1390 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2015-9420
Software Genérico Web Cloud Windows
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

The soundcloud-is-gold plugin before 2.3.2 for WordPress has XSS via the wp-admin/admin-ajax.php?action=get_soundcloud_player id parameter.

CVE-2020-15324
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a world-readable axess/opt/axXMPPHandler/config/xmpp_config.py file that stores hardcoded credentials.

CVE-2019-6129
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has stated "I don't think it is libpng's job to free this buffer.

CVE-2020-10002
watchOS Cloud Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Windows. A local user may be able to read arbitrary files.

CVE-2020-8224
Desktop Client Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-94 1 PoC

A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL config into a fixed directory.

CVE-2008-5080
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.4%
2008 1 PoC

awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter. NOTE: this issue exists because of an incomplete fix for CVE-2008-3714.

CVE-2019-18297
SPPA-T3000 MS3000 Migration Server Cloud
N/A
UNKNOWN
EPSS
0.1%
2019 CWE-122 1 PoC

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with local access to the MS3000 Server and low privileges could gain root privileges by sending specifically crafted packets to a named pipe. Please note that an attacker needs to have local access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

CVE-2020-27159
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
8.3%
2020 2 PoCs

Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validation of user input in Western Digital My Cloud NAS devices prior to 5.04.114

CVE-2019-10267
Software Genérico Cloud
N/A
UNKNOWN
EPSS
64.0%
2019 2 PoCs

An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to upload a file into any directory of the server. One can insert a JSP shell into the web server's directory and execute it. This leads to full access to the system, as the configured user (e.g., Administrator).

CVE-2020-15345
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_instances_for_update API.

CVE-2020-15348
Software Genérico Cloud
N/A
UNKNOWN
EPSS
1.2%
2020 1 PoC

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows use of live/CPEManager/AXCampaignManager/delete_cpes_by_ids?cpe_ids= for eval injection of Python code.

CVE-2019-15450
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The Samsung j3popeltecan Android device with a build fingerprint of samsung/j3popeltevl/j3popeltecan:8.1.0/M1AJQ/J327WVLS3BSA2:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed

CVE-2020-9029
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to messagelog.php.

CVE-2014-2586
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
8.6%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in the login audit form in McAfee Cloud Single Sign On (SSO) allows remote attackers to inject arbitrary web script or HTML via a crafted password.

CVE-2015-8993
CloudAV (Beta) Cloud
N/A
UNKNOWN
EPSS
0.0%
2015 1 PoC

Malicious file execution vulnerability in Intel Security CloudAV (Beta) before 0.5.0.151.3 allows attackers to make the product momentarily vulnerable via executing preexisting specifically crafted malware during installation or uninstallation, but not during normal operation.

CVE-2019-18294
SPPA-T3000 MS3000 Migration Server Cloud
N/A
UNKNOWN
EPSS
0.2%
2019 CWE-122 1 PoC

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18290, CVE-2019-18291, CVE-2019-18292, CVE-2019-18298, CVE-2019-18299, CVE-2019-18300, CVE-2019-18301, CVE-2019-18302, CVE-2019-18303, CVE-2019-18304, CVE-2019-18305, CVE-2019-18306, and CVE-2019-18307. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnera

CVE-2020-26524
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

CodeLathe FileCloud before 20.2.0.11915 allows username enumeration.

CVE-2020-15343
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user_key API.

CVE-2020-8225
Desktop Client Cloud
N/A
UNKNOWN
EPSS
0.6%
2020 CWE-312 2 PoCs

A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials.

CVE-2019-15689
Kaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud Cloud
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

Kaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud prior to version 2020 patch E have bug that allows a local user to execute arbitrary code via execution compromised file placed by an attacker with administrator rights. No privilege escalation. Possible whitelisting bypass some of the security products