VendorsVinchinvinchin_backup_and_recoveryany version
Vulnerabilities

Vinchin Backup And Recovery any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2023-45498
VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability.
Published 2023-10-27 · Modified
9.8EPSS 0.205
CVE-2023-45499
VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials.
Published 2023-10-27 · Modified
9.8EPSS 0.079
CVE-2024-22901
Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.
Published 2024-02-02 · Modified
9.8EPSS 0.011
CVE-2024-22902
Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.
Published 2024-02-02 · Modified
9.8EPSS 0.011
CVE-2024-25228
Vinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerifydiyResult function in ManoeuvreHandler.class.php.
Published 2024-03-14 · Modified
8.8EPSS 0.259
CVE-2024-22899
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.
Published 2024-02-02 · Modified
8.8EPSS 0.024
CVE-2024-22900
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function.
Published 2024-02-02 · Modified
8.8EPSS 0.019
CVE-2024-22903
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.
Published 2024-02-02 · Modified
8.8EPSS 0.019