漏洞列表 360566
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2026-28719
Unauthorized resource manipulation due to improper authorization checks. The following products are
MEDIUM 4.3 2026-03-06
acronis cyber_protect
NVD
CVE-2026-28718
Denial of service due to insufficient input validation in authentication logging. The following prod
MEDIUM 5.3 2026-03-06
acronis cyber_protect
NVD
CVE-2026-28717
Local privilege escalation due to improper directory permissions. The following products are affecte
MEDIUM 5.0 2026-03-06
acronis cyber_protect
NVD
CVE-2026-28716
Information disclosure and manipulation due to improper authorization checks. The following products
MEDIUM 4.4 2026-03-06
acronis cyber_protect
NVD
CVE-2026-28715
Sensitive information disclosure due to improper authorization checks. The following products are af
MEDIUM 6.5 2026-03-06
acronis cyber_protect
NVD
CVE-2026-28714
Unnecessary transmission of sensitive cryptographic material. The following products are affected: A
MEDIUM 4.8 2026-03-06
acronis cyber_protect
NVD
CVE-2026-28713
Default credentials set for local privileged user in Virtual Appliance. The following products are a
HIGH 7.1 2026-03-06
acronis agent acronis cyber_protect
NVD
CVE-2026-28712
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected:
MEDIUM 6.3 2026-03-06
acronis cyber_protect
NVD
CVE-2026-28711
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected:
MEDIUM 6.3 2026-03-06
acronis cyber_protect
NVD
CVE-2026-28710
Sensitive information disclosure and manipulation due to improper authentication. The following prod
HIGH 8.1 2026-03-06
acronis cyber_protect
NVD
CVE-2026-28709
Unauthorized resource manipulation due to improper authorization checks. The following products are
MEDIUM 4.3 2026-03-06
acronis cyber_protect
NVD
CVE-2026-27778
The WebSocket Application Programming Interface lacks restrictions on the number of authentication r
HIGH 7.5 2026-03-06
未知
NVD
CVE-2026-27770
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
MEDIUM 6.5 2026-03-06
未知
NVD
CVE-2026-24912
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows mu
HIGH 7.3 2026-03-06
未知
NVD
CVE-2026-22552
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorize
CRITICAL 9.4 2026-03-06
未知
NVD
CVE-2025-30413
Credentials are not deleted from Acronis Agent after plan revocation. The following products are aff
MEDIUM 4.4 2026-03-06
acronis agent acronis cyber_protect
NVD
CVE-2025-11792
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected:
HIGH 7.3 2026-03-06
acronis agent
NVD
CVE-2025-11791
Sensitive information disclosure and manipulation due to insufficient authorization checks. The foll
MEDIUM 5.5 2026-03-06
acronis agent acronis cyber_protect
NVD
CVE-2025-11790
Credentials are not deleted from Acronis Agent after plan revocation. The following products are aff
MEDIUM 4.4 2026-03-06
acronis agent
NVD
CVE-2026-26125
Payment Orchestrator Service Elevation of Privilege Vulnerability
HIGH 8.6 2026-03-05
未知
NVD