106 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2024-33893
Software Genérico Web Cloud
6.1
MEDIUM
EPSS
1.6%
2024 2 PoCs

Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to XSS when displaying the logs due to improper input sanitization. This is fixed in version 21.2s10 and 22.1s3.

CVE-2024-37791
Software Genérico Web Database Cloud
6.0
MEDIUM
EPSS
2.7%
2024 1 PoC

DuxCMS3 v3.1.3 was discovered to contain a SQL injection vulnerability via the keyword parameter at /article/Content/index?class_id.

CVE-2024-0092
GPU display driver, vGPU software, and Cloud Gaming Cloud Windows
5.5
MEDIUM
EPSS
0.1%
2024 CWE-703 1 PoC

NVIDIA GPU Driver for Windows and Linux contains a vulnerability where an improper check or improper handling of exception conditions might lead to denial of service.

CVE-2024-26160
Windows 11 version 22H2 Cloud Windows
5.5
MEDIUM
EPSS
38.1%
2024 CWE-126 2 PoCs

Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability

CVE-2024-0094
vGPU software and Cloud Gaming Cloud
5.5
MEDIUM
EPSS
0.0%
2024 CWE-799 1 PoC

NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where an untrusted guest VM can cause improper control of the interaction frequency in the host. A successful exploit of this vulnerability might lead to denial of service.

CVE-2024-28345
Software Genérico Cloud
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue discovered in Sipwise C5 NGCP Dashboard below mr11.5.1 allows a low privileged user to access the Journal endpoint by directly visit the URL.

CVE-2024-0086
vGPU software and Cloud Gaming Cloud
5.5
MEDIUM
EPSS
0.0%
2024 CWE-476 1 PoC

NVIDIA vGPU software for Linux contains a vulnerability where the software can dereference a NULL pointer. A successful exploit of this vulnerability might lead to denial of service and undefined behavior in the vGPU plugin.

CVE-2024-28144
Scan2Net Cloud
5.5
MEDIUM
EPSS
0.1%
2024 CWE-384 2 PoCs

An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaws in the self-developed session management. If two users access the web interface from the same IP they are logged in as the other user.

CVE-2024-51026
Software Genérico Web Cloud
5.4
MEDIUM
EPSS
1.0%
2024 1 PoC

The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious payload into the Content= field.

CVE-2024-33892
Software Genérico Cloud
5.3
MEDIUM
EPSS
0.2%
2024 1 PoC

Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. This is fixed in version 21.2s10 and 22.1s3

CVE-2024-11054
Simple Music Cloud Community System Web Cloud
5.3
MEDIUM
EPSS
0.1%
2024 CWE-434 1 PoC

A vulnerability classified as critical was found in SourceCodester Simple Music Cloud Community System 1.0. This vulnerability affects unknown code of the file /music/ajax.php?action=signup. The manipulation of the argument pp leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-55069
Software Genérico Cloud
5.3
MEDIUM
EPSS
0.3%
2024 1 PoC

ffmpeg 7.1 is vulnerable to Null Pointer Dereference in function iamf_read_header in /libavformat/iamfdec.c.

CVE-2024-11662
OpsManage Web Cloud
5.3
MEDIUM
EPSS
0.1%
2024 CWE-502 1 PoC

A vulnerability was found in welliamcao OpsManage 3.0.1/3.0.2/3.0.3/3.0.4/3.0.5. It has been rated as critical. This issue affects the function deploy_host_vars of the file /apps/api/views/deploy_api.py of the component API Endpoint. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-8129
DNS-120 Web Cloud
5.3
MEDIUM
EPSS
16.8%
2024 CWE-77 1 PoC

A vulnerability, which was classified as critical, was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. Affected is the function cgi_s3_modify of the file /cgi-bin/s3.cgi of the component HTTP POST Request Handler. The manipulation of the argument f_job_name leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerab

CVE-2024-3505
Artifactory Self-Hosted Cloud
4.3
MEDIUM
EPSS
0.5%
2024 CWE-200 1 PoC

JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments.

CVE-2024-1098
Rebuild Cloud
4.3
MEDIUM
EPSS
0.2%
2024 CWE-200 2 PoCs

A vulnerability was found in Rebuild up to 3.5.5 and classified as problematic. This issue affects the function QiniuCloud.getStorageFile of the file /filex/proxy-download. The manipulation of the argument url leads to information disclosure. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252455.

CVE-2024-52510
security-advisories Cloud
4.2
MEDIUM
EPSS
0.5%
2024 CWE-295 1 PoC

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that the Nextcloud Desktop client is upgraded to 3.14.2 or later.

CVE-2024-0243
langchain-ai/langchain Web Cloud
3.7
LOW
EPSS
0.1%
2024 CWE-918 4 PoCs

With the following crawler configuration: ```python from bs4 import BeautifulSoup as Soup url = "https://example.com" loader = RecursiveUrlLoader( url=url, max_depth=2, extractor=lambda x: Soup(x, "html.parser").text ) docs = loader.load() ``` An attacker in control of the contents of `https://example.com` could place a malicious HTML file in there with links like "https://example.completely.different/my_file.html" and the crawler would proceed to download that file as well even though `prevent_outside=True`. https://github.com/langchain-ai/langchain/blob/bf0b3cc0b5ade1fb95a5b1b6fa260e

CVE-2024-4519
Complete Web-Based School Management System Web Cloud
3.5
LOW
EPSS
0.1%
2024 CWE-79 1 PoC

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /view/teacher_salary_details3.php. The manipulation of the argument month leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263123.

CVE-2024-21803
Linux kernel Web Cloud
3.5
LOW
EPSS
0.0%
2024 CWE-416 1 PoC

Use After Free vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (bluetooth modules) allows Local Execution of Code. This vulnerability is associated with program files https://gitee.Com/anolis/cloud-kernel/blob/devel-5.10/net/bluetooth/af_bluetooth.C. This issue affects Linux kernel: from v2.6.12-rc2 before v6.8-rc1.