CVE-2025-59469Critical· 9.0▾ MidnightThis vulnerability allows a Backup or Tape Operator to write files as root.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 49.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
This vulnerability allows a Backup or Tape Operator to write files as root.
veeam_backup_&_replication >= 13.0.0.4967, < 13.0.1.1071Upgrade past the affected range:
veeam_backup_&_replication 13.0.1.1071Connected by shared product, vendor, weakness, or advisory.
CVE-2025-59470Critical· 9.0This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.
CVE-2025-55125High· 7.8This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.
CVE-2025-59468Critical· 9.0This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.
CVE-2021-25122High· 7.5When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning u…
CVE-2022-31746Medium· 6.5Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header
CVE-2026-32996High· 7.3This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.