610 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2024-52510
security-advisories Cloud
4.2
MEDIUM
EPSS
0.5%
2024 CWE-295 1 PoC

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that the Nextcloud Desktop client is upgraded to 3.14.2 or later.

CVE-2021-2257
Cloud Infrastructure Web Database Cloud
4.1
MEDIUM
EPSS
0.2%
2021 3 PoCs

Vulnerability in the Oracle Storage Cloud Software Appliance product of Oracle Storage Gateway (component: Management Console). The supported version that is affected is Prior to 16.3.1.4.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Storage Cloud Software Appliance. While the vulnerability is in Oracle Storage Cloud Software Appliance, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Storage Cloud Software Appliance

CVE-2017-7497
CFME Cloud
4.1
MEDIUM
EPSS
0.1%
2017 CWE-284 1 PoC

The dialog for creating cloud volumes (cinder provider) in CloudForms does not filter cloud tenants by user. An attacker with the ability to create storage volumes could use this to create storage volumes for any other tenant.

CVE-2022-29839
My Cloud Cloud
4.1
MEDIUM
EPSS
0.1%
2022 CWE-522 1 PoC

Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker who has gained access to a relevant endpoint to use that information to access protected data. This issue affects: Western Digital My Cloud My Cloud versions prior to 5.25.124 on Linux.

CVE-2022-28192
NVIDIA Virtual GPU Software and NVIDIA Cloud Gaming Cloud
4.1
MEDIUM
EPSS
0.1%
2022 CWE-416 1 PoC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where it may lead to a use-after-free, which in turn may cause denial of service. This attack is complex to carry out because the attacker needs to have control over freeing some host side resources out of sequence, which requires elevated privileges.

CVE-2023-21447
Samsung Cloud Cloud
4.0
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper access control vulnerabilities in Samsung Cloud prior to version 5.3.0.32 allows local attackers to access information with Samsung Cloud's privilege via implicit intent.

CVE-2022-39869
SmartThings Cloud
4.0
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via REMOVE_PERSISTENT_BANNER broadcast.

CVE-2022-39867
SmartThings Cloud
4.0
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via SHOW_PERSISTENT_BANNER broadcast.

CVE-2022-39871
SmartThings Cloud
4.0
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcasts.

CVE-2022-39870
SmartThings Cloud
4.0
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via PUSH_MESSAGE_RECEIVED broadcast.