Vulnerabilities > Veeam > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-09-07 | CVE-2024-42020 | Cross-site Scripting vulnerability in Veeam ONE 12.0.0.2498/12.0.1.2591 A Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection. | 5.4 |
2024-02-07 | CVE-2024-22021 | Unspecified vulnerability in Veeam products Vulnerability?CVE-2024-22021 allows?a?Veeam Recovery Orchestrator user with a low?privileged?role (Plan?Author)?to retrieve?plans?from?a?Scope other than the one they are assigned to. | 4.3 |
2023-11-07 | CVE-2023-38548 | Unspecified vulnerability in Veeam ONE 12.0.0.2498/12.0.1.2591 A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service. | 4.3 |
2023-11-07 | CVE-2023-38549 | Cross-site Scripting vulnerability in Veeam ONE A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service. | 5.4 |
2023-11-07 | CVE-2023-41723 | Unspecified vulnerability in Veeam ONE A vulnerability in Veeam ONE allows a user with the Veeam ONE Read-Only User role to view the Dashboard Schedule. | 4.3 |
2022-07-14 | CVE-2022-32225 | Cross-site Scripting vulnerability in Veeam Management Pack 8.0 A reflected DOM-Based XSS vulnerability has been discovered in the Help directory of Veeam Management Pack for Microsoft System Center 8.0. | 6.1 |
2019-07-27 | CVE-2019-14298 | Cross-site Scripting vulnerability in Veeam ONE Reporter 9.5.0.3201 Veeam ONE Reporter 9.5.0.3201 allows XSS via a crafted Description(config) field to addDashboard or editDashboard in CommonDataHandlerReadOnly.ashx. | 5.4 |
2019-07-27 | CVE-2019-14297 | Cross-site Scripting vulnerability in Veeam ONE Reporter 9.5.0.3201 Veeam ONE Reporter 9.5.0.3201 allows XSS via the Add/Edit Widget with a crafted Caption field to setDashboardWidget in CommonDataHandlerReadOnly.ashx. | 5.4 |