114 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2023-32707
Splunk Enterprise Cloud
8.8
HIGH
EPSS
82.7%
2023 CWE-285 3 PoCs

In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who holds a role that has the ‘edit_user’ capability assigned to it can escalate their privileges to that of the admin user by providing specially crafted web requests.

CVE-2023-37928
NAS326 firmware Cloud
8.8
HIGH
EPSS
2.1%
2023 CWE-78 1 PoC

A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an authenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

CVE-2023-0189
vGPU software (guest driver - Linux), NVIDIA Cloud Gaming (guest driver - Linux) Cloud
8.8
HIGH
EPSS
0.2%
2023 CWE-822 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2023-37927
NAS326 firmware Cloud
8.8
HIGH
EPSS
1.0%
2023 CWE-78 1 PoC

The improper neutralization of special elements in the CGI program of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an authenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

CVE-2023-46526
Software Genérico Cloud
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function resetCloudPwdRegister.

CVE-2023-1306
InsightCloudSec Cloud
8.8
HIGH
EPSS
0.6%
2023 CWE-94 1 PoC

An authenticated attacker can leverage an exposed resource.db() accessor method to smuggle Python method calls via a Jinja template, which can lead to code execution. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.

CVE-2023-1304
InsightCloudSec Cloud
8.8
HIGH
EPSS
0.5%
2023 CWE-94 1 PoC

An authenticated attacker can leverage an exposed getattr() method via a Jinja template to smuggle OS commands and perform other actions that are normally expected to be private methods. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.

CVE-2023-2845
cloudexplorer-dev/cloudexplorer-lite Cloud
8.8
HIGH
EPSS
0.1%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0.

CVE-2023-30350
Software Genérico Cloud
8.8
HIGH
EPSS
3.3%
2023 1 PoC

FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin password.

CVE-2023-6017
h2oai/h2o-3 Cloud
8.7
HIGH
EPSS
0.2%
2023 CWE-840 1 PoC

H2O included a reference to an S3 bucket that no longer existed allowing an attacker to take over the S3 bucket URL.

CVE-2023-6263
NxCloud Cloud
8.3
HIGH
EPSS
0.2%
2023 CWE-290 1 PoC

An issue was discovered by IPVM team in Network Optix NxCloud before 23.1.0.40440. It was possible to add a fake VMS server to NxCloud by using the exact identification of a legitimate VMS server. As result, it was possible to retrieve authorization headers from legitimate users when the legitimate client connects to the fake VMS server.

CVE-2023-31027
NVIDIA GPU Display driver, vGPU driver, and Cloud gaming driver Cloud Windows
8.2
HIGH
EPSS
0.0%
2023 CWE-427 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability that allows Windows users with low levels of privilege to escalate privileges when an administrator is updating GPU drivers, which may lead to escalation of privileges.

CVE-2023-42442
jumpserver Web Cloud ⚡ nuclei
8.2
HIGH
EPSS
88.2%
2023 CWE-287 2 PoCs

JumpServer is an open source bastion host and a professional operation and maintenance security audit system. Starting in version 3.0.0 and prior to versions 3.5.5 and 3.6.4, session replays can download without authentication. Session replays stored in S3, OSS, or other cloud storage are not affected. The api `/api/v1/terminal/sessions/` permission control is broken and can be accessed anonymously. SessionViewSet permission classes set to `[RBACPermission | IsSessionAssignee]`, relation is or, so any permission matched will be allowed. Versions 3.5.5 and 3.6.4 have a fix. After upgrading, vis

CVE-2023-22893
Software Genérico Web Cloud ⚡ nuclei
8.2
HIGH
EPSS
76.7%
2023 2 PoCs

Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for authentication. A remote attacker could forge an ID token that is signed using the 'None' type algorithm to bypass authentication and impersonate any user that use AWS Cognito for authentication.

CVE-2023-1305
InsightCloudSec Cloud
8.1
HIGH
EPSS
0.3%
2023 CWE-653 1 PoC

An authenticated attacker can leverage an exposed “box” object to read and write arbitrary files from disk, provided those files can be parsed as yaml or JSON. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.

CVE-2023-0391
CloudPanel Cloud
8.1
HIGH
EPSS
0.2%
2023 CWE-321 2 PoCs

MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, shared across every installation of CloudPanel. This behavior was observed in version 2.2.0. There has been no indication from the vendor this has been addressed in version 2.2.1.

CVE-2023-31017
NVIDIA GPU Display driver, vGPU driver, and Cloud gaming driver Cloud Windows
7.8
HIGH
EPSS
0.0%
2023 CWE-552 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may be able to write arbitrary data to privileged locations by using reparse points. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

CVE-2023-31019
NVIDIA GPU Display driver, vGPU driver, and Cloud gaming driver Cloud Windows
7.8
HIGH
EPSS
0.0%
2023 CWE-284 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in wksServicePlugin.dll, where the driver implementation does not restrict or incorrectly restricts access from the named pipe server to a connecting client, which may lead to potential impersonation to the client's secure context.

CVE-2023-0182
vGPU software (guest driver - Windows), NVIDIA Cloud Gaming (guest driver - Windows) Cloud Windows
7.8
HIGH
EPSS
0.1%
2023 CWE-787 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an out-of-bounds write can lead to denial of service, information disclosure, and data tampering.