114 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2023-4468
Trio 8500 Cloud
4.3
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

A vulnerability was found in Poly Trio 8500, Trio 8800 and Trio C60. It has been classified as problematic. This affects an unknown part of the component Poly Lens Management Cloud Registration. The manipulation leads to missing authorization. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The identifier VDB-249261 was assigned to this vulnerability.

CVE-2023-6289
Swift Performance Lite Web Cloud Windows
4.3
MEDIUM
EPSS
2.9%
2023 2 PoCs

The Swift Performance Lite WordPress plugin before 2.3.6.15 does not prevent users from exporting the plugin's settings, which may include sensitive information such as Cloudflare API tokens.

CVE-2023-21447
Samsung Cloud Cloud
4.0
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper access control vulnerabilities in Samsung Cloud prior to version 5.3.0.32 allows local attackers to access information with Samsung Cloud's privilege via implicit intent.

CVE-2023-27892
Software Genérico Cloud
3.8
LOW
EPSS
0.1%
2023 1 PoC

Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.7.0 allow a global buffer overflow via crafted messages. Flaws in cf_confirmExecTx() in ethereum_contracts.c can be used to reveal arbitrary microcontroller memory on the device screen or crash the device. With physical access to a PIN-unlocked device, attackers can extract the BIP39 mnemonic secret from the hardware wallet.

CVE-2023-22813
My Cloud OS 5 Mobile App Web Cloud
3.3
LOW
EPSS
0.2%
2023 CWE-200 1 PoC

A device API endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps, My Cloud Home iOS and Android Mobile Apps, SanDisk ibi iOS and Android Mobile Apps, My Cloud OS 5 Web App, My Cloud Home Web App and the SanDisk ibi Web App. Due to a permissive CORS policy and missing authentication requirement for private IPs, a remote attacker on the same network as the device could obtain device information by convincing a victim user to visit an attacker-controlled server and issue a cross-site request. This issue affects My Cloud OS 5 Mobile App: be

CVE-2023-0194
vGPU software (guest driver - Windows), NVIDIA Cloud Gaming (guest driver - Windows) Cloud Windows
2.0
LOW
EPSS
0.1%
2023 CWE-1284 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer driver, where an invalid display configuration may lead to denial of service.

CVE-2023-0195
vGPU software (guest driver - Windows), NVIDIA Cloud Gaming (guest driver - Windows) Cloud Windows
2.0
LOW
EPSS
0.1%
2023 CWE-1284 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer driver nvlddmkm.sys, where an can cause CWE-1284, which may lead to hypothetical Information leak of unimportant data such as local variable data of the driver

CVE-2023-22957
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.4%
2023 4 PoCs

An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attacker with access to backup or configuration files is able to decrypt encrypted values and retrieve sensitive information, e.g., the device root password.

CVE-2023-1597
tagDiv Cloud Library Web Cloud Windows
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and authenticated users, allowing unauthenticated users to change arbitrary user metadata, which could lead to privilege escalation by setting themselves as an admin of the blog.

CVE-2023-45992
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.6%
2023 3 PoCs

A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user of the admin management interface. A successful attack, combined with a certain admin activity, could allow the attacker to gain full admin privileges on the exploited system.

CVE-2023-45311
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.9%
2023 2 PoCs

fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adversary to execute arbitrary code if any JavaScript project (that depends on fsevents) distributes code that was obtained from that URL at a time when it was controlled by an adversary. NOTE: some sources feel that this means that no version is affected any longer, because the URL is not controlled by an adversary.

CVE-2023-46157
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.6%
2023 2 PoCs

File-Manager in MGT CloudPanel 2.0.0 through 2.3.2 allows the lowest privilege user to achieve OS command injection by changing file ownership and changing file permissions to 4755.

CVE-2023-36630
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

In CloudPanel before 2.3.1, insecure file upload leads to privilege escalation and authentication bypass.

CVE-2023-36482
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue was discovered in Samsung NFC S3NRN4V, S3NSN4V, S3NSEN4, SEN82AB, and S3NRN82. A buffer copy without checking its input size can cause an NFC service restart.