1390 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2021-45226
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.3%
2021 3 PoCs

An issue was discovered in COINS Construction Cloud 11.12. Due to improper validation of user-controlled HTTP headers, attackers can cause it to send password-reset e-mails pointing to arbitrary websites.

CVE-2021-22018
VMware vCenter Server, VMware Cloud Foundation Cloud
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to port 9087 on vCenter Server may exploit this issue to delete non critical files.

CVE-2021-32483
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges to view the restricted Dashboard.

CVE-2021-45967
Software Genérico Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
92.6%
2021 1 PoC

An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints.

CVE-2021-20077
Tenable Nessus Agent Cloud
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

Nessus Agent versions 7.2.0 through 8.2.2 were found to inadvertently capture the IAM role security token on the local host during initial linking of the Nessus Agent when installed on an Amazon EC2 instance. This could allow a privileged attacker to obtain the token.

CVE-2021-44651
Software Genérico Cloud
N/A
UNKNOWN
EPSS
7.8%
2021 1 PoC

Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper security patch for CVE-2021-40175.

CVE-2021-22006
VMware vCenter Server, VMware Cloud Foundation Cloud
N/A
UNKNOWN
EPSS
57.3%
2021 2 PoCs

The vCenter Server contains a reverse proxy bypass vulnerability due to the way the endpoints handle the URI. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to access restricted endpoints.

CVE-2021-21991
VMware vCenter Server, VMware Cloud Foundation Cloud
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The vCenter Server contains a local privilege escalation vulnerability due to the way it handles session tokens. A malicious actor with non-administrative user access on vCenter Server host may exploit this issue to escalate privileges to Administrator on the vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash).

CVE-2021-45966
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
11.0%
2021 1 PoC

An issue was discovered in Pascom Cloud Phone System before 7.20.x. In the management REST API, /services/apply in exd.pl allows remote attackers to execute arbitrary code via shell metacharacters.

CVE-2021-3178
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8, when there is an NFS export of a subdirectory of a filesystem, allows remote attackers to traverse to other parts of the filesystem via READDIRPLUS. NOTE: some parties argue that such a subdirectory export is not intended to prevent this attack; see also the exports(5) no_subtree_check default behavior

CVE-2021-22053
Spring Cloud Netflix Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
89.6%
2021 CWE-94 2 PoCs

Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within the request URI path during the resolution of view templates. When a request is made at `/hystrix/monitor;[user-provided data]`, the path elements following `hystrix/monitor` are being evaluated as SpringEL expressions, which can lead to code execution.

CVE-2021-45223
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.5%
2021 3 PoCs

An issue was discovered in COINS Construction Cloud 11.12. Due to insufficient input neutralization, it is vulnerable to denial of service attacks via forced server crashes.

CVE-2021-3310
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
1.1%
2021 2 PoCs

Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code execution and information disclosure (by reading local files).

CVE-2021-38112
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
17.7%
2021 1 PoC

In the Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows, argument injection in the workspaces:// URI handler can lead to remote code execution because of the Chromium Embedded Framework (CEF) --gpu-launcher argument. This is fixed in 3.1.9.

CVE-2021-31583
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.9%
2021 3 PoCs

Sipwise C5 NGCP WWW Admin version 3.6.7 up to and including platform version NGCP CE 3.0 has multiple authenticated stored and reflected XSS vulnerabilities when input passed via several parameters to several scripts is not properly sanitized before being returned to the user: Stored XSS in callforward/time/set/save (POST tsetname); Reflected XSS in addressbook (GET filter); Stored XSS in addressbook/save (POST firstname, lastname, company); and Reflected XSS in statistics/versions (GET lang).

CVE-2021-24392
WordPress Membership SwiftCloud.io Web Database Cloud Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

An id GET parameter of the WordPress Membership SwiftCloud.io WordPress plugin through 1.0 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

CVE-2021-45224
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.4%
2021 3 PoCs

An issue was discovered in COINS Construction Cloud 11.12. In several locations throughout the application, JavaScript code is passed as a URL parameter. Attackers can trivially alter this code to cause malicious behaviour. The application is therefore vulnerable to reflected XSS via malicious URLs.

CVE-2021-22016
VMware vCenter Server, VMware Cloud Foundation Web Cloud
N/A
UNKNOWN
EPSS
1.2%
2021 1 PoC

The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attacker may exploit this issue to execute malicious scripts by tricking a victim into clicking a malicious link.

CVE-2021-4160
OpenSSL Cloud
N/A
UNKNOWN
EPSS
0.4%
2021 2 PoCs

There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including some of the TLS 1.3 default curves. Impact was not analyzed in detail, because the pre-requisites for attack are considered unlikely and include reusing private keys. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed of

CVE-2021-22007
VMware vCenter Server, VMware Cloud Foundation Cloud
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The vCenter Server contains a local information disclosure vulnerability in the Analytics service. An authenticated user with non-administrative privilege may exploit this issue to gain access to sensitive information.