152 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2022-42256
vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) Cloud
5.3
MEDIUM
EPSS
0.0%
2022 CWE-190 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow in index validation may lead to denial of service, information disclosure, or data tampering.

CVE-2022-23716
Elastic Cloud Enterprise Cloud
5.3
MEDIUM
EPSS
0.2%
2022 CWE-532 1 PoC

A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment logs in the Logging and Monitoring cluster.

CVE-2022-41210
SAP Customer Data Cloud (Gigya) Cloud
5.2
MEDIUM
EPSS
0.1%
2022 CWE-338 1 PoC

SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses insecure random number generator program which makes it easy for the attacker to predict future random numbers. This can lead to information disclosure and modification of certain user settings.

CVE-2022-41209
SAP Customer Data Cloud (Gigya) Cloud
5.2
MEDIUM
EPSS
0.0%
2022 CWE-326 1 PoC

SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses encryption method which lacks proper diffusion and does not hide the patterns well. This can lead to information disclosure. In certain scenarios, application might also be susceptible to replay attacks.

CVE-2022-29840
My Cloud OS 5 Cloud
5.1
MEDIUM
EPSS
0.0%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL to point back to the loopback adapter was addressed in Western Digital My Cloud OS 5 devices. This could allow the URL to exploit other vulnerabilities on the local server.This issue affects My Cloud OS 5 devices before 5.26.202.

CVE-2022-4979
Experience Platform Web Cloud
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

A cross-site scripting (XSS) vulnerability exists in Sitecore Experience Platform (XP) 7.5 - 10.2 and CMS 7.2 - 7.2 Update-6 that may allow authenticated Sitecore Shell users to be tricked into executing custom JS code. Managed Cloud Standard customers who run the affected Sitecore Experience Platform / CMS versions are also affected.

CVE-2022-38714
DataStage on Cloud Pak for Data Cloud
4.9
MEDIUM
EPSS
0.0%
2022 1 PoC

IBM DataStage on Cloud Pak for Data 4.0.6 to 4.5.2 stores sensitive credential information that can be read by a privileged user. IBM X-Force ID: 235060.

CVE-2022-44213
Software Genérico Web Cloud
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

ZKTeco Xiamen Information Technology ZKBio ECO ADMS <=3.1-164 is vulnerable to Cross Site Scripting (XSS).

CVE-2022-3601
Image Hover Effects Css3 Web Cloud Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Image Hover Effects Css3 WordPress plugin through 4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-29837
My Cloud Home Cloud
4.7
MEDIUM
EPSS
0.1%
2022 CWE-22 1 PoC

A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to initiate installation of custom ZIP packages and overwrite system files. This could potentially lead to a code execution.

CVE-2022-36329
My Cloud Home and My Cloud Home Duo Cloud
4.4
MEDIUM
EPSS
0.1%
2022 CWE-400 1 PoC

An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices.This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191.

CVE-2022-42259
vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) Cloud
4.4
MEDIUM
EPSS
0.1%
2022 CWE-190 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to denial of service.

CVE-2022-29838
My Cloud Cloud
4.3
MEDIUM
EPSS
0.2%
2022 CWE-287 1 PoC

Improper Authentication vulnerability in the encrypted volumes and auto mount features of Western Digital My Cloud devices allows insecure direct access to the drive information in the case of a device reset. This issue affects: Western Digital My Cloud My Cloud versions prior to 5.25.124 on Linux.

CVE-2022-29839
My Cloud Cloud
4.1
MEDIUM
EPSS
0.1%
2022 CWE-522 1 PoC

Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker who has gained access to a relevant endpoint to use that information to access protected data. This issue affects: Western Digital My Cloud My Cloud versions prior to 5.25.124 on Linux.

CVE-2022-28192
NVIDIA Virtual GPU Software and NVIDIA Cloud Gaming Cloud
4.1
MEDIUM
EPSS
0.1%
2022 CWE-416 1 PoC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where it may lead to a use-after-free, which in turn may cause denial of service. This attack is complex to carry out because the attacker needs to have control over freeing some host side resources out of sequence, which requires elevated privileges.

CVE-2022-39867
SmartThings Cloud
4.0
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via SHOW_PERSISTENT_BANNER broadcast.

CVE-2022-39869
SmartThings Cloud
4.0
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via REMOVE_PERSISTENT_BANNER broadcast.

CVE-2022-39870
SmartThings Cloud
4.0
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via PUSH_MESSAGE_RECEIVED broadcast.

CVE-2022-39871
SmartThings Cloud
4.0
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcasts.

CVE-2022-29832
GX Works3 Cloud
3.7
LOW
EPSS
0.2%
2022 CWE-316 1 PoC

Cleartext Storage of Sensitive Information in Memory vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and later, GX Works2 all versions and GX Developer versions 8.40S and later allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated users could obtain information about the project file for MELSEC safety CPU modules or project file for MELSEC Q/FX/L series with security setting.