106 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2024-33895
Software Genérico Cloud
6.6
MEDIUM
EPSS
0.4%
2024 1 PoC

Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is fixed in version 21.2s10 and 22.1s3, the key is now unique per device.

CVE-2024-44765
Software Genérico Cloud
6.5
MEDIUM
EPSS
2.7%
2024 2 PoCs

An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH CloudPanel v2.0.0 to v2.4.2 allows low-privilege users to bypass access controls and gain unauthorized access to sensitive configuration files and administrative functionality.

CVE-2024-0078
GPU Display driver, vGPU driver, Cloud Gaming driver Cloud Windows
6.5
MEDIUM
EPSS
0.0%
2024 CWE-476 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user in a guest can cause a NULL-pointer dereference in the host, which may lead to denial of service.

CVE-2024-55466
Software Genérico Cloud
6.5
MEDIUM
EPSS
0.4%
2024 1 PoC

An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1 allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2024-0093
vGPU software and Cloud Gaming Cloud
6.5
MEDIUM
EPSS
0.2%
2024 CWE-200 1 PoC

NVIDIA GPU software for Linux contains a vulnerability where it can expose sensitive information to an actor that is not explicitly authorized to have access to that information. A successful exploit of this vulnerability might lead to information disclosure.

CVE-2024-0079
vGPU driver, Cloud Gaming driver Cloud Windows
6.5
MEDIUM
EPSS
0.0%
2024 CWE-476 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user in a guest VM can cause a NULL-pointer dereference in the host. A successful exploit of this vulnerability may lead to denial of service.

CVE-2024-28275
Software Genérico Cloud
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Puwell Cloud Tech Co, Ltd 360Eyes Pro v3.9.5.16(3090516) was discovered to transmit sensitive information in cleartext. This vulnerability allows attackers to intercept and access sensitive information, including users' credentials and password change requests.

CVE-2024-2466
curl Web Cloud
6.5
MEDIUM
EPSS
0.1%
2024 3 PoCs

libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc).

CVE-2024-53614
Software Genérico Cloud
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

A hardcoded decryption key in Thinkware Cloud APK v4.3.46 allows attackers to access sensitive data and execute arbitrary commands with elevated privileges.

CVE-2024-45736
Splunk Enterprise Web Cloud
6.5
MEDIUM
EPSS
0.1%
2024 CWE-400 1 PoC

In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2312.204, and 9.1.2312.111, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a search query with an improperly formatted "INGEST_EVAL" parameter as part of a [Field Transformation](https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Managefieldtransforms) which could crash the Splunk daemon (splunkd).

CVE-2024-9379
🔥 KEV CSA (Cloud Services Appliance) Database Cloud
6.5
MEDIUM
EPSS
81.7%
2024 CWE-89 1 PoC

SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

CVE-2024-45589
Software Genérico Web Cloud
6.5
MEDIUM
EPSS
7.8%
2024 2 PoCs

RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote attacker to cause a denial of service via the username parameters.

CVE-2024-29976
NAS326 firmware Cloud
6.5
MEDIUM
EPSS
5.7%
2024 CWE-269 2 PoCs

** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the command “show_allsessions” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an authenticated attacker to obtain a logged-in administrator’s session information containing cookies on an affected device.

CVE-2024-0085
vGPU software and Cloud Gaming Cloud Windows
6.3
MEDIUM
EPSS
0.1%
2024 CWE-266 1 PoC

NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged operations on the host. A successful exploit of this vulnerability might lead to data tampering, escalation of privileges, and denial of service.

CVE-2024-9513
NetAdmin IAM Web Cloud
6.3
MEDIUM
EPSS
13.6%
2024 CWE-203 1 PoC

A vulnerability was found in Netadmin Software NetAdmin IAM up to 3.5 and classified as problematic. Affected by this issue is some unknown functionality of the file /controller/api/Answer/ReturnUserQuestionsFilled of the component HTTP POST Request Handler. The manipulation of the argument username leads to information exposure through discrepancy. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure is planni

CVE-2024-36986
Splunk Enterprise Cloud
6.3
MEDIUM
EPSS
0.3%
2024 CWE-200 1 PoC

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, an authenticated user could run risky commands using the permissions of a higher-privileged user to bypass SPL safeguards for risky commands in the Analytics Workspace. The vulnerability requires the authenticated user to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will.

CVE-2024-57423
Software Genérico Web Cloud
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

A Cross Site Scripting vulnerability in CloudClassroom-PHP Project v1.0 allows a remote attacker to execute arbitrary code via the exid parameter of the assessment function.

CVE-2024-22550
Software Genérico Cloud
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

An arbitrary file upload vulnerability in the component /alsdemo/ss/mediam.cgi of ShopSite v14.0 allows attackers to execute arbitrary code via uploading a crafted SVG file.

CVE-2024-0075
GPU Display driver, vGPU driver, Cloud Gaming driver Cloud Windows
6.1
MEDIUM
EPSS
0.1%
2024 CWE-476 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user may cause a NULL-pointer dereference by accessing passed parameters the validity of which has not been checked. A successful exploit of this vulnerability may lead to denial of service and limited information disclosure.

CVE-2024-13865
S3Player Web Cloud Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The S3Player WordPress plugin through 4.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.