7.8

CVSS3.0

CVE-2024-40709 -

A missing authorization vulnerability allows a local low-privileged user on the machine to escalate their privileges to root level.

πŸ“… Published: Sept. 7, 2024, 4:11 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-40713 -

A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA.

πŸ“… Published: Sept. 7, 2024, 4:11 p.m. πŸ”„ Last Modified: May 1, 2025, 6:17 p.m.

9.8

CVSS3.1

CVE-2024-40711 -

A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

πŸ“… Published: Sept. 7, 2024, 4:11 p.m. πŸ”„ Last Modified: Oct. 30, 2025, 8:40 p.m.

8.5

CVSS3.0

CVE-2024-39715 -

A code injection vulnerability that allows a low-privileged user with REST API access granted to remotely upload arbitrary files to the VSPC server using REST API, leading to remote code execution on VSPC server.

πŸ“… Published: Sept. 7, 2024, 4:11 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-40712 -

A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE).

πŸ“… Published: Sept. 7, 2024, 4:11 p.m. πŸ”„ Last Modified: May 1, 2025, 6:17 p.m.

8.5

CVSS3.0

CVE-2024-38651 -

A code injection vulnerability can allow a low-privileged user to overwrite files on that VSPC server, which can lead to remote code execution on VSPC server.

πŸ“… Published: Sept. 7, 2024, 4:11 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-42020 -

A Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection.

πŸ“… Published: Sept. 7, 2024, 4:11 p.m. πŸ”„ Last Modified: Oct. 27, 2024, 3:35 p.m.

9.9

CVSS3.0

CVE-2024-39714 -

A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to remote code execution on VSPC server.

πŸ“… Published: Sept. 7, 2024, 4:11 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-40710 -

A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcredentials and passwords). Exploiting these vulnerabilities requires a user who has been assigned a low-privileged role with…

πŸ“… Published: Sept. 7, 2024, 4:11 p.m. πŸ”„ Last Modified: May 1, 2025, 6:13 p.m.

8.1

CVSS3.1

CVE-2024-39718 -

An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account.

πŸ“… Published: Sept. 7, 2024, 4:11 p.m. πŸ”„ Last Modified: May 8, 2025, 2:41 p.m.
Total resulsts: 348434
Page 8563 of 34,844
Β« previous page Β» next page
Filters