610 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2024-45589
Software Genérico Web Cloud
6.5
MEDIUM
EPSS
7.8%
2024 2 PoCs

RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote attacker to cause a denial of service via the username parameters.

CVE-2024-0093
vGPU software and Cloud Gaming Cloud
6.5
MEDIUM
EPSS
0.2%
2024 CWE-200 1 PoC

NVIDIA GPU software for Linux contains a vulnerability where it can expose sensitive information to an actor that is not explicitly authorized to have access to that information. A successful exploit of this vulnerability might lead to information disclosure.

CVE-2024-44765
Software Genérico Cloud
6.5
MEDIUM
EPSS
2.7%
2024 2 PoCs

An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH CloudPanel v2.0.0 to v2.4.2 allows low-privilege users to bypass access controls and gain unauthorized access to sensitive configuration files and administrative functionality.

CVE-2024-2466
curl Web Cloud
6.5
MEDIUM
EPSS
0.1%
2024 3 PoCs

libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc).

CVE-2024-55466
Software Genérico Cloud
6.5
MEDIUM
EPSS
0.4%
2024 1 PoC

An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1 allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2024-53614
Software Genérico Cloud
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

A hardcoded decryption key in Thinkware Cloud APK v4.3.46 allows attackers to access sensitive data and execute arbitrary commands with elevated privileges.

CVE-2024-45736
Splunk Enterprise Web Cloud
6.5
MEDIUM
EPSS
0.1%
2024 CWE-400 1 PoC

In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2312.204, and 9.1.2312.111, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a search query with an improperly formatted "INGEST_EVAL" parameter as part of a [Field Transformation](https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Managefieldtransforms) which could crash the Splunk daemon (splunkd).

CVE-2024-29976
NAS326 firmware Cloud
6.5
MEDIUM
EPSS
5.7%
2024 CWE-269 2 PoCs

** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the command “show_allsessions” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an authenticated attacker to obtain a logged-in administrator’s session information containing cookies on an affected device.

CVE-2024-0078
GPU Display driver, vGPU driver, Cloud Gaming driver Cloud Windows
6.5
MEDIUM
EPSS
0.0%
2024 CWE-476 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user in a guest can cause a NULL-pointer dereference in the host, which may lead to denial of service.

CVE-2024-9379
🔥 KEV CSA (Cloud Services Appliance) Database Cloud
6.5
MEDIUM
EPSS
81.7%
2024 CWE-89 1 PoC

SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

CVE-2024-28275
Software Genérico Cloud
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Puwell Cloud Tech Co, Ltd 360Eyes Pro v3.9.5.16(3090516) was discovered to transmit sensitive information in cleartext. This vulnerability allows attackers to intercept and access sensitive information, including users' credentials and password change requests.

CVE-2024-0079
vGPU driver, Cloud Gaming driver Cloud Windows
6.5
MEDIUM
EPSS
0.0%
2024 CWE-476 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user in a guest VM can cause a NULL-pointer dereference in the host. A successful exploit of this vulnerability may lead to denial of service.

CVE-2019-8988
TIBCO Data Science for AWS Web Cloud
6.5
MEDIUM
EPSS
0.2%
2019 1 PoC

The application server component of TIBCO Software Inc.'s TIBCO Data Science for AWS, and TIBCO Spotfire Data Science contains a persistent cross-site contains a vulnerability that theoretically allows a user to escalate their privileges on the affected system, in a way that may allow for data modifications and deletions that should be denied. Affected releases are TIBCO Software Inc.'s TIBCO Data Science for AWS: versions up to and including 6.4.0, and TIBCO Spotfire Data Science: versions up to and including 6.4.0.

CVE-2021-40186
DNN Platform Web Networking Cloud
6.5
MEDIUM
EPSS
0.3%
2021 CWE-918 1 PoC

The AppCheck research team identified a Server-Side Request Forgery (SSRF) vulnerability within the DNN CMS platform, formerly known as DotNetNuke. SSRF vulnerabilities allow the attacker to exploit the target system to make network requests on their behalf, allowing a range of possible attacks. In the most common scenario, the attacker exploits SSRF vulnerabilities to attack systems behind the firewall and access sensitive information from Cloud Provider metadata services.

CVE-2025-50867
Software Genérico Web Database Cloud
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

A SQL Injection vulnerability exists in the takeassessment2.php endpoint of the CloudClassroom-PHP-Project 1.0, where the Q5 POST parameter is directly embedded in SQL statements without sanitization.

CVE-2025-44608
Software Genérico Web Database Cloud
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

CloudClassroom-PHP Project v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter.

CVE-2025-60682
Software Genérico Web Networking Cloud
6.5
MEDIUM
EPSS
0.7%
2025 1 PoC

A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the cloudupdate_check binary, specifically in the sub_402414 function that handles cloud update parameters. User-supplied 'magicid' and 'url' values are directly concatenated into shell commands and executed via system() without any sanitization or escaping. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device.

CVE-2025-25469
Software Genérico Cloud
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/iamf.c.

CVE-2025-15574
Pocket WiFi 3.0 Cloud
6.5
MEDIUM
EPSS
0.0%
2025 CWE-330 1 PoC

When connecting to the Solax Cloud MQTT server the username is the "registration number", which is the 10 character string printed on the SolaX Power Pocket device / the QR code on the device. The password is derived from the "registration number" using a proprietary XOR/transposition algorithm. Attackers with the knowledge of the registration numbers can connect to the MQTT server and impersonate the dongle / inverters.

CVE-2025-25953
Software Genérico Cloud
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 was discovered to contain an Azure JWT access token exposure. This vulnerability allows authenticated attackers to escalate privileges and access sensitive information.