1390 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2020-15343
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user_key API.

CVE-2020-8225
Desktop Client Cloud
N/A
UNKNOWN
EPSS
0.6%
2020 CWE-312 2 PoCs

A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials.

CVE-2019-15689
Kaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud Cloud
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

Kaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud prior to version 2020 patch E have bug that allows a local user to execute arbitrary code via execution compromised file placed by an attacker with administrator rights. No privilege escalation. Possible whitelisting bypass some of the security products

CVE-2020-8133
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-657 1 PoC

A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.

CVE-2008-5722
Software Genérico Cloud
N/A
UNKNOWN
EPSS
7.7%
2008 2 PoCs

Buffer overflow in SAWStudio 3.9i allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long SAWSTUDIO PREFERENCES STRUCT value in a .prf (preferences) file.

CVE-2020-26146
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design.

CVE-2019-15688
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud Cloud
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component did not adequately inform the user about the threat of redirecting to an untrusted site. Bypass.

CVE-2020-8230
Desktop Client Cloud Windows
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-119 2 PoCs

A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed to corrupt memory.

CVE-2015-8843
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.0%
2015 1 PoC

The Foxit Cloud Update Service (FoxitCloudUpdateService) in Foxit Reader 6.1 through 6.2.x and 7.x before 7.2.2, when an update to the Cloud plugin is available, allows local users to gain privileges by writing crafted data to a shared memory region, which triggers memory corruption.

CVE-2020-15322
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account.

CVE-2019-5161
WAGO PFC200 Firmware Cloud
N/A
UNKNOWN
EPSS
4.9%
2019 1 PoC

An exploitable remote code execution vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). A specially crafted XML file will direct the Cloud Connectivity service to download and execute a shell script with root privileges.

CVE-2020-2094
Jenkins Health Advisor by CloudBees Plugin DevOps Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A missing permission check in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers with Overall/Read permission to send a fixed email to an attacker-specific recipient.

CVE-2019-18302
SPPA-T3000 MS3000 Migration Server Cloud
N/A
UNKNOWN
EPSS
0.2%
2019 CWE-190 1 PoC

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server can trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18290, CVE-2019-18291, CVE-2019-18292, CVE-2019-18294, CVE-2019-18298, CVE-2019-18299, CVE-2019-18300, CVE-2019-18301, CVE-2019-18303, CVE-2019-18304, CVE-2019-18305, CVE-2019-18306, and CVE-2019-18307. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerabi

CVE-2020-27160
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
4.9%
2020 2 PoCs

Addressed remote code execution vulnerability in AvailableApps.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114 (issue 3 of 3).

CVE-2020-8259
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-522 2 PoCs

Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the encryption keys.

CVE-2019-18306
SPPA-T3000 MS3000 Migration Server Cloud
N/A
UNKNOWN
EPSS
0.2%
2019 CWE-125 1 PoC

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18290, CVE-2019-18291, CVE-2019-18292, CVE-2019-18294, CVE-2019-18298, CVE-2019-18299, CVE-2019-18300, CVE-2019-18301, CVE-2019-18302, CVE-2019-18303, CVE-2019-18304, CVE-2019-18305, and CVE-2019-18307. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnera

CVE-2020-8229
Desktop Client Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-400 2 PoCs

A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system.

CVE-2020-12830
Software Genérico Cloud
N/A
UNKNOWN
EPSS
3.2%
2020 1 PoC

Addressed multiple stack buffer overflow vulnerabilities that could allow an attacker to carry out escalation of privileges through unauthorized remote code execution in Western Digital My Cloud devices before 5.04.114.

CVE-2021-31584
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.4%
2021 3 PoCs

Sipwise C5 NGCP www_csc version 3.6.4 up to and including platform NGCP CE mr3.8.13 allows call/click2dial CSRF attacks for actions with administrative privileges.

CVE-2020-24916
Software Genérico Cloud
N/A
UNKNOWN
EPSS
44.3%
2020 3 PoCs

CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.