128 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2021-25368
Samsung Cloud Cloud
3.3
LOW
EPSS
0.1%
2021 CWE-287 2 PoCs

Hijacking vulnerability in Samsung Cloud prior to version 4.7.0.3 allows attackers to intercept when the provider is executed.

CVE-2021-25316
SUSE Linux Enterprise Server 12-SP5 Cloud
3.3
LOW
EPSS
0.0%
2021 CWE-377 1 PoC

A Insecure Temporary File vulnerability in s390-tools of SUSE Linux Enterprise Server 12-SP5, SUSE Linux Enterprise Server 15-SP2 allows local attackers to prevent VM live migrations This issue affects: SUSE Linux Enterprise Server 12-SP5 s390-tools versions prior to 2.1.0-18.29.1. SUSE Linux Enterprise Server 15-SP2 s390-tools versions prior to 2.11.0-9.20.1.

CVE-2021-45227
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

An issue was discovered in COINS Construction Cloud 11.12. Due to an inappropriate use of HTML IFRAME elements, the file upload functionality is vulnerable to a persistent Cross-Site Scripting (XSS) attack.

CVE-2021-21980
VMware vCenter Server and VMware Cloud Foundation Cloud
N/A
UNKNOWN
EPSS
7.5%
2021 1 PoC

The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.

CVE-2021-29243
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS.

CVE-2021-43269
Software Genérico Cloud
N/A
UNKNOWN
EPSS
1.1%
2021 2 PoCs

In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config (PAC) file, leading to arbitrary code execution. This affects Incydr Basic, Advanced, and Gov F1; CrashPlan Cloud; and CrashPlan for Small Business. (Incydr Professional and Enterprise are unaffected.)

CVE-2021-24848
Mediamatic – Media Library Folders Web Database Cloud Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 1 PoC

The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authenticated user, does not sanitise the categoryID parameter before using it in a SQL statement, leading to an SQL injection

CVE-2021-21986
VMware vCenter Server and VMware Cloud Foundation Cloud
N/A
UNKNOWN
EPSS
1.5%
2021 1 PoC

The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-ins. A malicious actor with network access to port 443 on vCenter Server may perform actions allowed by the impacted plug-ins without authentication.

CVE-2021-45225
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.4%
2021 3 PoCs

An issue was discovered in COINS Construction Cloud 11.12. Due to improper input neutralization, it is vulnerable to reflected cross-site scripting (XSS) via malicious links (affecting the search window and activity view window).

CVE-2021-24792
Shiny Buttons – CSS3 Button Generator for WordPress Web Cloud Windows
N/A
UNKNOWN
EPSS
12.1%
2021 CWE-79 1 PoC

The Shiny Buttons WordPress plugin through 1.1.0 does not have any authorisation and CSRF in place when saving a template (wpbtn_save_template function hooked to the init action), nor sanitise and escape them before outputting them in the admin dashboard, which allow unauthenticated users to add a malicious template and lead to Stored Cross-Site Scripting issues.

CVE-2021-22008
VMware vCenter Server, VMware Cloud Foundation Web Cloud
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

The vCenter Server contains an information disclosure vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by sending a specially crafted json-rpc message to gain access to sensitive information.

CVE-2021-35508
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

NMSAccess32.exe in TeraRecon AQNetClient 4.4.13 allows attackers to execute a malicious binary with SYSTEM privileges via a low-privileged user account. To exploit this, a low-privileged user must change the service configuration or overwrite the binary service.

CVE-2021-36224
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Western Digital My Cloud devices before OS5 have a nobody account with a blank password.

CVE-2021-22014
VMware vCenter Server, VMware Cloud Foundation Cloud
N/A
UNKNOWN
EPSS
1.2%
2021 1 PoC

The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastructure). An authenticated VAMI user with network access to port 5480 on vCenter Server may exploit this issue to execute code on the underlying operating system that hosts vCenter Server.

CVE-2021-42952
Software Genérico Cloud
N/A
UNKNOWN
EPSS
2.9%
2021 1 PoC

Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability. Upon launching Remote Code Execution from the Notebook, users can then use that to subsequently escape the running context sandbox and proceed to access internal Zepl assets including cloud metadata services.

CVE-2021-45226
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.3%
2021 3 PoCs

An issue was discovered in COINS Construction Cloud 11.12. Due to improper validation of user-controlled HTTP headers, attackers can cause it to send password-reset e-mails pointing to arbitrary websites.

CVE-2021-22011
VMware vCenter Server, VMware Cloud Foundation Web Cloud
N/A
UNKNOWN
EPSS
0.8%
2021 1 PoC

vCenter Server contains an unauthenticated API endpoint vulnerability in vCenter Server Content Library. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to perform unauthenticated VM network setting manipulation.

CVE-2021-22018
VMware vCenter Server, VMware Cloud Foundation Cloud
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to port 9087 on vCenter Server may exploit this issue to delete non critical files.

CVE-2021-42979
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

NoMachine Cloud Server is affected by Integer Overflow. IOCTL Handler 0x22001B in the NoMachine Cloud Server above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

CVE-2021-36696
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in social media links on a user profile due to lack of input validation.