610 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2022-42054
Software Genérico Web Cloud
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

Multiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Company Name and Description text fields.

CVE-2022-46087
Software Genérico Web Cloud
5.4
MEDIUM
EPSS
0.5%
2022 2 PoCs

CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through notification received by the admin user.

CVE-2026-4171
serverless-express Web Cloud
5.3
MEDIUM
EPSS
0.0%
2026 CWE-639 1 PoC

A security vulnerability has been detected in CodeGenieApp serverless-express up to 4.17.1. Affected by this issue is some unknown functionality of the file examples/lambda-function-url/packages/api/models/TodoList.ts of the component API Endpoint. The manipulation of the argument userId leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-2561
JD Cloud Box AX6600 Web Cloud
5.3
MEDIUM
EPSS
0.2%
2026 CWE-269 1 PoC

A vulnerability was found in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. This affects the function web_get_ddns_uptime of the file /jdcapi of the component jdcweb_rpc. Performing a manipulation results in Remote Privilege Escalation. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-1548
A7000R Cloud
5.3
MEDIUM
EPSS
0.5%
2026 CWE-77 1 PoC

A flaw has been found in Totolink A7000R 4.1cu.4154. This impacts the function CloudACMunualUpdateUserdata of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument url causes command injection. The attack can be initiated remotely. The exploit has been published and may be used.

CVE-2023-47529
Cloud Templates & Patterns collection Cloud
5.3
MEDIUM
EPSS
3.4%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ThemeIsle Cloud Templates & Patterns collection.This issue affects Cloud Templates & Patterns collection: from n/a through 1.2.2.

CVE-2023-6341
CMS360 Web Cloud
5.3
MEDIUM
EPSS
0.9%
2023 CWE-639 1 PoC

Catalis (previously Icon Software) CMS360 allows a remote, unauthenticated attacker to view sensitive court documents by modifying document and other identifiers in URLs. The impact varies based on the intention and configuration of a specific CMS360 installation.

CVE-2023-31416
Elastic Cloud on Kubernetes DevOps Cloud
5.3
MEDIUM
EPSS
0.2%
2023 CWE-200 1 PoC

Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment.

CVE-2024-11054
Simple Music Cloud Community System Web Cloud
5.3
MEDIUM
EPSS
0.1%
2024 CWE-434 1 PoC

A vulnerability classified as critical was found in SourceCodester Simple Music Cloud Community System 1.0. This vulnerability affects unknown code of the file /music/ajax.php?action=signup. The manipulation of the argument pp leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-11662
OpsManage Web Cloud
5.3
MEDIUM
EPSS
0.1%
2024 CWE-502 1 PoC

A vulnerability was found in welliamcao OpsManage 3.0.1/3.0.2/3.0.3/3.0.4/3.0.5. It has been rated as critical. This issue affects the function deploy_host_vars of the file /apps/api/views/deploy_api.py of the component API Endpoint. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-8129
DNS-120 Web Cloud
5.3
MEDIUM
EPSS
16.8%
2024 CWE-77 1 PoC

A vulnerability, which was classified as critical, was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. Affected is the function cgi_s3_modify of the file /cgi-bin/s3.cgi of the component HTTP POST Request Handler. The manipulation of the argument f_job_name leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerab

CVE-2024-33892
Software Genérico Cloud
5.3
MEDIUM
EPSS
0.2%
2024 1 PoC

Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. This is fixed in version 21.2s10 and 22.1s3

CVE-2024-55069
Software Genérico Cloud
5.3
MEDIUM
EPSS
0.3%
2024 1 PoC

ffmpeg 7.1 is vulnerable to Null Pointer Dereference in function iamf_read_header in /libavformat/iamfdec.c.

CVE-2019-17335
TIBCO Spotfire Analytics Platform for AWS Marketplace Cloud
5.3
MEDIUM
EPSS
0.3%
2019 1 PoC

The Data access layer component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains multiple vulnerabilities that theoretically allow an attacker access to data cached from a data source, or a portion of a data source, that the attacker should not have access to. The attacker would need privileges to save a Spotfire file to the library. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: version 10.6.0 and TIBCO Spotfire Server: versions 7.11.7 and below, versions 7.12.0, 7.13.0, 7.14.0

CVE-2019-25337
OwnCloud Web Cloud
5.3
MEDIUM
EPSS
0.2%
2019 CWE-203 1 PoC

OwnCloud 8.1.8 contains a username enumeration vulnerability that allows remote attackers to discover user accounts by manipulating the share.php endpoint. Attackers can send crafted GET requests to /index.php/core/ajax/share.php with a wildcard search parameter to retrieve comprehensive user information.

CVE-2021-21973
🔥 KEV VMware vCenter Server Cloud ⚡ nuclei
5.3
MEDIUM
EPSS
90.4%
2021 1 PoC

The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).

CVE-2021-22017
🔥 KEV VMware vCenter Server, VMware Cloud Foundation Web Cloud ⚡ nuclei
5.3
MEDIUM
EPSS
74.8%
2021 1 PoC

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.

CVE-2017-20221
SDT-CS3B1 Web Networking Cloud
5.3
MEDIUM
EPSS
0.0%
2017 CWE-352 3 PoCs

Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains a cross-site request forgery vulnerability that allows authenticated attackers to execute arbitrary system commands by exploiting missing request validation. Attackers can craft malicious web pages that perform administrative actions when visited by logged-in users, enabling command execution with router privileges.

CVE-2025-59716
Software Genérico Cloud ⚡ nuclei
5.3
MEDIUM
EPSS
0.7%
2025 0 PoCs

ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of insufficient validation of the supplied token in showPasswordForm, the server responds differently when an e-mail address corresponds to a valid pending guest user rather than a non-existent user.

CVE-2025-10626
Online Exam Form Submission Web Database Cloud
5.3
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A flaw has been found in SourceCodester Online Exam Form Submission 1.0. Affected by this issue is some unknown functionality of the file /admin/update_s3.php. This manipulation of the argument credits causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.