208 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2020-8225
Desktop Client Cloud
N/A
UNKNOWN
EPSS
0.6%
2020 CWE-312 2 PoCs

A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials.

CVE-2020-8133
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-657 1 PoC

A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.

CVE-2020-15326
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded certificate for Ejabberd in ejabberd.pem.

CVE-2020-26146
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design.

CVE-2020-15314
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account.

CVE-2020-8230
Desktop Client Cloud Windows
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-119 2 PoCs

A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed to corrupt memory.

CVE-2020-15322
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account.

CVE-2020-28940
Software Genérico Cloud
N/A
UNKNOWN
EPSS
3.6%
2020 1 PoC

On Western Digital My Cloud OS 5 devices before 5.06.115, the NAS Admin dashboard has an authentication bypass vulnerability that could allow an unauthenticated user to execute privileged commands on the device.

CVE-2020-2094
Jenkins Health Advisor by CloudBees Plugin DevOps Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A missing permission check in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers with Overall/Read permission to send a fixed email to an attacker-specific recipient.

CVE-2020-27160
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
4.9%
2020 2 PoCs

Addressed remote code execution vulnerability in AvailableApps.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114 (issue 3 of 3).

CVE-2020-35609
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A denial-of-service vulnerability exists in the asynchronous ioctl functionality of Microsoft Azure Sphere 20.05. A sequence of specially crafted ioctl calls can cause a denial of service. An attacker can write shellcode to trigger this vulnerability.

CVE-2020-10777
CloudForms Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms.

CVE-2020-8259
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-522 2 PoCs

Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the encryption keys.

CVE-2020-8229
Desktop Client Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-400 2 PoCs

A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system.

CVE-2020-12830
Software Genérico Cloud
N/A
UNKNOWN
EPSS
3.2%
2020 1 PoC

Addressed multiple stack buffer overflow vulnerabilities that could allow an attacker to carry out escalation of privileges through unauthorized remote code execution in Western Digital My Cloud devices before 5.04.114.

CVE-2020-24916
Software Genérico Cloud
N/A
UNKNOWN
EPSS
44.3%
2020 3 PoCs

CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.

CVE-2020-7010
Elastic Cloud on Kubernetes DevOps Database Cloud
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-335 1 PoC

Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an attacker is able to determine when the current Elastic Stack cluster was deployed they may be able to more easily brute force the Elasticsearch credentials generated by ECK.

CVE-2020-27744
Software Genérico Cloud
N/A
UNKNOWN
EPSS
10.4%
2020 1 PoC

An issue was discovered on Western Digital My Cloud NAS devices before 5.04.114. They allow remote code execution with resultant escalation of privileges.

CVE-2020-8179
Nextcloud Deck Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-284 1 PoC

Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks.

CVE-2020-28971
Software Genérico Cloud
N/A
UNKNOWN
EPSS
3.1%
2020 1 PoC

An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie, because of insufficient validation of URI paths.