Cloud Backup
Vendor:
First CVE: Nov 10, 2016 · Active for 9 years
345
Total CVEs
More Total CVEs than 100% of tracked products
43.1
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
2.3%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Cloud Backup over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 10, 2016
9 years ago
Most Recent CVE
May 3, 2023
1,178 days ago
CVE Severity & Scoring
Cloud Backup345 CVEs
43%
42%
11%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local134 (38.8%)
Network192 (55.7%)
Unknown0 (0.0%)
Physical12 (3.5%)
Adjacent Network7 (2.0%)
Attack Complexity
Low254 (73.6%)
High91 (26.4%)
Unknown0 (0.0%)
User Interaction
None286 (82.9%)
Unknown0 (0.0%)
Required59 (17.1%)
Privileges Required
Low110 (31.9%)
High30 (8.7%)
None205 (59.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (345 CVEs).
345 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42013CRITICAL It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directori | Oct 7, 2021 | 9.8 | 99 | YES | YES |
CVE-2021-41773CRITICAL A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories con | Oct 5, 2021 | 9.8 | 99 | YES | YES |
CVE-2021-3156HIGH Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg | Jan 26, 2021 | 7.8 | 99 | YES | YES |
CVE-2021-40438CRITICAL A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | Sep 16, 2021 | 9.0 | 97 | YES | YES |
CVE-2021-22555HIGH A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory | Jul 7, 2021 | 7.8 | 96 | YES | YES |
CVE-2019-2215HIGH A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploi | Oct 11, 2019 | 7.8 | 96 | YES | YES |
CVE-2020-11023MEDIUM In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's | Apr 29, 2020 | 6.1 | 95 | YES | YES |
CVE-2016-5195HIGH Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature | Nov 10, 2016 | 7.0 | 95 | YES | YES |
CVE-2021-44790CRITICAL A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an explo | Dec 20, 2021 | 9.8 | 88 | NO | YES |
CVE-2018-15473MEDIUM OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has be | Aug 17, 2018 | 5.3 | 86 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (345 CVEs).
CISA KEV
8 CVEs
2.3% of CVEs· 96th percentile
Metasploit
6 CVEs
1.7% of CVEs· 96th percentile
Nuclei
5 CVEs
1.4% of CVEs· 96th percentile
ExploitDB
14 CVEs
4.1% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (345 CVEs).
Media Mentions
Signals from CVEs in this product scope (345 CVEs).
Top CNAs Publishing CVEs For Cloud Backup
Top CWEs
Versions
No cataloged versions.