128 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2021-42979
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

NoMachine Cloud Server is affected by Integer Overflow. IOCTL Handler 0x22001B in the NoMachine Cloud Server above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

CVE-2021-45967
Software Genérico Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
92.6%
2021 1 PoC

An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints.

CVE-2021-20077
Tenable Nessus Agent Cloud
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

Nessus Agent versions 7.2.0 through 8.2.2 were found to inadvertently capture the IAM role security token on the local host during initial linking of the Nessus Agent when installed on an Amazon EC2 instance. This could allow a privileged attacker to obtain the token.

CVE-2021-44651
Software Genérico Cloud
N/A
UNKNOWN
EPSS
7.8%
2021 1 PoC

Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper security patch for CVE-2021-40175.

CVE-2021-22146
Software Genérico Web Database Cloud
N/A
UNKNOWN
EPSS
29.9%
2021 2 PoCs

All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting the anonymous user has no permissions and is unable to successfully query any Elasticsearch APIs, an attacker could leverage the anonymous user to gain insight into certain details of a deployed cluster.

CVE-2021-29994
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Cloudera Hue 4.6.0 allows XSS.

CVE-2021-22006
VMware vCenter Server, VMware Cloud Foundation Cloud
N/A
UNKNOWN
EPSS
57.3%
2021 2 PoCs

The vCenter Server contains a reverse proxy bypass vulnerability due to the way the endpoints handle the URI. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to access restricted endpoints.

CVE-2021-21991
VMware vCenter Server, VMware Cloud Foundation Cloud
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The vCenter Server contains a local privilege escalation vulnerability due to the way it handles session tokens. A malicious actor with non-administrative user access on vCenter Server host may exploit this issue to escalate privileges to Administrator on the vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash).

CVE-2021-36695
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in the download file feature on a manager profile due to lack of input validation.

CVE-2021-45966
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
11.0%
2021 1 PoC

An issue was discovered in Pascom Cloud Phone System before 7.20.x. In the management REST API, /services/apply in exd.pl allows remote attackers to execute arbitrary code via shell metacharacters.

CVE-2021-3178
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8, when there is an NFS export of a subdirectory of a filesystem, allows remote attackers to traverse to other parts of the filesystem via READDIRPLUS. NOTE: some parties argue that such a subdirectory export is not intended to prevent this attack; see also the exports(5) no_subtree_check default behavior

CVE-2021-22048
VMware vCenter Server and VMware Cloud Foundation Cloud Windows
N/A
UNKNOWN
EPSS
1.4%
2021 2 PoCs

The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative access to vCenter Server may exploit this issue to elevate privileges to a higher privileged group.

CVE-2021-22053
Spring Cloud Netflix Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
89.6%
2021 CWE-94 2 PoCs

Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within the request URI path during the resolution of view templates. When a request is made at `/hystrix/monitor;[user-provided data]`, the path elements following `hystrix/monitor` are being evaluated as SpringEL expressions, which can lead to code execution.

CVE-2021-45223
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.5%
2021 3 PoCs

An issue was discovered in COINS Construction Cloud 11.12. Due to insufficient input neutralization, it is vulnerable to denial of service attacks via forced server crashes.

CVE-2021-3310
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
1.1%
2021 2 PoCs

Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code execution and information disclosure (by reading local files).

CVE-2021-41506
Software Genérico Cloud
N/A
UNKNOWN
EPSS
1.1%
2021 1 PoC

Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI3518_50H10L_S39 V4.02.R11.7601.Nat.Onvif.20170420, V4.02.R11.Nat.Onvif.20160422, V4.02.R11.7601.Nat.Onvif.20170424, V4.02.R11.Nat.Onvif.20170327, V4.02.R11.Nat.Onvif.20161205, V4.02.R11.Nat.20170301, V4.02.R12.Nat.OnvifS.20170727 is affected by a backdoor in the macGuarder and dvrHelper binaries of DVR/NVR/IP camera firmware due to static root account credentials in the system.

CVE-2021-24864
WP Cloudy, weather plugin Web Database Cloud Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The WP Cloudy, weather plugin WordPress plugin before 4.4.9 does not escape the post_id parameter before using it in a SQL statement in the admin dashboard, leading to a SQL Injection issue

CVE-2021-40868
Software Genérico Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
27.0%
2021 2 PoCs

In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.

CVE-2021-30132
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges.

CVE-2021-40371
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
4.6%
2021 2 PoCs

Gridpro Request Management for Windows Azure Pack before 2.0.7912 allows Directory Traversal for remote code execution, as demonstrated by ..\\ in a scriptName JSON value to ServiceManagerTenant/GetVisibilityMap.