CVE & Exploit Intelligence Database

Updated 53m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
41 results Clear all
CVE-2024-28222 9.8 CRITICAL 1 PoC EPSS 0.01
Veritas Netbackup < 8.1.2 - Path Traversal
In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.
CWE-22 Mar 07, 2024
CVE-2023-37237 6.5 MEDIUM EPSS 0.00
Veritas Netbackup Appliance - Incorrect Permission Assignment
In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arbitrary operating system commands via SSH.
CWE-732 Jun 29, 2023
CVE-2022-37000 6.5 MEDIUM EPSS 0.00
Veritas NetBackup <9.1.0.1 - Info Disclosure
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). Under certain conditions, an attacker with authenticated access to a NetBackup Client could remotely read files on a NetBackup Primary server.
Jul 28, 2022
CVE-2022-36999 6.5 MEDIUM EPSS 0.00
Veritas NetBackup <9.1.0.1 - Info Disclosure
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). Under certain conditions, an attacker with authenticated access to a NetBackup Client could remotely read files on a NetBackup Primary server.
Jul 28, 2022
CVE-2022-36998 6.3 MEDIUM EPSS 0.00
Veritas Flex Appliance - Out-of-Bounds Write
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely trigger a stack-based buffer overflow on the NetBackup Primary server, resulting in a denial of service.
CWE-787 Jul 28, 2022
CVE-2022-36997 7.1 HIGH EPSS 0.00
Veritas Flex Appliance - SSRF
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely trigger impacts that include arbitrary file read, Server-Side Request Forgery (SSRF), and denial of service.
CWE-918 Jul 28, 2022
CVE-2022-36996 4.3 MEDIUM EPSS 0.00
Veritas NetBackup <9.1.0.1 - Info Disclosure
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with access to a NetBackup Client could remotely gather information about any host known to a NetBackup Primary server.
Jul 28, 2022
CVE-2022-36995 4.3 MEDIUM EPSS 0.00
Veritas NetBackup <9.1.0.1 - Privilege Escalation
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could arbitrarily create directories on a NetBackup Primary server.
Jul 28, 2022
CVE-2022-36994 6.3 MEDIUM EPSS 0.00
Veritas NetBackup <9.1.0.1 - Info Disclosure
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could arbitrarily read files from a NetBackup Primary server.
Jul 28, 2022
CVE-2022-36993 8.8 HIGH EPSS 0.01
Veritas NetBackup <9.1.0.1 - RCE
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely execute arbitrary commands on a NetBackup Primary server.
Jul 28, 2022
CVE-2022-36992 9.9 CRITICAL EPSS 0.01
Veritas NetBackup <9.1.0.1 - RCE
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely execute arbitrary commands on a NetBackup Primary server (in specific notify conditions).
Jul 28, 2022
CVE-2022-36991 8.1 HIGH EPSS 0.00
Veritas NetBackup <9.1.0.1 - Privilege Escalation
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could arbitrarily write content to a partially controlled path on a NetBackup Primary server.
Jul 28, 2022
CVE-2022-36990 9.6 CRITICAL EPSS 0.00
Veritas NetBackup <9.1.0.1 - Privilege Escalation
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely write arbitrary files to arbitrary locations from any Client to any other Client via a Primary server.
Jul 28, 2022
CVE-2022-36989 8.8 HIGH EPSS 0.01
Veritas NetBackup <9.1.0.1 - RCE
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely execute arbitrary commands on a NetBackup Primary server.
Jul 28, 2022
CVE-2022-36988 8.0 HIGH EPSS 0.01
Veritas NetBackup <9.1.0.1 - RCE
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup OpsCenter server, NetBackup Primary server, or NetBackup Media server could remotely execute arbitrary commands on a NetBackup Primary server or NetBackup Media server.
Jul 28, 2022
CVE-2022-36987 8.5 HIGH EPSS 0.00
Veritas NetBackup <9.1.0.1 - Privilege Escalation
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could arbitrarily write files to a NetBackup Primary server.
Jul 28, 2022
CVE-2022-36986 8.6 HIGH EPSS 0.01
Veritas NetBackup <9.1.0.1 - RCE
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with unauthenticated access could remotely execute arbitrary commands on a NetBackup Primary server.
Jul 28, 2022
CVE-2022-36985 7.8 HIGH EPSS 0.00
Veritas NetBackup <9.1.0.1 - Privilege Escalation
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with unprivileged local access to a Windows NetBackup Primary server could potentially escalate their privileges.
Jul 28, 2022
CVE-2022-36984 7.7 HIGH EPSS 0.00
Veritas Flex Appliance - Denial of Service
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely trigger a denial of service attack against a NetBackup Primary server.
Jul 28, 2022
CVE-2022-22965 9.8 CRITICAL KEV RANSOMWARE 117 PoCs Analysis NUCLEI EPSS 0.94
Vmware Spring Framework < 5.2.20 - Code Injection
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
CWE-94 Apr 01, 2022