1390 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2020-28940
Software Genérico Cloud
N/A
UNKNOWN
EPSS
3.6%
2020 1 PoC

On Western Digital My Cloud OS 5 devices before 5.06.115, the NAS Admin dashboard has an authentication bypass vulnerability that could allow an unauthenticated user to execute privileged commands on the device.

CVE-2018-16524
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.5%
2018 1 PoC

Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component allow information disclosure during parsing of TCP options in prvCheckOptions.

CVE-2021-22018
VMware vCenter Server, VMware Cloud Foundation Cloud
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to port 9087 on vCenter Server may exploit this issue to delete non critical files.

CVE-2019-9949
Software Genérico Cloud
N/A
UNKNOWN
EPSS
1.5%
2019 1 PoC

Western Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 before firmware 2.31.183 are affected by a code execution (as root, starting from a low-privilege user session) vulnerability. The cgi-bin/webfile_mgr.cgi file allows arbitrary file write by abusing symlinks. Specifically, this occurs by uploading a tar archive that contains a symbolic link, then uploading another archive that writes a file to the link using the "cgi_untar" command. Other commands might also be susceptible. Code can be executed because the "name" parameter passed to the cg

CVE-2020-10777
CloudForms Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms.

CVE-2015-9464
Software Genérico Web Cloud Windows
N/A
UNKNOWN
EPSS
6.0%
2015 1 PoC

The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.

CVE-2020-8179
Nextcloud Deck Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-284 1 PoC

Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks.

CVE-2020-12757
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials with the default time-to-live lease duration instead of the engine-configured setting. This may lead to generated GCP credentials being valid for longer than intended. Fixed in 1.4.2.

CVE-2018-12357
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2018 1 PoC

Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions.

CVE-2020-5405
Spring Cloud Config Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
88.0%
2020 CWE-23 1 PoC

Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.

CVE-2019-15685
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud Cloud
N/A
UNKNOWN
EPSS
0.3%
2019 4 PoCs

Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component allowed an attacker remotely disable such product's security features as private browsing and anti-banner. Bypass.

CVE-2020-9032
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to kernlog.php.

CVE-2020-15327
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication.

CVE-2020-8118
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
1.3%
2020 CWE-918 1 PoC

An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.

CVE-2020-6800
Thunderbird Cloud
N/A
UNKNOWN
EPSS
1.2%
2020 1 PoC

Mozilla developers and community members reported memory safety bugs present in Firefox 72 and Firefox ESR 68.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.

CVE-2020-8223
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-269 1 PoC

A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assigned themselves.

CVE-2014-5670
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2014 2 PoCs

The SAS: Zombie Assault 3 (aka com.ninjakiwi.sas3zombieassault) application 2.56 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2015-1791
Software Genérico Cloud
N/A
UNKNOWN
EPSS
10.2%
2015 13 PoCs

Race condition in the ssl3_get_new_session_ticket function in ssl/s3_clnt.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b, when used for a multi-threaded client, allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact by providing a NewSessionTicket during an attempt to reuse a ticket that had been obtained earlier.

CVE-2019-6215
iOS Cloud Windows
N/A
UNKNOWN
EPSS
32.3%
2019 1 PoC

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.

CVE-2020-8293
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.6%
2020 CWE-400 1 PoC

A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules.