1390 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2024-29974
NAS326 firmware Cloud
9.8
CRITICAL
EPSS
47.6%
2024 CWE-434 2 PoCs

** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute arbitrary code by uploading a crafted configuration file to a vulnerable device.

CVE-2024-45489
Software Genérico Web Cloud
9.8
CRITICAL
EPSS
7.9%
2024 2 PoCs

Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to create or update a boost using another user's ID. This installs the boost in the victim's browser and runs arbitrary Javascript on that browser in a privileged context. NOTE: this is a no-action cloud vulnerability with zero affected users.

CVE-2024-28056
Software Genérico Cloud
9.8
CRITICAL
EPSS
0.8%
2024 1 PoC

Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentication component is removed from an Amplify project, a Condition property is removed but "Effect":"Allow" remains present, and consequently sts:AssumeRoleWithWebIdentity would be available to threat actors with no conditions. Thus, if Amplify CLI had been used to remove the Authentication component from a project built between August 2019 and January 2024, an "assume role" may have occurred, and may have been leveraged to obtain unauthorized access

CVE-2023-4474
NAS326 firmware Cloud
9.8
CRITICAL
EPSS
16.3%
2023 CWE-78 1 PoC

The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

CVE-2023-37265
CasaOS-Gateway Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
91.1%
2023 CWE-306 0 PoCs

CasaOS is an open-source Personal Cloud system. Due to a lack of IP address verification an unauthenticated attackers can execute arbitrary commands as `root` on CasaOS instances. The problem was addressed by improving the detection of client IP addresses in `391dd7f`. This patch is part of CasaOS 0.4.4. Users should upgrade to CasaOS 0.4.4. If they can't, they should temporarily restrict access to CasaOS to untrusted users, for instance by not exposing it publicly.

CVE-2024-48904
Trend Micro Cloud Edge Cloud
9.8
CRITICAL
EPSS
7.2%
2024 2 PoCs

An command injection vulnerability in Trend Micro Cloud Edge could allow a remote attacker to execute arbitrary code on affected appliances. Please note: authentication is not required in order to exploit this vulnerability.

CVE-2023-6553
BackupBliss – Backup & Migration with Free Cloud Storage Web Cloud Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.5%
2023 CWE-94 7 PoCs

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated attackers to easily execute code on the server.

CVE-2021-22005
🔥 KEV VMware vCenter Server, VMware Cloud Foundation Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
2021 16 PoCs

The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.

CVE-2024-21899
QTS Cloud
9.8
CRITICAL
EPSS
11.4%
2024 CWE-287 2 PoCs

An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later

CVE-2023-3197
MStore API – Create Native Android & iOS Apps On The Cloud Web Database Cloud Windows ⚡ nuclei
9.8
CRITICAL
EPSS
32.4%
2023 CWE-89 0 PoCs

The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2025-45814
Software Genérico Cloud
9.8
CRITICAL
EPSS
0.3%
2025 1 PoC

Missing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v7.02.08 allows attackers to execute a session hijacking attack.

CVE-2025-15559
WorkTime (on-prem/cloud) Web Cloud
9.8
CRITICAL
EPSS
0.2%
2025 CWE-78 1 PoC

An unauthenticated attacker can inject OS commands when calling a server API endpoint in NesterSoft WorkTime. The server API call to generate and download the WorkTime client from the WorkTime server is vulnerable in the “guid” parameter. This allows an attacker to execute arbitrary commands on the WorkTime server as NT Authority\SYSTEM with the highest privileges. Attackers are able to access or manipulate sensitive data and take over the whole server.

CVE-2026-30286
Software Genérico Cloud
9.8
CRITICAL
EPSS
0.1%
2026 1 PoC

An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2026011614 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

CVE-2024-29972
NAS326 firmware Web Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
92.7%
2024 CWE-78 4 PoCs

** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

CVE-2023-2734
MStore API – Create Native Android & iOS Apps On The Cloud Web Cloud Windows ⚡ nuclei
9.8
CRITICAL
EPSS
63.1%
2023 CWE-288 0 PoCs

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart sync from mobile REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.

CVE-2024-29973
NAS326 firmware Web Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
94.1%
2024 CWE-78 11 PoCs

** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

CVE-2024-37084
Spring Cloud Data Flow Web Cloud
9.8
CRITICAL
EPSS
83.3%
2024 5 PoCs

In Spring Cloud Data Flow versions prior to 2.11.4,  a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server

CVE-2026-3224
Server Cloud
9.8
CRITICAL
EPSS
0.1%
2026 CWE-287 1 PoC

Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an arbitrary Entra ID user via a forged JSON Web Token (JWT).

CVE-2021-36226
Software Genérico Cloud
9.8
CRITICAL
EPSS
0.2%
2021 1 PoC

Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.

CVE-2023-34362
🔥 KEV Software Genérico Database Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2023 15 PoCs

In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, and execute SQL statements that alter or delete database elements. NOTE: this is exploited in the wild in M