1390 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2007-2244
Software Genérico Cloud
N/A
UNKNOWN
EPSS
21.8%
2007 1 PoC

Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) BMP, (2) DIB, or (3) RLE file.

CVE-2014-7617
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2014 2 PoCs

The www.roads365.com (aka ydx.android) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2013-2050
Software Genérico Database Cloud
N/A
UNKNOWN
EPSS
54.2%
2013 1 PoC

SQL injection vulnerability in the miq_policy controller in Red Hat CloudForms 2.0 Management Engine (CFME) 5.1 and ManageIQ Enterprise Virtualization Manager 5.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the profile[] parameter in an explorer action.

CVE-2021-3178
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8, when there is an NFS export of a subdirectory of a filesystem, allows remote attackers to traverse to other parts of the filesystem via READDIRPLUS. NOTE: some parties argue that such a subdirectory export is not intended to prevent this attack; see also the exports(5) no_subtree_check default behavior

CVE-2021-22053
Spring Cloud Netflix Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
89.6%
2021 CWE-94 2 PoCs

Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within the request URI path during the resolution of view templates. When a request is made at `/hystrix/monitor;[user-provided data]`, the path elements following `hystrix/monitor` are being evaluated as SpringEL expressions, which can lead to code execution.

CVE-2021-45223
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.5%
2021 3 PoCs

An issue was discovered in COINS Construction Cloud 11.12. Due to insufficient input neutralization, it is vulnerable to denial of service attacks via forced server crashes.

CVE-2021-3310
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
1.1%
2021 2 PoCs

Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code execution and information disclosure (by reading local files).

CVE-2021-38112
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
17.7%
2021 1 PoC

In the Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows, argument injection in the workspaces:// URI handler can lead to remote code execution because of the Chromium Embedded Framework (CEF) --gpu-launcher argument. This is fixed in 3.1.9.

CVE-2021-31583
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.9%
2021 3 PoCs

Sipwise C5 NGCP WWW Admin version 3.6.7 up to and including platform version NGCP CE 3.0 has multiple authenticated stored and reflected XSS vulnerabilities when input passed via several parameters to several scripts is not properly sanitized before being returned to the user: Stored XSS in callforward/time/set/save (POST tsetname); Reflected XSS in addressbook (GET filter); Stored XSS in addressbook/save (POST firstname, lastname, company); and Reflected XSS in statistics/versions (GET lang).

CVE-2013-4097
Software Genérico Cloud
N/A
UNKNOWN
EPSS
5.3%
2013 1 PoC

ServerAdmin/TestDRConnection.jsp in DS3 Authentication Server allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in a -REG-E-OPEN error message.

CVE-2021-24392
WordPress Membership SwiftCloud.io Web Database Cloud Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

An id GET parameter of the WordPress Membership SwiftCloud.io WordPress plugin through 1.0 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

CVE-2021-45224
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.4%
2021 3 PoCs

An issue was discovered in COINS Construction Cloud 11.12. In several locations throughout the application, JavaScript code is passed as a URL parameter. Attackers can trivially alter this code to cause malicious behaviour. The application is therefore vulnerable to reflected XSS via malicious URLs.

CVE-2021-22016
VMware vCenter Server, VMware Cloud Foundation Web Cloud
N/A
UNKNOWN
EPSS
1.2%
2021 1 PoC

The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attacker may exploit this issue to execute malicious scripts by tricking a victim into clicking a malicious link.

CVE-2014-6737
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2014 2 PoCs

The Ultimate Target-Armored Sniper (aka air.wood.liame.ultimatetarget) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2013-4098
Software Genérico Cloud
N/A
UNKNOWN
EPSS
4.9%
2013 1 PoC

ServerAdmin/ErrorViewer.jsp in DS3 Authentication Server allow remote attackers to inject arbitrary error-page text via the message parameter.

CVE-2021-4160
OpenSSL Cloud
N/A
UNKNOWN
EPSS
0.4%
2021 2 PoCs

There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including some of the TLS 1.3 default curves. Impact was not analyzed in detail, because the pre-requisites for attack are considered unlikely and include reusing private keys. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed of

CVE-2021-22007
VMware vCenter Server, VMware Cloud Foundation Cloud
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The vCenter Server contains a local information disclosure vulnerability in the Analytics service. An authenticated user with non-administrative privilege may exploit this issue to gain access to sensitive information.

CVE-2021-22019
VMware vCenter Server, VMware Cloud Foundation Web Cloud
N/A
UNKNOWN
EPSS
1.5%
2021 1 PoC

The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 5480 on vCenter Server may exploit this issue by sending a specially crafted jsonrpc message to create a denial of service condition.

CVE-2023-22957
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.4%
2023 4 PoCs

An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attacker with access to backup or configuration files is able to decrypt encrypted values and retrieve sensitive information, e.g., the device root password.

CVE-2021-45228
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

An XSS issue was discovered in COINS Construction Cloud 11.12. Due to insufficient neutralization of user input in the description of a task, it is possible to store malicious JavaScript code in the task description. This is later executed when it is reflected back to the user.