urbackup CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

urbackup vulnerability overview

Aggregates CVE and security vulnerability intelligence across all urbackup-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk cross-site scripting and vendor risk memory corruption and related security problems, affecting vendor surface software deployment and vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-47102 UrBackup Server 2.5.31 allows brute-force enumeration of user accounts because a failure message confirms that a username is not valid. [email protected] 5.3 0.26% 2023-11-07 2025-09-29
CVE-2018-20013 In UrBackup 2.2.6, an attacker can send a malformed request to the client over the network, and trigger a fileservplugin/CClientThread.cpp CClientThread::ProcessPacket metadata_id!=0 assertion, leading to shutting down the client application. [email protected] 7.5 0.47% 2019-06-18 2024-11-21
CVE-2018-20014 In UrBackup 2.2.6, an attacker can send a malformed request to the client over the network, and trigger a fileservplugin/CClientThread.cpp CClientThread::GetFileHashAndMetadata NULL pointer dereference, leading to shutting down the client application. [email protected] 7.5 0.47% 2019-06-07 2024-11-21
CVE-2017-16950 Cross - site scripting (XSS) vulnerability in UrBackup Server before 2.1.20 allows remote attackers to inject arbitrary web script or HTML via the action parameter. [email protected] 6.1 0.24% 2017-12-17 2026-05-13
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence