vciy

CVEs we hold for Cloud

Records whose assigning authority named Cloud as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-73356WordPress Breeze plugin <= 2.5.12 - Arbitrary Content Deletion vulnerabilityCloudways Breeze
CVE-2026-62323Cloudreve: Unauthorized file write via WOPI view sessions whose access token secret is ignoredcloudreve
CVE-2026-59335Case-Sensitive Authorization Check Bypass via Identity Zone ID Case Manipulation Leads to Full UAA CompromiseCloud Foundry cf-deployment
CVE-2026-55769CloudNativePG: Overriding operators can lead to privilege escalation in CloudNativePG for SQL queries without a fixed…cloudnative-pg
CVE-2026-55765CloudNativePG: Cleartext role passwords recorded in pg_stat_statements allow privileged tenant roles to recover the…cloudnative-pg
CVE-2026-55502Cloudreve: OAuth Admin.Read scope can update OneDrive storage policy credentialscloudreve
CVE-2026-55499Cloudreve: Broken access control in file event stream leaks activity events for unshared siblings to single-file share…cloudreve
CVE-2026-55497Cloudreve: Server crash through image decompression/pixel bomb in thumbnail & avatar decoding (DoS)cloudreve
CVE-2026-55496Cloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because SearchActive() omits the…cloudreve
CVE-2026-55495Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Accountcloudreve
CVE-2026-54563Cloudreve: Path Traversal / Broken Access Control in Cloudreve WebDAV (`/dav`) — scoped DAV credential escapes its…cloudreve
CVE-2026-54562Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responsescloudreve
CVE-2026-54560Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claimcloudreve
CVE-2026-47840LDAP StartTLS unconditionally disables hostname verificationCloudFoundry Foundation Cf-deployment
CVE-2026-47839Federated OIDC Users Can Bypass externalGroupsWhitelist to Gain uaa.adminCloud Foundry Foundation cf-deployment
CVE-2026-47833no title heldCloud Foundry Foundation bpm-release
CVE-2026-47831Cryptographically Weak Password Generation in bosh-windows-stemcell-builder Allows Remote SSH Brute-Force AttacksCloud Foundry Foundation bosh-windows-stemcell-builder
CVE-2026-47830Incorrect Permission Assignment Allows Local Privilege Escalation to SYSTEM via Executable OverwriteCloud Foundry Foundation bosh-windows-stemcell-builder
CVE-2026-47829Argument Injection in BOSH CLI Allows Local Command Execution on Operator Workstations via Compromised DirectorCloudFoundry Foundation bosh-cli
CVE-2026-47827CVE-2026-47827 – BOSH CLI Powershell InjectionCloud Foundry Foundation BOSH CLI
CVE-2026-47826blobs.yaml Path Traversal Allows File WritesCloudFoundry Foundation BOSH CLI tool
CVE-2026-45782Cloud Hypervisor: Use-after-free in virtio-block Async I/O Completioncloud-hypervisor
CVE-2026-45291Cloudburst Network erroneously handles invalid connectionsCloudburstMC Network
CVE-2026-45290Cloudburst Network has DoS in RakNet connection handling due to missing bound checksCloudburstMC Network
CVE-2026-45289CloudburstMC Protocol: Partially missing validation for FULL type authentication tokensCloudburstMC Protocol
CVE-2026-45132CloudPirates Open Source Helm Charts: GitHub Actions workflow leaks PAT and SSH signing key via unsafe credential…CloudPirates-io helm-charts
CVE-2026-45131CloudPirates Open Source Helm Charts: GitHub Actions pull_request_target workflow allows secret exfiltration via fork…CloudPirates-io helm-charts
CVE-2026-44477CloudNativePG: Metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCEcloudnative-pg
CVE-2026-41861Arbitrary Root File Write via Path Traversal in BOSH agentCloudFoundry Foundation BOSH
CVE-2026-41860no title heldCloud Foundry Foundation BOSH
CVE-2026-41859no title heldCloud Foundry Foundation BOSH
CVE-2026-41858no title heldCloud Foundry Foundation windows-utilities-release
CVE-2026-41857BOSH CLI Shell InjectionCloudFoundry BOSH BOSH CLI
CVE-2026-41704Compromised VM can make arbitrary blobstore deletesCloud Foundry Foundation BOSH Director
CVE-2026-41013Tenant-controlled comma smuggles arbitrary CIFS mount optionsCloudFoundry Foundation CF Deployment
CVE-2026-41012BOSH vSphere CPI Improper Cert ValidationCloud Foundry bosh-vsphere-cpi-release
CVE-2026-41011no title heldCloud Foundry Foundation BOSH
CVE-2026-41010no title heldCloud Foundry Foundation BOSH Director
CVE-2026-41009Local Blobstore may allow arbitrary reads/deletesCloud Foundry Foundation BOSH Director
CVE-2026-41005UAA accepts SAML Encrypted Assertions authentication bypassCloud Foundry CF Deployment
CVE-2026-40965no title heldCloud Foundry Foundation CF Deployment
CVE-2026-40964no title heldCloud Foundry Foundation CF Deployment
CVE-2026-3844Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remotecloudways Breeze Cache
CVE-2026-35023Wimi Teamwork On-Premises < 8.2.0 IDOR via preview.phpCloud Solutions SAS Wimi Teamwork
CVE-2026-32254Kube-router Proxy Module Blindly Trusts ExternalIPs/LoadBalancer IPs Enabling Cluster-Wide Traffic Hijacking and DNS DoScloudnativelabs kube-router
CVE-2026-2836Cache poisoning via insecure-by-default cache keyCloudflare https://github.com/cloudflare/pingora
CVE-2026-2835HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding MisparsingCloudflare https://github.com/cloudflare/pingora
CVE-2026-2833HTTP Request Smuggling via Premature UpgradeCloudflare https://github.com/cloudflare/pingora
CVE-2026-27652CloudCharge cloudcharge.se Insufficient Session ExpirationCloudCharge cloudcharge.se
CVE-2026-27211Cloud Hypervisor: Host File Exfiltration via QCOW Backing File Abusecloud-hypervisor
CVE-2026-25768LavinMQ is missing vhost access controlcloudamqp lavinmq
CVE-2026-25767LavinMQ has incomplete shovel configuration validationcloudamqp lavinmq
CVE-2026-25726Cloudreve is vulnerable to Account Takeover via Weak Cryptographic Token Generation (Insecure PRNG Seeding)cloudreve
CVE-2026-25114CloudCharge cloudcharge.se Improper Restriction of Excessive Authentication AttemptsCloudCharge cloudcharge.se
CVE-2026-24560WordPress Cloudinary plugin <= 3.3.2 - Broken Access Control vulnerabilityCloudinary
CVE-2026-24525WordPress CLP Varnish Cache plugin <= 1.0.2 - Broken Access Control vulnerabilityCloudPanel CLP Varnish Cache
CVE-2026-22734Cloud Foundry UAA SAML 2.0 Signature BypassCloud Foundry UUA
CVE-2026-22727Cloud Foundry unprotected internal endpointsCloudfoundry Cloud Foundry
CVE-2026-22726Route Services Firewall BypassCloudFoundry Foundation CF Deployment
CVE-2026-22723UAA User Token Revocation logic errorCloudfoundry Foundation UAA
CVE-2026-2128Breeze Cache <= 2.5.2 - Unauthenticated Exposure of Sensitive Information to an Unauthorized Actor via Crafted Login…cloudways Breeze Cache
CVE-2026-20781CloudCharge cloudcharge.se Missing Authentication for Critical FunctionCloudCharge cloudcharge.se
CVE-2026-20733CloudCharge cloudcharge.se Insufficiently Protected CredentialsCloudCharge cloudcharge.se
CVE-2026-14440Cloudflare Universal SSL automatically managed CAA RRset supersedes customer-configured CAA recordsCloudflare Universal SSL
CVE-2026-12707Unbounded path event queue growth in quiche via peer-driven source connection ID rotationCloudflare quiche
CVE-2026-12523Resource exhaustion in quiche HTTP/3 and QPACK layersCloudflare quiche
CVE-2026-1229Incorrect calculation in CIRCL secp384r1 CombinedMultCloudflare CIRCL
CVE-2026-11941Use-after-free in connection ID iterator and FFI functionsCloudflare Quiche
CVE-2026-11325cloudflare/pages-action is deprecated — migration required by September 18th, 2026Cloudflare https://github.com/cloudflare/pages-action
CVE-2026-0933OS Command Injection in `wrangler pages deploy`Cloudflare Wrangler
CVE-2025-8529cloudfavorites favorites-web CollectController.java getCollectLogoUrl server-side request forgerycloudfavorites favorites-web
CVE-2025-7054Infinite loop triggered by connection ID retirementCloudflare quiche
CVE-2025-7045Cloud SAML SSO <= 1.0.19 - Missing Authorization to Unauthenticated Identity Provider Deletion via delete_config Actioncloudinfrastructureservices Cloud SAML SSO – Single Sign On…
CVE-2025-7040Cloud SAML SSO <= 1.0.19 - Missing Authorization to Unauthenticated Settings Modification via set_organization_settings…cloudinfrastructureservices Cloud SAML SSO – Single Sign On…
CVE-2025-69364WordPress Breeze plugin <= 2.2.21 - Broken Access Control vulnerabilityCloudways Breeze
CVE-2025-59427Cloudflare vite plugin exposes secrets over the built-in dev servercloudflare workers-sdk
CVE-2025-49264WordPress Cloud SAML SSO - Single Sign On Login <= 1.0.18 - Local File Inclusion VulnerabilityCloud SAML SSO - Single Sign On Login
CVE-2025-4821Incorrect congestion window growth by invalid ACK rangesCloudflare quiche
CVE-2025-4820Incorrect congestion window growth by optimistic ACKCloudflare quiche
CVE-2025-3884Cloudera Hue Ace Editor Directory Traversal Information Disclosure VulnerabilityCloudera Hue
CVE-2025-34133Wimi Teamwork < v7.38.17 CSRFCloud Solutions SAS Wimi Teamwork
CVE-2025-31807WordPress Product Notices for WooCommerce plugin <= 1.3.4 - Cross Site Request Forgery (CSRF) vulnerabilityCloudRedux Product Notices for WooCommerce
CVE-2025-23999WordPress Breeze plugin <= 2.2.13 - Broken Access Control vulnerabilityCloudways Breeze
CVE-2025-23721WordPress Mobigate plugin <= 1.0.3 - Reflected Cross Site Scripting (XSS) vulnerabilitycloudvn Mobigate
CVE-2025-22246CVE-2025-22246 – UAA Private Key ExposureCloud Foundry CF deployment
CVE-2025-22216CVE-2025-22216 UAA Missing Zone ValidationCloud Foundry UAA
CVE-2025-15241CloudPanel Community Edition HTTP Header users redirectCloudPanel Community Edition
CVE-2025-13864Breeze – WordPress Cache Plugin <= 2.2.21 - Missing Authorization to Cache Deletioncloudways Breeze Cache
CVE-2025-13353gokey allows secret recovery from a seed file without the master passwordCloudflare gokey
CVE-2025-12613no title heldn/a cloudinary
CVE-2025-11757Improper Neutralization of Wildcards or Matching Symbols in CloudEdge Online Cameras and AppCloudEdge App
CVE-2025-0651File symlink abuse might lead to deleting files belonging to SYSTEM userCloudflare WARP
CVE-2024-50431WordPress Breeze plugin <= 2.1.14 - Cross Site Scripting (XSS) vulnerabilityCloudways Breeze
CVE-2024-50422WordPress Breeze plugin <= 2.1.14 - Broken Access Control vulnerabilityCloudways Breeze
CVE-2024-45389Pagefind DOM clobbering could escalate to Cross-site Scripting (XSS)CloudCannon pagefind
CVE-2024-38826CVE-2024-38826 Cloud Controller Denial of Service AttackCloud Foundry
CVE-2024-37082no title heldCloud Foundry haproxy-boshrelease
CVE-2024-30249Cloudburst Network DoS in RakNet connection handlingCloudburstMC Network
CVE-2024-28110Go SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentialscloudevents sdk-go
CVE-2024-27188WordPress Breeze plugin <= 2.1.3 - Cross Site Scripting (XSS) vulnerabilityCloudways Breeze
CVE-2024-22279GoRouter Denial of Service AttackCloud Foundry Routing Release
CVE-2024-1765Unlimited resource allocation by QUIC CRYPTO frames flooding in quicheCloudflare quiche
CVE-2024-1410Unbounded storage of information related to connection ID retirement, in quicheCloudflare quiche
CVE-2024-0212Cloudflare WordPress plugin enables information disclosure of Cloudflare API (for low privileged users)Cloudflare-WordPress
CVE-2023-7080Arbitrary remote code execution within wrangler dev Workers sandboxCloudflare wrangler
CVE-2023-7079Arbitrary remote file read in Wrangler dev serverCloudflare wrangler
CVE-2023-7078Server-Side Request Forgery (SSRF) in MiniflareCloudflare miniflare
CVE-2023-6992Memory corruption issues is Cloudflare zlib implementationCloudflare zlib
CVE-2023-6549no title heldCloud Software Group NetScaler ADC
CVE-2023-6548no title heldCloud Software Group NetScaler Gateway
CVE-2023-6193Unbounded queuing of path validation messages in cloudflare-quicheCloudflare quiche
CVE-2023-6184no title heldCloud Software Group Citrix Session Recording
CVE-2023-6180Resource exhaustion via memory leak in tokio-boringCloudflare tokio-boring
CVE-2023-5914no title heldCloud Software Group Citrix StoreFront
CVE-2023-4967Denial of serviceCloud Software Group NetScaler Gateway
CVE-2023-44397CloudExplorer Lite permission bypass vulnerabilityCloudExplorer-Dev CloudExplorer-Lite
CVE-2023-4241lol-html panics on certain HTML inputsCloudflare lol-html
CVE-2023-39519CloudExplorer Lite sensitive information leakage vulnerabilityCloudExplorer-Dev CloudExplorer-Lite
CVE-2023-38692Command injection vulnerability in module management function in CloudExplorer LiteCloudExplorer-Dev CloudExplorer-Lite
CVE-2023-3766Invalid Slice Split Results in Server PanicCloudflare odoh-rs
CVE-2023-3747Insufficient Validation on Override Codes for Always-Enabled WARP ModeCloudflare WARP Client
CVE-2023-34240Weak passwords allowed in cloudexplorer-liteCloudExplorer-Dev CloudExplorer-Lite
CVE-2023-3423Weak Password Requirements in cloudexplorer-dev/cloudexplorer-litecloudexplorer-dev/cloudexplorer-lite
CVE-2023-34061CVE-2023-34061 – Gorouter route pruningCloud Foundry CF deployment
CVE-2023-34041CVE-2023-34041-Abuse of HTTP Hop-by-Hop Headers in Cloud Foundry GorouterCloud Foundry CF Deployment
CVE-2023-3348Directory traversal vulnerability in Cloudflare WranglerCloudflare Wrangler
CVE-2023-32591WordPress DBargain Plugin <= 3.0.0 is vulnerable to Cross Site Scripting (XSS)Cloud Primero B.V DBargain
CVE-2023-32316Users can add themselves to any organization in CloudExplorer LiteCloudExplorer-Dev CloudExplorer-Lite
CVE-2023-32311The CloudExplorer Lite missing permissions checkCloudExplorer-Dev CloudExplorer-Lite
CVE-2023-30612Malicious HTTP requests could close arbitrary opening file descriptors in cloud-hypervisorcloud-hypervisor
CVE-2023-3040Out of Bounds Access Leading to Undefined BehaviorCloudflare lua-resty-json
CVE-2023-3036Out of Bounds Slice index in cfnts leads to remote panicCloudflare cfnts
CVE-2023-2845Improper Access Control in cloudexplorer-dev/cloudexplorer-litecloudexplorer-dev/cloudexplorer-lite
CVE-2023-2844Authorization Bypass Through User-Controlled Key in cloudexplorer-dev/cloudexplorer-litecloudexplorer-dev/cloudexplorer-lite
CVE-2023-2754Plaintext transmission of DNS requests in Windows 1.1.1.1 WARP clientCloudflare WARP
CVE-2023-2512Buffer under-read in workerdCloudflare workerd
CVE-2023-24546no title heldn/a CloudVision
CVE-2023-20903no title heldn/a Cloud Foundry
CVE-2023-20885CF workflows leak credentials in system audit logsCloud FOundry cf-nfs-volume release
CVE-2023-20882no title heldn/a Cloud Foundry Routing release
CVE-2023-20881no title heldn/a Cloud Controller API
CVE-2023-1862Remote access to warp-svc.exe in Cloudflare WARPCloudflare WARP Client
CVE-2023-1732Improper random reading in CIRCLCloudflare CIRCL
CVE-2023-1412Local Privilege Escalation Vulnerability in WARP's MSI InstallerCloudflare WARP
CVE-2023-1314Local Privilege Escalation Vulnerability in cloudflared's InstallerCloudflare cloudflared
CVE-2023-0654Spoofing User's Activity Loads in WARP Mobile Client (Android)Cloudflare WARP Client
CVE-2023-0652Local Privilege Escalation in Cloudflare WARP Installer (Windows)Cloudflare WARP
CVE-2023-0421Cloud Manager <= 1.0 - Reflected XSSUnknown Cloud Manager
CVE-2023-0238Injecting Activity Loads in WARP Mobile ClientCloudflare WARP Client
CVE-2022-4960cloudfavorites favorites-web Nickname cross site scriptingcloudfavorites favorites-web
CVE-2022-4773cloudsync LocalFilesystemConnector.java getItem path traversaln/a cloudsync
CVE-2022-4457WARP client manifest misconfiguration leading to Task HijackingCloudflare WARP
CVE-2022-4428support_uri validation missing in WARP client for WindowsCloudflare WARP
CVE-2022-3616OctoRPKI crash when maximum iterations number is reachedCloudflare OctoRPKI
CVE-2022-3512Lock WARP switch bypass using warp-cli 'add-trusted-ssid' commandCloudflare WARP
CVE-2022-3337Lock WARP switch bypass by removing VPN profile on iOS mobile clientCloudflare WARP
CVE-2022-3322Lock WARP switch bypass on WARP mobile client using iOS quick actionCloudflare WARP
CVE-2022-3321Lock WARP switch feature bypass on WARP mobile client for iOSCloudflare WARP
CVE-2022-3320Bypassing Cloudflare Zero Trust policies using warp-cli set-custom-endpoint commandCloudflare WARP
CVE-2022-32167Cloudreve - Stored XSSCloudreve
CVE-2022-31733no title heldn/a Cloud Foundry Diego and CF Deployment
CVE-2022-29444WordPress Breeze plugin <= 2.0.2 - Plugin Settings Change leading to Cross-Site Scripting (XSS) vulnerabilityCloudways Breeze (WordPress plugin)
CVE-2022-2529Multiple DoS Attack Vectors in sflow packet handlingCloudflare goflow
CVE-2022-2225Zero Trust Secure Web Gateway policies bypass using WARP client subcommandsCloudflare WARP
CVE-2022-2147Unquoted Service Path in Cloudflare WARP for WindowsCloudflare WARP
CVE-2022-2145Cloudlfare WARP Arbitrary File OverwriteCloudflare WARP
CVE-2021-41130X-Endpoint-API-UserInfo can be spoofed in cloudendpoints Extensible Service Proxycloudendpoints esp
CVE-2021-40008no title heldn/a CloudEngine 12800;CloudEngine 5800;CloudEngine 6800…
CVE-2021-39976no title heldn/a CloudEngine 5800
CVE-2021-3978Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpkiCloudflare octorpki
CVE-2021-3912OctoRPKI crashes when processing GZIP bomb returned via malicious repositoryCloudflare octorpki
CVE-2021-3911Misconfigured IP address field in ROA leads to OctoRPKI crashCloudflare octorpki
CVE-2021-3910NUL character in ROA causes OctoRPKI to crashCloudflare octorpki
CVE-2021-3909Infinite open connection causes OctoRPKI to hang foreverCloudflare octorpki
CVE-2021-3908Infinite certificate chain depth results in OctoRPKI running foreverCloudflare octorpki
CVE-2021-3907Arbitrary filepath traversal via URI injectionCloudflare octorpki
CVE-2021-3761OctoRPKI lacks contextual out-of-bounds check when validating RPKI ROA maxLength valuesCloudflare octorpki
CVE-2021-37122no title heldn/a CloudEngine 12800;CloudEngine 5800;CloudEngine 6800…
CVE-2021-27002no title heldn/a Cloud Manager
CVE-2021-26992no title heldn/a Cloud Manager
CVE-2021-26991no title heldn/a Cloud Manager
CVE-2021-26990no title heldn/a Cloud Manager
CVE-2021-22393no title heldn/a CloudEngine 12800;CloudEngine 5800;CloudEngine 6800…
CVE-2021-22362no title heldn/a CloudEngine 12800;CloudEngine 5800;CloudEngine 6800…
CVE-2021-22332no title heldn/a CloudEngine 12800;CloudEngine 5800;CloudEngine 6800…
CVE-2021-22328no title heldn/a CloudEngine 12800;CloudEngine 5800;CloudEngine 6800…
CVE-2021-22115no title heldn/a Cloud Control API
CVE-2021-22101no title heldn/a Cloud Foundry Cloud Controller
CVE-2021-22100no title heldn/a Cloud Controller (CAPI) by cloud foundry
CVE-2021-22001no title heldn/a Cloud Foundry UAA server
CVE-2021-21956no title heldCloudLinux Inc Imunify360
CVE-2020-9137no title heldn/a CloudEngine 12800;CloudEngine 5800;CloudEngine 6800…
CVE-2020-9120no title heldn/a CloudEngine 1800V
CVE-2020-5423Cloud Controller is vulnerable to denial of service via YAML parsingCloud Foundry CF Deployment
CVE-2020-5422UAA password may appear in BOSH System Metrics Server process argumentsCloud Foundry BOSH System Metrics Server
CVE-2020-5420Gorouter is vulnerable to DoS attack via invalid HTTP responsesCloud Foundry CF Deployment
CVE-2020-5418Cloud Controller allows users with no roles to list dropletsCloud Foundry CF Deployment
CVE-2020-5417Cloud Controller may allow developers to claim sensitive routesCloud Foundry CF Deployment
CVE-2020-5416CF clusters with NGINX in front of them may be vulnerable to DoSCloud Foundry CF Deployment
CVE-2020-5402UAA fails to check the state parameter when authenticating with external IDPsCloud Foundry UAA

200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.