| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| This vulnerability in Veeam Agent for Microsoft Windows allows any local user to terminate arbitrary processes on the system. |
| This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to make the agent write files to arbitrary locations when an administrator installs it. |
| This vulnerability in Veeam Backup Enterprise Manager allows an attacker to execute script in the browser of a portal user who opens a crafted link. |
| This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server. |
| This vulnerability in Veeam Backup & Replication allows a Backup Viewer to modify the Enterprise Manager master key and stored antivirus update credentials. |
| This vulnerability in Veeam Backup & Replication allows an authenticated Cloud Connect tenant to read arbitrary files on the service provider host. |
| A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. |
| A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account. |
| A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account. |
| A vulnerability that records guest OS processing credentials in cleartext in a support log on the guest, allowing a user with read access to that log to recover privileged account credentials. |
| A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally. |
| A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins. |
| A vulnerability allowing remote unauthenticated code execution on the agent host. |
| A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service. |
| A vulnerability allowing local privilege escalation to the Reporter service context. |
| A vulnerability allowing a low-privileged user to inject SQL and extract database contents. |
| A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials. |
| A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link. |
| A vulnerability allowing a high-privileged user to execute arbitrary code on the server. |
| A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution. |