Vulnerabilities > Veeam > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-09-07 CVE-2024-42020 Cross-site Scripting vulnerability in Veeam ONE 12.0.0.2498/12.0.1.2591
A Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection.
network
low complexity
veeam CWE-79
5.4
2024-02-07 CVE-2024-22021 Unspecified vulnerability in Veeam products
Vulnerability?CVE-2024-22021 allows?a?Veeam Recovery Orchestrator user with a low?privileged?role (Plan?Author)?to retrieve?plans?from?a?Scope other than the one they are assigned to.
network
low complexity
veeam
4.3
2023-11-07 CVE-2023-38548 Unspecified vulnerability in Veeam ONE 12.0.0.2498/12.0.1.2591
A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service.
network
low complexity
veeam
4.3
2023-11-07 CVE-2023-38549 Cross-site Scripting vulnerability in Veeam ONE
A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service.
network
low complexity
veeam CWE-79
5.4
2023-11-07 CVE-2023-41723 Unspecified vulnerability in Veeam ONE
A vulnerability in Veeam ONE allows a user with the Veeam ONE Read-Only User role to view the Dashboard Schedule.
network
low complexity
veeam
4.3
2022-07-14 CVE-2022-32225 Cross-site Scripting vulnerability in Veeam Management Pack 8.0
A reflected DOM-Based XSS vulnerability has been discovered in the Help directory of Veeam Management Pack for Microsoft System Center 8.0.
network
low complexity
veeam CWE-79
6.1
2019-07-27 CVE-2019-14298 Cross-site Scripting vulnerability in Veeam ONE Reporter 9.5.0.3201
Veeam ONE Reporter 9.5.0.3201 allows XSS via a crafted Description(config) field to addDashboard or editDashboard in CommonDataHandlerReadOnly.ashx.
network
low complexity
veeam CWE-79
5.4
2019-07-27 CVE-2019-14297 Cross-site Scripting vulnerability in Veeam ONE Reporter 9.5.0.3201
Veeam ONE Reporter 9.5.0.3201 allows XSS via the Add/Edit Widget with a crafted Caption field to setDashboardWidget in CommonDataHandlerReadOnly.ashx.
network
low complexity
veeam CWE-79
5.4