1390 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2021-31584
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.4%
2021 3 PoCs

Sipwise C5 NGCP www_csc version 3.6.4 up to and including platform NGCP CE mr3.8.13 allows call/click2dial CSRF attacks for actions with administrative privileges.

CVE-2020-24916
Software Genérico Cloud
N/A
UNKNOWN
EPSS
44.3%
2020 3 PoCs

CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.

CVE-2007-3815
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
0.1%
2007 1 PoC

Buffer overflow in pirs32.exe in Poslovni informator Republike Slovenije (PIRS) 2007 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long search string in certain fields in the GUI. NOTE: this may cross privilege boundaries if PIRS is used by data-entry workers who do not have full access to the underlying Windows environment.

CVE-2014-9921
Cloud Analysis and Deconstructive Services (CADS) Cloud
N/A
UNKNOWN
EPSS
1.2%
2014 1 PoC

Information disclosure vulnerability in McAfee (now Intel Security) Cloud Analysis and Deconstructive Services (CADS) 1.0.0.3x, 1.0.0.4d and earlier allows remote unauthenticated users to view, add, and remove users via a configuration error.

CVE-2014-1585
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.7%
2014 1 PoC

The WebRTC video-sharing feature in dom/media/MediaManager.cpp in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 does not properly recognize Stop Sharing actions for videos in IFRAME elements, which allows remote attackers to obtain sensitive information from the local camera by maintaining a session after the user tries to discontinue streaming.

CVE-2015-0440
Software Genérico Database Cloud
N/A
UNKNOWN
EPSS
0.3%
2015 1 PoC

Unspecified vulnerability in the Oracle Knowledge component in Oracle Right Now Service Cloud 8.2.3.10.1 and 8.4.7.2 allows remote attackers to affect integrity via unknown vectors related to Information Manager Console.

CVE-2020-28971
Software Genérico Cloud
N/A
UNKNOWN
EPSS
3.1%
2020 1 PoC

An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie, because of insufficient validation of URI paths.

CVE-2020-24379
Software Genérico Cloud
N/A
UNKNOWN
EPSS
1.1%
2020 3 PoCs

WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.

CVE-2020-8235
Nextcloud Deck app Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-639 1 PoC

Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments.

CVE-2020-15334
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows escape-sequence injection into the /var/log/axxmpp.log file.

CVE-2020-24219
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
25.2%
2020 1 PoC

An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-matching programming flaws, and retrieve any file from the device's file system, including the configuration file with the cleartext administrative password.

CVE-2020-8139
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-284 1 PoC

A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.

CVE-2020-8150
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-310 1 PoC

A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.

CVE-2020-15342
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user API.

CVE-2020-29563
Software Genérico Cloud
N/A
UNKNOWN
EPSS
5.6%
2020 1 PoC

An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to gain access to the device.

CVE-2021-41556
Software Genérico Cloud
N/A
UNKNOWN
EPSS
2.4%
2021 1 PoC

sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code Execution. If a victim executes an attacker-controlled squirrel script, it is possible for the attacker to break out of the squirrel script sandbox even if all dangerous functionality such as File System functions has been disabled. An attacker might abuse this bug to target (for example) Cloud services that allow customization via SquirrelScripts, or distribute malware through video games that embed a Squirrel Engine.

CVE-2020-13630
Software Genérico Database Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 3 PoCs

ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.

CVE-2020-8181
Nextcloud Contact Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-840 1 PoC

A missing file type check in Nextcloud Contacts 3.2.0 allowed a malicious user to upload any file as avatars.

CVE-2021-21986
VMware vCenter Server and VMware Cloud Foundation Cloud
N/A
UNKNOWN
EPSS
1.5%
2021 1 PoC

The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-ins. A malicious actor with network access to port 443 on vCenter Server may perform actions allowed by the impacted plug-ins without authentication.

CVE-2020-15313
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account.