NA - CVE-2024-40713 - A vulnerability that allows a user who has been...
A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA.
NA - CVE-2024-40714 - An improper certificate validation...
An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations.
NA - CVE-2024-40718 - A server side request forgery vulnerability...
A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vulnerability.
NA - CVE-2024-42019 - A vulnerability that allows an attacker to...
A vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This attack requires user interaction and data collected from Veeam Backup & Replication.
NA - CVE-2024-42024 - A vulnerability that allows an attacker in...
A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the machine where the Veeam ONE Agent is installed.
High - CVE-2024-1596 - The Ninja Forms - File Uploads plugin for...
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. RTX file) in all versions up to, and including, 3.3.16 due to...