VendorsAcroniscyber_protect15
Vulnerabilities

Acronis Cyber Protect 15

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

51CVEs
CVE-2020-35664
An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. There is cross-site scripting (XSS) in the console.
Published 2021-02-22 · Modified
6.1EPSS 0.007
CVE-2021-44201
Cross-site scripting (XSS) was possible in notification pop-ups
Published 2021-11-29 · Modified
6.1EPSS 0.006
CVE-2021-38087
Reflected cross-site scripting (XSS) was possible on the login page in Acronis Cyber Protect 15 prior to build 27009.
Published 2021-08-12 · Modified
6.1EPSS 0.006
CVE-2022-30992
Open redirect via user-controlled query parameter
Published 2022-05-18 · Modified
6.1EPSS 0.006
CVE-2022-30991
HTML injection via report name
Published 2022-05-18 · Modified
6.1EPSS 0.006
CVE-2023-41745
Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30991, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.
Published 2023-08-31 · Modified
6.1EPSS 0.002
CVE-2021-44199
DLL hijacking could lead to denial of service
Published 2021-11-29 · Modified
5.5EPSS 0.002
CVE-2021-44203
Stored cross-site scripting (XSS) was possible in protection plan details
Published 2021-11-29 · Modified
5.4EPSS 0.005
CVE-2021-44202
Stored cross-site scripting (XSS) was possible in activity details
Published 2021-11-29 · Modified
5.4EPSS 0.005
CVE-2021-44200
Self cross-site scripting (XSS) was possible on devices page
Published 2021-11-29 · Modified
5.4EPSS 0.005
CVE-2023-44205
Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
Published 2023-09-27 · Modified
5.3EPSS 0.006
← Prev2 / 2