM) attack to exploit this vulnerability.
- risk 0.50cvss 7.5epss 0.09
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSRSReport class. Due to the improper…
- risk 0.48cvss 7.2epss 0.12
A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code.
- risk 0.47cvss —epss 0.00
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
- risk 0.47cvss 7.2epss 0.00
Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
- risk 0.47cvss 7.1epss 0.06
From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to remove arbitrary files on the VSPC server machine.
- risk 0.47cvss 7.2epss 0.01
Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.
- risk 0.46cvss 7.0epss 0.00
DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searches these directories for necessary DLLs. If an attacker places a malicious DLL in one of these directories, the Veeam Agent might load it…
- risk 0.42cvss 6.5epss 0.00
A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources.
- risk 0.42cvss 6.5epss 0.00
A vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by leveraging a combination of methods in a remote management interface. This can be achieved using a session object that allows for credential enumeration and…
- risk 0.42cvss 6.5epss 0.00
A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by calling a series of methods over an external protocol, ultimately retrieving the credentials using a malicious setup on the attacker's side.…
- risk 0.42cvss 6.5epss 0.00
An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.
- risk 0.40cvss 6.1epss 0.00
A vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the local system with elevated permissions.
- risk 0.40cvss 6.1epss 0.01
A reflected DOM-Based XSS vulnerability has been discovered in the Help directory of Veeam Management Pack for Microsoft System Center 8.0. This vulnerability could be exploited by an attacker by convincing a legitimate user to visit a crafted URL on a Veeam Management Pack for…
- risk 0.37cvss 5.4epss 0.19
A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service. Note: The criticality of this vulnerability is reduced as it requires interaction by a…
- risk 0.35cvss 5.4epss 0.00
A Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection.
- risk 0.35cvss 5.4epss 0.01
Veeam ONE Reporter 9.5.0.3201 allows XSS via a crafted Description(config) field to addDashboard or editDashboard in CommonDataHandlerReadOnly.ashx.
- risk 0.35cvss 5.4epss 0.01
Veeam ONE Reporter 9.5.0.3201 allows XSS via the Add/Edit Widget with a crafted Caption field to setDashboardWidget in CommonDataHandlerReadOnly.ashx.
- risk 0.34cvss 5.3epss 0.00
An incorrect permission assignment vulnerability allows an attacker to modify product configuration files.
- risk 0.29cvss 4.3epss 0.12
A vulnerability in Veeam ONE allows a user with the Veeam ONE Read-Only User role to view the Dashboard Schedule. Note: The criticality of this vulnerability is reduced because the user with the Read-Only role is only able to view the schedule and cannot make changes.
- risk 0.29cvss 4.3epss 0.12
A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service.
- risk 0.28cvss 4.3epss 0.00
A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves using retrieved credentials to expose sensitive NTLM hashes, impacting systems beyond the initial…
- risk 0.28cvss 4.3epss 0.00
Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retrieve plans from a Scope other than the one they are assigned to.
- risk 0.18cvss 2.7epss 0.01
Veeam Backup Enterprise Manager allows high-privileged users to read backup session logs.
- risk 0.00cvss —epss 0.00
A vulnerability allowing a low-privileged user to inject SQL and extract database contents.
- risk 0.00cvss —epss 0.00
A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.
- risk 0.00cvss —epss 0.00
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins.
- risk 0.00cvss —epss 0.00
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service.
- risk 0.00cvss 5.3epss 0.00
Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset link. When the targeted user clicks the link delivered by email, the reset code…
- CVE-2015-5742Oct 16, 2015risk 0.00cvss —epss 0.01
VeeamVixProxy in Veeam Backup & Replication (B&R) before 8.0 update 3 stores local administrator credentials in log files with world-readable permissions, which allows local users to obtain sensitive information by reading the files.
Page 2 of 2