152 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2022-4348
RuoYi-Cloud Cloud
3.5
LOW
EPSS
0.2%
2022 CWE-707 1 PoC

A vulnerability was found in y_project RuoYi-Cloud. It has been rated as problematic. Affected by this issue is some unknown functionality of the component JSON Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-215108.

CVE-2022-25826
Galaxy S3 PlugIn Cloud
1.9
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

Information Exposure vulnerability in Galaxy S3 Plugin prior to version 2.2.03.22012751 allows attacker to access password information of connected WiFiAp in the log

CVE-2022-29836
My Cloud Home Web Cloud
1.9
LOW
EPSS
0.2%
2022 CWE-22 1 PoC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability was discovered via an HTTP API on Western Digital My Cloud Home; My Cloud Home Duo; and SanDisk ibi devices that could allow an attacker to abuse certain parameters to point to random locations on the file system. This could also allow the attacker to initiate the installation of custom packages at these locations. This can only be exploited once the attacker has been authenticated to the device. This issue affects: Western Digital My Cloud Home and My Cloud Home Duo versions prior to 8.11.0-113 on Lin

CVE-2022-36330
My Cloud Home and My Cloud Home Duo Cloud
1.9
LOW
EPSS
0.4%
2022 CWE-120 1 PoC

A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code execution in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices. An attacker would require exploitation of another vulnerability to raise their privileges in order to exploit this buffer overflow vulnerability. This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191. 

CVE-2022-22946
Spring Cloud Gateway Web Cloud
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.

CVE-2022-37416
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Ittiam libmpeg2 before 2022-07-27 uses memcpy with overlapping memory blocks in impeg2_mc_fullx_fully_8x8.

CVE-2022-29383
Software Genérico Networking Database Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
75.2%
2022 3 PoCs

NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.

CVE-2022-23119
Trend Micro Deep Security Agent for Linux Cloud
N/A
UNKNOWN
EPSS
1.2%
2022 2 PoCs

A directory traversal vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to read arbitrary files from the file system. Please note: an attacker must first obtain compromised access to the target Deep Security Manager (DSM) or the target agent must be not yet activated or configured in order to exploit this vulnerability.

CVE-2022-42150
Software Genérico DevOps Cloud
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

TinyLab linux-lab v1.1-rc1 and cloud-labv0.8-rc2, v1.1-rc1 are vulnerable to insecure permissions. The default configuration could cause Container Escape.

CVE-2022-33713
Samsung Cloud Cloud
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-285 1 PoC

Implicit Intent hijacking vulnerability in Samsung Cloud prior to version 5.2.0 allows attacker to get sensitive information.

CVE-2022-22966
VMware Cloud Director Cloud
N/A
UNKNOWN
EPSS
6.4%
2022 2 PoCs

An authenticated, high privileged malicious actor with network access to the VMware Cloud Director tenant or provider may be able to exploit a remote code execution vulnerability to gain access to the server.

CVE-2022-0659
Sync QCloud COS Web Cloud Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Sync QCloud COS WordPress plugin before 2.0.1 does not escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-29550
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2022 2 PoCs

An issue was discovered in Qualys Cloud Agent 4.8.0-49. It writes "ps auxwwe" output to the /var/log/qualys/qualys-cloud-agent-scan.log file. This may, for example, unexpectedly write credentials (from environment variables) to disk in cleartext. NOTE: there are no common circumstances in which qualys-cloud-agent-scan.log can be read by a user other than root; however, the file contents could be exposed through site-specific operational practices. The vendor does NOT characterize this as a vulnerability because the ps data collection is intentional, and would only capture credentials on a mach

CVE-2022-23715
Elastic Cloud Enterprise Web Database Cloud
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-532 1 PoC

A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystore settings values in logs such as the audit log or deployment logs in the Logging and Monitoring cluster. The affected APIs are PATCH /api/v1/user and PATCH /deployments/{deployment_id}/elasticsearch/{ref_id}/keystore

CVE-2022-3078
Kernel Cloud
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-476 1 PoC

An issue was discovered in the Linux kernel through 5.16-rc6. There is a lack of check after calling vzalloc() and lack of free after allocation in drivers/media/test-drivers/vidtv/vidtv_s302m.c.

CVE-2022-23120
Trend Micro Deep Security Agent for Linux Cloud
N/A
UNKNOWN
EPSS
0.4%
2022 2 PoCs

A code injection vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to escalate privileges and run arbitrary code in the context of root. Please note: an attacker must first obtain access to the target agent in an un-activated and unconfigured state in order to exploit this vulnerability.

CVE-2022-25166
Software Genérico Networking Cloud Windows
N/A
UNKNOWN
EPSS
1.1%
2022 1 PoC

An issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to include a UNC path in the OpenVPN configuration file when referencing file paths for parameters (such as auth-user-pass). When this file is imported and the client attempts to validate the file path, it performs an open operation on the path and leaks the user's Net-NTLMv2 hash to an external server. This could be exploited by having a user open a crafted malicious ovpn configuration file.

CVE-2022-29908
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

The folioupdate service in Fabasoft Cloud Enterprise Client 22.4.0043 allows Local Privilege Escalation.

CVE-2022-25165
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
1.0%
2022 1 PoC

An issue was discovered in Amazon AWS VPN Client 2.0.0. A TOCTOU race condition exists during the validation of VPN configuration files. This allows parameters outside of the AWS VPN Client allow list to be injected into the configuration file prior to the AWS VPN Client service (running as SYSTEM) processing the file. Dangerous arguments can be injected by a low-level user such as log, which allows an arbitrary destination to be specified for writing log files. This leads to an arbitrary file write as SYSTEM with partial control over the files content. This can be abused to cause an elevation

CVE-2022-37177
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

HireVue Hiring Platform V1.0 suffers from Use of a Broken or Risky Cryptographic Algorithm. NOTE: this is disputed by the vendor for multiple reasons, e.g., it is inconsistent with CVE ID assignment rules for cloud services, and no product with version V1.0 exists. Furthermore, the rail-fence cipher has been removed, and TLS 1.2 is now used for encryption.