1390 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2025-54793
astro Web Cloud ⚡ nuclei
5.5
MEDIUM
EPSS
1.0%
2025 CWE-601 2 PoCs

Astro is a web framework for content-driven websites. In versions 5.2.0 through 5.12.7, there is an Open Redirect vulnerability in the trailing slash redirection logic when handling paths with double slashes. This allows an attacker to redirect users to arbitrary external domains by crafting URLs such as https://mydomain.com//malicious-site.com/. This increases the risk of phishing and other social engineering attacks. This affects sites that use on-demand rendering (SSR) with the Node or Cloudflare adapters. It does not affect static sites, or sites deployed to Netlify or Vercel. This issue i

CVE-2023-31022
NVIDIA GPU Display driver, vGPU driver, and Cloud gaming driver Cloud Windows
5.5
MEDIUM
EPSS
0.1%
2023 CWE-476 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a NULL-pointer dereference may lead to denial of service.

CVE-2022-42266
vGPU software (guest driver) - Windows, NVIDIA Cloud Gaming (guest driver) Cloud Windows
5.5
MEDIUM
EPSS
0.1%
2022 CWE-200 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an unprivileged regular user can cause exposure of sensitive information to an actor that is not explicitly authorized to have access to that information, which may lead to limited information disclosure.

CVE-2023-30775
libtiff Cloud
5.5
MEDIUM
EPSS
0.1%
2023 CWE-119 1 PoC

A vulnerability was found in the libtiff library. This security flaw causes a heap buffer overflow in extractContigSamples32bits, tiffcrop.c.

CVE-2023-0197
vGPU software (Virtual GPU Manager - Citrix Hypervisor, VMware vSphere, Red Hat Enterprise Linux KVM), NVIDIA Cloud Gaming (Virtual GPU Manager - Red Hat Enterprise Linux KVM) Networking Cloud
5.5
MEDIUM
EPSS
0.1%
2023 CWE-476 1 PoC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious user in a guest VM can cause a NULL-pointer dereference, which may lead to denial of service.

CVE-2021-33602
F-Secure endpoint protection products on Windows and Mac. F-Secure Linux Security (32-bit) F-Secure Linux Security 64 F-Secure Atlant & F-Secure Cloud Protection for Salesforce Cloud Windows
5.5
MEDIUM
EPSS
0.3%
2021 1 PoC

A vulnerability affecting the F-Secure Antivirus engine was discovered when the engine tries to unpack a zip archive (LZW decompression method), and this can crash the scanning engine. The vulnerability can be exploited remotely by an attacker. A successful attack will result in Denial-of-Service of the Anti-Virus engine.

CVE-2022-34677
vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) Cloud
5.5
MEDIUM
EPSS
0.0%
2022 CWE-125 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause an integer to be truncated, which may lead to denial of service or data tampering.

CVE-2023-31023
NVIDIA GPU Display driver, vGPU driver, and Cloud gaming driver Cloud Windows
5.5
MEDIUM
EPSS
0.0%
2023 CWE-822 1 PoC

NVIDIA Display Driver for Windows contains a vulnerability where an attacker may cause a pointer dereference of an untrusted value, which may lead to denial of service.

CVE-2022-46087
Software Genérico Web Cloud
5.4
MEDIUM
EPSS
0.5%
2022 2 PoCs

CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through notification received by the admin user.

CVE-2026-24069
SAST Cloud
5.4
MEDIUM
EPSS
0.0%
2026 CWE-863 2 PoCs

Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to continue accessing the application. Kiuwan Cloud was affected, and Kiuwan SAST on-premise (KOP) was affected before 2.8.2509.4.

CVE-2024-51026
Software Genérico Web Cloud
5.4
MEDIUM
EPSS
1.0%
2024 1 PoC

The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious payload into the Content= field.

CVE-2023-33829
Software Genérico Web Cloud
5.4
MEDIUM
EPSS
2.9%
2023 6 PoCs

A stored cross-site scripting (XSS) vulnerability in Cloudogu GmbH SCM Manager v1.2 to v1.60 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description text field.

CVE-2022-32167
Cloudreve Web Cloud
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cloudreve versions v1.0.0 through v3.5.3 are vulnerable to Stored Cross-Site Scripting (XSS), via the file upload functionality. A low privileged user will be able to share a file with an admin user, which could lead to privilege escalation.

CVE-2023-3588
Teamwork Cloud - Business Edition Web Cloud
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

A stored Cross-site Scripting (XSS) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x allows an attacker to execute arbitrary script code.

CVE-2020-6200
SAP Commerce Cloud (SmartEdit Extension) Web Cloud
5.4
MEDIUM
EPSS
0.4%
2020 1 PoC

The SAP Commerce (SmartEdit Extension), versions- 6.6, 6.7, 1808, 1811, is vulnerable to client-side angularjs template injection, a variant of Cross-Site-Scripting (XSS) that exploits the templating facilities of the angular framework.

CVE-2020-14787
Communications Diameter Signaling Router (DSR) Web Networking Database Cloud
5.4
MEDIUM
EPSS
0.2%
2020 1 PoC

Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: User Interface). Supported versions that are affected are 8.0.0.0-8.4.0.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router (DSR). Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Diameter Signaling Router (DSR), attacks may significantly impact additional products. Successful attack

CVE-2025-36094
Cloud Pak for Business Automation Cloud
5.4
MEDIUM
EPSS
0.1%
2025 CWE-1284 1 PoC

IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007 could allow an authenticated user to cause a denial of service or corrupt existing data due to the improper validation of input length.

CVE-2025-3230
Mattermost Cloud
5.4
MEDIUM
EPSS
0.2%
2025 CWE-303 1 PoC

Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon user deactivation, allowing deactivated users to maintain full system access by exploiting access token validation flaws via continued usage of previously issued tokens.

CVE-2023-32751
Software Genérico Web Cloud
5.4
MEDIUM
EPSS
1.0%
2023 2 PoCs

Pydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are generated using the Amazon AWS SDK for JavaScript [1]. The secrets used to sign these URLs are hardcoded and exposed through the JavaScript files of the web application. Therefore, it is possible to generate valid signatures for arbitrary download URLs. By uploading an HTML file and modifying the download URL to serve the file inline instead of as an attachment, any included JavaScript code is executed when the URL is opened in a browser, leading to a cross-site scripting vulnerabi

CVE-2023-28628
uri Web Cloud
5.4
MEDIUM
EPSS
0.2%
2023 CWE-706 1 PoC

lambdaisland/uri is a pure Clojure/ClojureScript URI library. In versions prior to 1.14.120 `authority-regex` allows an attacker to send malicious URLs to be parsed by the `lambdaisland/uri` and return the wrong authority. This issue is similar to but distinct from CVE-2020-8910. The regex in question doesn't handle the backslash (`\`) character in the username correctly, leading to a wrong output. ex. a payload of `https://example.com\\@google.com` would return that the host is `google.com`, but the correct host should be `example.com`. Given that the library returns the wrong authority this