Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Vinchin

First CVE: Aug 3, 2022Active for: 4 yearsTotal CVEs: 9

Vinchin is a backup-and-recovery vendor whose vulnerability footprint concentrates in its core backup product, where disclosures skew strongly toward critical-severity outcomes and have an elevated tendency to acquire public exploit code. The recurring weakness classes—command injection, hard-coded credentials, and code injection—reflect the code-execution risk inherent to administrative backup software that often runs with high privilege and processes untrusted data. Defenders should treat this vendor's advisories as high-priority for any instances managing production data; live exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
9.4
Avg CVSS Score
Higher Avg CVSS Score than 90% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Vinchin over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 3, 2022
3 years ago
Most Recent CVE
Mar 14, 2024
862 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-45498CRITICAL
VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability.
Oct 27, 20239.851NOYES
CVE-2023-45499CRITICAL
VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials.
Oct 27, 20239.846NOYES
CVE-2024-25228HIGH
Vinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerifydiyResult function in ManoeuvreHandler.class.php.
Mar 14, 20248.835NONO
CVE-2024-22902CRITICAL
Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.
Feb 2, 20249.832NONO
CVE-2022-35866CRITICAL
This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery 6.5.0.17561. Authentication is not required to exploit
Aug 3, 20229.830NONO
CVE-2024-22903HIGH
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.
Feb 2, 20248.829NONO
CVE-2024-22900HIGH
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function.
Feb 2, 20248.827NONO
CVE-2024-22901CRITICAL
Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.
Feb 2, 20249.826NONO
CVE-2024-22899HIGH
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.
Feb 2, 20248.824NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
44%
56%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (44.4%)
High0 (0.0%)
None5 (55.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
22.2% of CVEs· 99th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Vinchin.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Vinchin — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Vinchin's Products

View all 2 CNAs →

Top CWEs