1390 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2023-0192
vGPU software (Virtual GPU Manager - Citrix Hypervisor, VMware vSphere, Red Hat Enterprise Linux KVM), NVIDIA Cloud Gaming (Virtual GPU Manager - Red Hat Enterprise Linux KVM) Networking Cloud Windows
4.7
MEDIUM
EPSS
0.1%
2023 CWE-269 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer handler, where improper privilege management can lead to escalation of privileges and information disclosure.

CVE-2020-6206
SAP Cloud Platform Integration for Data Services Cloud
4.7
MEDIUM
EPSS
0.2%
2020 1 PoC

SAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning massages. This could mislead the victim to follow malicious instructions inserted by external attackers, leading to Cross Site Request Forgery.

CVE-2020-8563
Kubernetes DevOps Cloud
4.7
MEDIUM
EPSS
0.1%
2020 CWE-532 1 PoC

In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the cloud controller manager's log. This affects < v1.19.3.

CVE-2025-30675
Apache CloudStack Web Cloud
4.7
MEDIUM
EPSS
0.4%
2025 CWE-200 1 PoC

In Apache CloudStack, a flaw in access control affects the listTemplates and listIsos APIs. A malicious Domain Admin or Resource Admin can exploit this issue by intentionally specifying the 'domainid' parameter along with the 'filter=self' or 'filter=selfexecutable' values. This allows the attacker to gain unauthorized visibility into templates and ISOs under the ROOT domain. A malicious admin can enumerate and extract metadata of templates and ISOs that belong to unrelated domains, violating isolation boundaries and potentially exposing sensitive or internal configuration details.  This vul

CVE-2021-40837
F-Secure endpoint protection products on Windows and Mac. F-Secure Linux Security (32-bit), F-Secure Linux Security 64, F-Secure Atlant, F-Secure Internet Gatekeeper & F-Secure Security Cloud Cloud Windows
4.6
MEDIUM
EPSS
0.3%
2021 1 PoC

A vulnerability affecting F-Secure antivirus engine before Capricorn update 2022-02-01_01 was discovered whereby decompression of ACE file causes the scanner service to stop. The vulnerability can be exploited remotely by an attacker. A successful attack will result in denial-of-service of the antivirus engine.

CVE-2023-23408
Azure HDInsight Web Cloud
4.5
MEDIUM
EPSS
7.6%
2023 CWE-79 1 PoC

Azure Apache Ambari Spoofing Vulnerability

CVE-2022-42259
vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) Cloud
4.4
MEDIUM
EPSS
0.1%
2022 CWE-190 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to denial of service.

CVE-2022-36329
My Cloud Home and My Cloud Home Duo Cloud
4.4
MEDIUM
EPSS
0.1%
2022 CWE-400 1 PoC

An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices.This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191.

CVE-2020-10773
kernel Cloud
4.4
MEDIUM
EPSS
0.0%
2020 CWE-626 1 PoC

A stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager functionality, where it incorrectly writes to the /proc/sys/vm/cmm_timeout file. This flaw allows a local user to see the kernel data.

CVE-2020-36772
cagefs Cloud
4.4
MEDIUM
EPSS
0.0%
2020 CWE-73 2 PoCs

CloudLinux CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to the sendmail proxy command. This allows local users to read and write arbitrary files of certain file formats outside the CageFS environment.

CVE-2021-23884
McAfee Content Security Reporter (CSR) Cloud
4.3
MEDIUM
EPSS
0.1%
2021 CWE-319 1 PoC

Cleartext Transmission of Sensitive Information vulnerability in the ePO Extension of McAfee Content Security Reporter (CSR) prior to 2.8.0 allows an ePO administrator to view the unencrypted password of the McAfee Web Gateway (MWG) or the password of the McAfee Web Gateway Cloud Server (MWGCS) read only user used to retrieve log files for analysis in CSR.

CVE-2024-3505
Artifactory Self-Hosted Cloud
4.3
MEDIUM
EPSS
0.5%
2024 CWE-200 1 PoC

JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments.

CVE-2024-1098
Rebuild Cloud
4.3
MEDIUM
EPSS
0.2%
2024 CWE-200 2 PoCs

A vulnerability was found in Rebuild up to 3.5.5 and classified as problematic. This issue affects the function QiniuCloud.getStorageFile of the file /filex/proxy-download. The manipulation of the argument url leads to information disclosure. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252455.

CVE-2022-29838
My Cloud Cloud
4.3
MEDIUM
EPSS
0.2%
2022 CWE-287 1 PoC

Improper Authentication vulnerability in the encrypted volumes and auto mount features of Western Digital My Cloud devices allows insecure direct access to the drive information in the case of a device reset. This issue affects: Western Digital My Cloud My Cloud versions prior to 5.25.124 on Linux.

CVE-2020-4315
Business Automation Content Analyzer on Cloud Web Cloud
4.3
MEDIUM
EPSS
0.2%
2020 1 PoC

IBM Business Automation Content Analyzer on Cloud 1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 177234.

CVE-2023-4468
Trio 8500 Cloud
4.3
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

A vulnerability was found in Poly Trio 8500, Trio 8800 and Trio C60. It has been classified as problematic. This affects an unknown part of the component Poly Lens Management Cloud Registration. The manipulation leads to missing authorization. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The identifier VDB-249261 was assigned to this vulnerability.

CVE-2025-22828
Apache CloudStack Web Cloud
4.3
MEDIUM
EPSS
18.4%
2025 CWE-200 1 PoC

CloudStack users can add and read comments (annotations) on resources they are authorised to access.  Due to an access validation issue that affects Apache CloudStack versions from 4.16.0, users who have access, prior access or knowledge of resource UUIDs can list and add comments (annotations) to such resources.  An attacker with a user-account and access or prior knowledge of resource UUIDs may exploit this issue to read contents of the comments (annotations) or add malicious comments (annotations) to such resources.  This may cause potential loss of confidentiality of CloudStack environm

CVE-2019-11206
TIBCO Spotfire Analytics Platform for AWS Marketplace Cloud
4.3
MEDIUM
EPSS
0.3%
2019 1 PoC

The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains vulnerabilities that theoretically allow a malicious user to undermine the integrity of comments and bookmarks. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 10.2.0, and TIBCO Spotfire Server: versions up to and including 7.11.2; 7.12.0; 7.13.0; 7.14.0; 10.0.0; 10.0.1; 10.1.0; and 10.2.0.

CVE-2019-6744
Knox DevOps Cloud
4.3
MEDIUM
EPSS
0.1%
2019 CWE-284 1 PoC

This vulnerability allows local attackers to disclose sensitive information on affected installations of Samsung Knox 1.2.02.39 on Samsung Galaxy S9 build G9600ZHS3ARL1 Secure Folder. An attacker must first obtain physical access to the device in order to exploit this vulnerability. The specific flaws exists within the the handling of the lock screen for Secure Folder. The issue results from the lack of proper validation that a user has correctly authenticated. An attacker can leverage this vulnerability to disclose the contents of the secure container. Was ZDI-CAN-7381.

CVE-2023-6289
Swift Performance Lite Web Cloud Windows
4.3
MEDIUM
EPSS
2.9%
2023 2 PoCs

The Swift Performance Lite WordPress plugin before 2.3.6.15 does not prevent users from exporting the plugin's settings, which may include sensitive information such as Cloudflare API tokens.