CVE & Exploit Intelligence Database

Updated 55m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
48 results Clear all
CVE-2024-53915 9.8 CRITICAL EPSS 0.03
Veritas Enterprise Vault <15.2 - Code Injection
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24405. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
CWE-502 Nov 24, 2024
CVE-2024-53914 9.8 CRITICAL EPSS 0.06
Veritas Enterprise Vault <15.2 - Code Injection
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24344. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
CWE-502 Nov 24, 2024
CVE-2024-53913 9.8 CRITICAL EPSS 0.06
Veritas Enterprise Vault <15.2 - Code Injection
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24343. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
CWE-502 Nov 24, 2024
CVE-2024-53912 9.8 CRITICAL EPSS 0.03
Veritas Enterprise Vault <15.2 - Code Injection
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24341. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
CWE-502 Nov 24, 2024
CVE-2024-53911 9.8 CRITICAL EPSS 0.03
Veritas Enterprise Vault <15.2 - RCE
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24339. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
CWE-502 Nov 24, 2024
CVE-2024-53910 9.8 CRITICAL EPSS 0.06
Veritas Enterprise Vault <15.2 - Code Injection
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24336. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
CWE-502 Nov 24, 2024
CVE-2024-53909 9.8 CRITICAL EPSS 0.06
Veritas Enterprise Vault <15.2 - Code Injection
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24334. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
CWE-502 Nov 24, 2024
CVE-2024-28222 9.8 CRITICAL 1 PoC EPSS 0.01
Veritas Netbackup < 8.1.2 - Path Traversal
In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.
CWE-22 Mar 07, 2024
CVE-2023-40256 9.8 CRITICAL EPSS 0.00
Veritas Netbackup Snapshot Manager - Improper Certificate Validation
A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to interact with the RabbitMQ service. This was caused by improper validation of the client certificate due to misconfiguration of the RabbitMQ service. Exploiting this impacts the confidentiality and integrity of messages controlling the backup and restore jobs, and could result in the service becoming unavailable. This impacts only the jobs controlling the backup and restore activities, and does not allow access to (or deletion of) the backup snapshot data itself. This vulnerability is confined to the NetBackup Snapshot Manager feature and does not impact the RabbitMQ instance on the NetBackup primary servers.
CWE-295 Aug 11, 2023
CVE-2022-46414 9.8 CRITICAL EPSS 0.02
Veritas NetBackup <3.0, Access Appliance <8.0.100 - RCE
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Unauthenticated remote command execution can occur via the management portal.
CWE-306 Dec 04, 2022
CVE-2022-42308 9.0 CRITICAL EPSS 0.00
Veritas Netbackup < 8.2 - Path Traversal
An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can delete arbitrary files by leveraging a path traversal in the pbx_exchange registration code.
CWE-22 Oct 03, 2022
CVE-2022-42302 9.0 CRITICAL EPSS 0.01
Veritas Netbackup < 10.0 - SQL Injection
An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a SQL Injection attack affecting the NBFSMCLIENT service.
CWE-89 Oct 03, 2022
CVE-2022-36992 9.9 CRITICAL EPSS 0.01
Veritas NetBackup <9.1.0.1 - RCE
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely execute arbitrary commands on a NetBackup Primary server (in specific notify conditions).
Jul 28, 2022
CVE-2022-36990 9.6 CRITICAL EPSS 0.00
Veritas NetBackup <9.1.0.1 - Privilege Escalation
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely write arbitrary files to arbitrary locations from any Client to any other Client via a Primary server.
Jul 28, 2022
CVE-2022-36956 9.0 CRITICAL EPSS 0.00
Veritas NetBackup - Command Injection
In Veritas NetBackup, the NetBackup Client allows arbitrary command execution from any remote host that has access to a valid host-id NetBackup certificate/private key from the same domain. The affects 9.0.x through 9.0.0.1 and 9.1.x through 9.1.0.1.
Jul 27, 2022
CVE-2022-36954 9.9 CRITICAL EPSS 0.00
Veritas NetBackup OpsCenter <10 - Privilege Escalation
In Veritas NetBackup OpsCenter, under specific conditions, an authenticated remote attacker may be able to create or modify OpsCenter user accounts. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
Jul 27, 2022
CVE-2022-36951 9.8 CRITICAL EPSS 0.01
Veritas NetBackup OpsCenter <10 - RCE
In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may compromise the host by exploiting an incorrectly patched vulnerability. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
Jul 27, 2022
CVE-2022-36950 9.8 CRITICAL EPSS 0.02
Veritas NetBackup OpsCenter <10 - RCE
In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may be able to perform remote command execution through a Java classloader manipulation. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
Jul 27, 2022
CVE-2022-36949 9.3 CRITICAL EPSS 0.00
Veritas NetBackup OpsCenter <10 - Privilege Escalation
In Veritas NetBackup OpsCenter, an attacker with local access to a NetBackup OpsCenter server could potentially escalate their privileges. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
Jul 27, 2022
CVE-2022-22965 9.8 CRITICAL KEV RANSOMWARE 117 PoCs Analysis NUCLEI EPSS 0.94
Vmware Spring Framework < 5.2.20 - Code Injection
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
CWE-94 Apr 01, 2022