Cloud Backup

Vendor:

First CVE: Nov 10, 2016 · Active for 9 years

345
Total CVEs
More Total CVEs than 100% of tracked products
43.1
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
2.3%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Cloud Backup over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 10, 2016
9 years ago
Most Recent CVE
May 3, 2023
1,178 days ago

CVE Severity & Scoring

Cloud Backup345 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local134 (38.8%)
Network192 (55.7%)
Unknown0 (0.0%)
Physical12 (3.5%)
Adjacent Network7 (2.0%)
Attack Complexity
Low254 (73.6%)
High91 (26.4%)
Unknown0 (0.0%)
User Interaction
None286 (82.9%)
Unknown0 (0.0%)
Required59 (17.1%)
Privileges Required
Low110 (31.9%)
High30 (8.7%)
None205 (59.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (345 CVEs).

345 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directori
Oct 7, 20219.899YESYES
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories con
Oct 5, 20219.899YESYES
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg
Jan 26, 20217.899YESYES
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Sep 16, 20219.097YESYES
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory
Jul 7, 20217.896YESYES
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploi
Oct 11, 20197.896YESYES
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's
Apr 29, 20206.195YESYES
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature
Nov 10, 20167.095YESYES
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an explo
Dec 20, 20219.888NOYES
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has be
Aug 17, 20185.386NOYES

Exploit Exposure

Signals from CVEs in this product scope (345 CVEs).

CISA KEV
8 CVEs
2.3% of CVEs· 96th percentile
Metasploit
6 CVEs
1.7% of CVEs· 96th percentile
Nuclei
5 CVEs
1.4% of CVEs· 96th percentile
ExploitDB
14 CVEs
4.1% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (345 CVEs).

Media Mentions

Signals from CVEs in this product scope (345 CVEs).

Top CNAs Publishing CVEs For Cloud Backup

Top CWEs

Versions

No cataloged versions.