CVEs we hold for Cloud
Records whose assigning authority named Cloud as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-73356WordPress Breeze plugin <= 2.5.12 - Arbitrary Content Deletion vulnerabilityCloudways Breeze
CVE-2026-62323Cloudreve: Unauthorized file write via WOPI view sessions whose access token secret is ignoredcloudreve
CVE-2026-59335Case-Sensitive Authorization Check Bypass via Identity Zone ID Case Manipulation Leads to Full UAA CompromiseCloud Foundry cf-deployment
CVE-2026-55769CloudNativePG: Overriding operators can lead to privilege escalation in CloudNativePG for SQL queries without a fixed…cloudnative-pg
CVE-2026-55765CloudNativePG: Cleartext role passwords recorded in pg_stat_statements allow privileged tenant roles to recover the…cloudnative-pg
CVE-2026-55502Cloudreve: OAuth Admin.Read scope can update OneDrive storage policy credentialscloudreve
CVE-2026-55499Cloudreve: Broken access control in file event stream leaks activity events for unshared siblings to single-file share…cloudreve
CVE-2026-55497Cloudreve: Server crash through image decompression/pixel bomb in thumbnail & avatar decoding (DoS)cloudreve
CVE-2026-55496Cloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because SearchActive() omits the…cloudreve
CVE-2026-55495Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Accountcloudreve
CVE-2026-54563Cloudreve: Path Traversal / Broken Access Control in Cloudreve WebDAV (`/dav`) — scoped DAV credential escapes its…cloudreve
CVE-2026-54562Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responsescloudreve
CVE-2026-54560Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claimcloudreve
CVE-2026-47840LDAP StartTLS unconditionally disables hostname verificationCloudFoundry Foundation Cf-deployment
CVE-2026-47839Federated OIDC Users Can Bypass externalGroupsWhitelist to Gain uaa.adminCloud Foundry Foundation cf-deployment
CVE-2026-47831Cryptographically Weak Password Generation in bosh-windows-stemcell-builder Allows Remote SSH Brute-Force AttacksCloud Foundry Foundation bosh-windows-stemcell-builder
CVE-2026-47830Incorrect Permission Assignment Allows Local Privilege Escalation to SYSTEM via Executable OverwriteCloud Foundry Foundation bosh-windows-stemcell-builder
CVE-2026-47829Argument Injection in BOSH CLI Allows Local Command Execution on Operator Workstations via Compromised DirectorCloudFoundry Foundation bosh-cli
CVE-2026-45290Cloudburst Network has DoS in RakNet connection handling due to missing bound checksCloudburstMC Network
CVE-2026-45289CloudburstMC Protocol: Partially missing validation for FULL type authentication tokensCloudburstMC Protocol
CVE-2026-45132CloudPirates Open Source Helm Charts: GitHub Actions workflow leaks PAT and SSH signing key via unsafe credential…CloudPirates-io helm-charts
CVE-2026-45131CloudPirates Open Source Helm Charts: GitHub Actions pull_request_target workflow allows secret exfiltration via fork…CloudPirates-io helm-charts
CVE-2026-44477CloudNativePG: Metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCEcloudnative-pg
CVE-2026-41861Arbitrary Root File Write via Path Traversal in BOSH agentCloudFoundry Foundation BOSH
CVE-2026-41704Compromised VM can make arbitrary blobstore deletesCloud Foundry Foundation BOSH Director
CVE-2026-41013Tenant-controlled comma smuggles arbitrary CIFS mount optionsCloudFoundry Foundation CF Deployment
CVE-2026-41009Local Blobstore may allow arbitrary reads/deletesCloud Foundry Foundation BOSH Director
CVE-2026-41005UAA accepts SAML Encrypted Assertions authentication bypassCloud Foundry CF Deployment
CVE-2026-3844Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remotecloudways Breeze Cache
CVE-2026-35023Wimi Teamwork On-Premises < 8.2.0 IDOR via preview.phpCloud Solutions SAS Wimi Teamwork
CVE-2026-32254Kube-router Proxy Module Blindly Trusts ExternalIPs/LoadBalancer IPs Enabling Cluster-Wide Traffic Hijacking and DNS DoScloudnativelabs kube-router
CVE-2026-2836Cache poisoning via insecure-by-default cache keyCloudflare https://github.com/cloudflare/pingora
CVE-2026-2835HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding MisparsingCloudflare https://github.com/cloudflare/pingora
CVE-2026-2833HTTP Request Smuggling via Premature UpgradeCloudflare https://github.com/cloudflare/pingora
CVE-2026-25726Cloudreve is vulnerable to Account Takeover via Weak Cryptographic Token Generation (Insecure PRNG Seeding)cloudreve
CVE-2026-25114CloudCharge cloudcharge.se Improper Restriction of Excessive Authentication AttemptsCloudCharge cloudcharge.se
CVE-2026-24525WordPress CLP Varnish Cache plugin <= 1.0.2 - Broken Access Control vulnerabilityCloudPanel CLP Varnish Cache
CVE-2026-2128Breeze Cache <= 2.5.2 - Unauthenticated Exposure of Sensitive Information to an Unauthorized Actor via Crafted Login…cloudways Breeze Cache
CVE-2026-20781CloudCharge cloudcharge.se Missing Authentication for Critical FunctionCloudCharge cloudcharge.se
CVE-2026-20733CloudCharge cloudcharge.se Insufficiently Protected CredentialsCloudCharge cloudcharge.se
CVE-2026-14440Cloudflare Universal SSL automatically managed CAA RRset supersedes customer-configured CAA recordsCloudflare Universal SSL
CVE-2026-12707Unbounded path event queue growth in quiche via peer-driven source connection ID rotationCloudflare quiche
CVE-2026-11325cloudflare/pages-action is deprecated — migration required by September 18th, 2026Cloudflare https://github.com/cloudflare/pages-action
CVE-2025-8529cloudfavorites favorites-web CollectController.java getCollectLogoUrl server-side request forgerycloudfavorites favorites-web
CVE-2025-7045Cloud SAML SSO <= 1.0.19 - Missing Authorization to Unauthenticated Identity Provider Deletion via delete_config Actioncloudinfrastructureservices Cloud SAML SSO – Single Sign On…
CVE-2025-7040Cloud SAML SSO <= 1.0.19 - Missing Authorization to Unauthenticated Settings Modification via set_organization_settings…cloudinfrastructureservices Cloud SAML SSO – Single Sign On…
CVE-2025-69364WordPress Breeze plugin <= 2.2.21 - Broken Access Control vulnerabilityCloudways Breeze
CVE-2025-59427Cloudflare vite plugin exposes secrets over the built-in dev servercloudflare workers-sdk
CVE-2025-49264WordPress Cloud SAML SSO - Single Sign On Login <= 1.0.18 - Local File Inclusion VulnerabilityCloud SAML SSO - Single Sign On Login
CVE-2025-3884Cloudera Hue Ace Editor Directory Traversal Information Disclosure VulnerabilityCloudera Hue
CVE-2025-31807WordPress Product Notices for WooCommerce plugin <= 1.3.4 - Cross Site Request Forgery (CSRF) vulnerabilityCloudRedux Product Notices for WooCommerce
CVE-2025-23999WordPress Breeze plugin <= 2.2.13 - Broken Access Control vulnerabilityCloudways Breeze
CVE-2025-23721WordPress Mobigate plugin <= 1.0.3 - Reflected Cross Site Scripting (XSS) vulnerabilitycloudvn Mobigate
CVE-2025-13864Breeze – WordPress Cache Plugin <= 2.2.21 - Missing Authorization to Cache Deletioncloudways Breeze Cache
CVE-2025-13353gokey allows secret recovery from a seed file without the master passwordCloudflare gokey
CVE-2025-11757Improper Neutralization of Wildcards or Matching Symbols in CloudEdge Online Cameras and AppCloudEdge App
CVE-2025-0651File symlink abuse might lead to deleting files belonging to SYSTEM userCloudflare WARP
CVE-2024-50431WordPress Breeze plugin <= 2.1.14 - Cross Site Scripting (XSS) vulnerabilityCloudways Breeze
CVE-2024-50422WordPress Breeze plugin <= 2.1.14 - Broken Access Control vulnerabilityCloudways Breeze
CVE-2024-45389Pagefind DOM clobbering could escalate to Cross-site Scripting (XSS)CloudCannon pagefind
CVE-2024-28110Go SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentialscloudevents sdk-go
CVE-2024-27188WordPress Breeze plugin <= 2.1.3 - Cross Site Scripting (XSS) vulnerabilityCloudways Breeze
CVE-2024-1765Unlimited resource allocation by QUIC CRYPTO frames flooding in quicheCloudflare quiche
CVE-2024-1410Unbounded storage of information related to connection ID retirement, in quicheCloudflare quiche
CVE-2024-0212Cloudflare WordPress plugin enables information disclosure of Cloudflare API (for low privileged users)Cloudflare-WordPress
CVE-2023-44397CloudExplorer Lite permission bypass vulnerabilityCloudExplorer-Dev CloudExplorer-Lite
CVE-2023-39519CloudExplorer Lite sensitive information leakage vulnerabilityCloudExplorer-Dev CloudExplorer-Lite
CVE-2023-38692Command injection vulnerability in module management function in CloudExplorer LiteCloudExplorer-Dev CloudExplorer-Lite
CVE-2023-3747Insufficient Validation on Override Codes for Always-Enabled WARP ModeCloudflare WARP Client
CVE-2023-3423Weak Password Requirements in cloudexplorer-dev/cloudexplorer-litecloudexplorer-dev/cloudexplorer-lite
CVE-2023-34041CVE-2023-34041-Abuse of HTTP Hop-by-Hop Headers in Cloud Foundry GorouterCloud Foundry CF Deployment
CVE-2023-32591WordPress DBargain Plugin <= 3.0.0 is vulnerable to Cross Site Scripting (XSS)Cloud Primero B.V DBargain
CVE-2023-32316Users can add themselves to any organization in CloudExplorer LiteCloudExplorer-Dev CloudExplorer-Lite
CVE-2023-30612Malicious HTTP requests could close arbitrary opening file descriptors in cloud-hypervisorcloud-hypervisor
CVE-2023-2845Improper Access Control in cloudexplorer-dev/cloudexplorer-litecloudexplorer-dev/cloudexplorer-lite
CVE-2023-2844Authorization Bypass Through User-Controlled Key in cloudexplorer-dev/cloudexplorer-litecloudexplorer-dev/cloudexplorer-lite
CVE-2023-1314Local Privilege Escalation Vulnerability in cloudflared's InstallerCloudflare cloudflared
CVE-2022-3320Bypassing Cloudflare Zero Trust policies using warp-cli set-custom-endpoint commandCloudflare WARP
CVE-2022-29444WordPress Breeze plugin <= 2.0.2 - Plugin Settings Change leading to Cross-Site Scripting (XSS) vulnerabilityCloudways Breeze (WordPress plugin)
CVE-2022-2225Zero Trust Secure Web Gateway policies bypass using WARP client subcommandsCloudflare WARP
CVE-2021-41130X-Endpoint-API-UserInfo can be spoofed in cloudendpoints Extensible Service Proxycloudendpoints esp
CVE-2021-3978Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpkiCloudflare octorpki
CVE-2021-3912OctoRPKI crashes when processing GZIP bomb returned via malicious repositoryCloudflare octorpki
CVE-2021-3908Infinite certificate chain depth results in OctoRPKI running foreverCloudflare octorpki
CVE-2021-3761OctoRPKI lacks contextual out-of-bounds check when validating RPKI ROA maxLength valuesCloudflare octorpki
CVE-2020-5423Cloud Controller is vulnerable to denial of service via YAML parsingCloud Foundry CF Deployment
CVE-2020-5422UAA password may appear in BOSH System Metrics Server process argumentsCloud Foundry BOSH System Metrics Server
CVE-2020-5420Gorouter is vulnerable to DoS attack via invalid HTTP responsesCloud Foundry CF Deployment
CVE-2020-5418Cloud Controller allows users with no roles to list dropletsCloud Foundry CF Deployment
CVE-2020-5417Cloud Controller may allow developers to claim sensitive routesCloud Foundry CF Deployment
CVE-2020-5416CF clusters with NGINX in front of them may be vulnerable to DoSCloud Foundry CF Deployment
CVE-2020-5402UAA fails to check the state parameter when authenticating with external IDPsCloud Foundry UAA
200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.