208 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2020-8179
Nextcloud Deck Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-284 1 PoC

Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks.

CVE-2020-28971
Software Genérico Cloud
N/A
UNKNOWN
EPSS
3.1%
2020 1 PoC

An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie, because of insufficient validation of URI paths.

CVE-2020-15338
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /cnr requests.

CVE-2020-8293
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.6%
2020 CWE-400 1 PoC

A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules.

CVE-2020-8227
Desktop Client Cloud
N/A
UNKNOWN
EPSS
0.9%
2020 CWE-22 2 PoCs

Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory.

CVE-2020-12757
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials with the default time-to-live lease duration instead of the engine-configured setting. This may lead to generated GCP credentials being valid for longer than intended. Fixed in 1.4.2.

CVE-2020-24379
Software Genérico Cloud
N/A
UNKNOWN
EPSS
1.1%
2020 3 PoCs

WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.

CVE-2020-8235
Nextcloud Deck app Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-639 1 PoC

Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments.

CVE-2020-8154
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
1.0%
2020 CWE-639 1 PoC

An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint.

CVE-2020-5405
Spring Cloud Config Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
88.0%
2020 CWE-23 1 PoC

Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.

CVE-2020-15334
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows escape-sequence injection into the /var/log/axxmpp.log file.

CVE-2020-27488
Software Genérico Cloud
N/A
UNKNOWN
EPSS
1.0%
2020 2 PoCs

Loxone Miniserver devices with firmware before 11.1 (aka 11.1.9.3) are unable to use an authentication method that is based on the "signature of the update package." Therefore, these devices (or attackers who are spoofing these devices) can continue to use an unauthenticated cloud service for an indeterminate time period (possibly forever). Once an individual device's firmware is updated, and authentication occurs once, the cloud service recategorizes the device so that authentication is subsequently always required, and spoofing cannot occur.

CVE-2020-9032
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to kernlog.php.

CVE-2020-24219
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
25.2%
2020 1 PoC

An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-matching programming flaws, and retrieve any file from the device's file system, including the configuration file with the cleartext administrative password.

CVE-2020-8139
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-284 1 PoC

A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.

CVE-2020-8117
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-280 1 PoC

Improper preservation of permissions in Nextcloud Server 14.0.3 causes the event details to be leaked when sharing a non-public event.

CVE-2020-15325
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded Erlang cookie for ejabberd replication.

CVE-2020-15327
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication.

CVE-2020-8150
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-310 1 PoC

A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.

CVE-2020-15342
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user API.