CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-59654 MEDIUM

Apache CloudStack: DoS caused by database connections leak

CVSS 6.8 EPSS 0.59% Aug 21, 2026
CVE-2026-47359 HIGH

Apache CloudStack: OS Command Injection due to unsanitized mount command

CVSS 8.8 EPSS 2.03% Aug 21, 2026
CVE-2026-50112 HIGH

Apache CloudStack: RCE and SSRF in direct download, metalink and NFS templates

CVSS 8.8 EPSS 0.72% Aug 21, 2026
CVE-2026-50222 HIGH

Apache CloudStack: Improper access control in Userdata reference APIs

CVSS 7.5 EPSS 0.54% Aug 21, 2026
CVE-2026-59085 CRITICAL

Apache CloudStack: Server-Side Request Forgery (SSRF) vulnerability in webhook module

CVSS 9.1 EPSS 0.59% Aug 21, 2026
CVE-2026-59655 HIGH

Apache CloudStack: Unauthenticated OAuth provider client-secret disclosure

CVSS 7.5 EPSS 0.60% Aug 21, 2026
CVE-2026-59657 HIGH

Apache CloudStack: Sensitive Information Disclosure via Cleartext Storage in AsyncJob

CVSS 7.5 EPSS 0.34% Aug 21, 2026
CVE-2026-59780 HIGH

Apache CloudStack: LDAP provider configuration disclosure

CVSS 7.5 EPSS 0.60% Aug 21, 2026
CVE-2026-59799 HIGH

Apache CloudStack: Missing Privilege Check in Two-Factor Authentication Disable Flow

CVSS 8.8 EPSS 0.60% Aug 21, 2026
CVE-2026-61397 HIGH

Apache CloudStack: OAuth2 Token Cross-Request Leak

CVSS 7.5 EPSS 0.60% Aug 21, 2026
CVE-2026-61398 CRITICAL

Apache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Instance Reset Password Function in UI

CVSS 9.1 EPSS 0.57% Aug 21, 2026
CVE-2026-61399 MEDIUM

Apache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Lock User Function in UI

CVSS 4.8 EPSS 0.50% Aug 21, 2026
CVE-2026-61400 HIGH

Apache CloudStack: Get and Run Diagnostics Command Injection

CVSS 8.8 EPSS 2.91% Aug 21, 2026
CVE-2026-61422 MEDIUM

Apache CloudStack: Authenticated pre-validation SSRF in registerTemplate

CVSS 4.3 EPSS 0.41% Aug 21, 2026
CVE-2026-62440 CRITICAL

Apache CloudStack: Improper access control in Kubernetes Service (CKS) cluster manipulation

CVSS 9.1 EPSS 0.54% Aug 21, 2026
CVE-2026-65613 MEDIUM

Apache CloudStack: Webhook Deliveries Incorrect Access

CVSS 4.3 EPSS 0.45% Aug 21, 2026
CVE-2026-66721 LOW

Apache CloudStack: Authorization issue with listHostTags for domain admins

CVSS 2.7 EPSS 0.48% Aug 21, 2026
CVE-2026-66722 HIGH

Apache CloudStack: ProjectRole & ProjectRolePermission authorization issue

CVSS 7.2 EPSS 0.62% Aug 21, 2026
CVE-2026-66797 HIGH

Apache CloudStack: Unauthorised comment creation and disclosure

CVSS 8.5 EPSS 0.46% Aug 21, 2026
CVE-2026-68745 HIGH

Apache CloudStack: SAML2 Signature Validation Silently Skipped for Cert-less IdP

CVSS 8.1 EPSS 0.20% Aug 21, 2026
CVE-2026-25199 CRITICAL

Apache CloudStack: Proxmox Extension Allows Unauthorized Cross-Tenant Instance Access

CVSS 9.1 EPSS 0.50% May 8, 2026
CVE-2026-25077 HIGH

Apache CloudStack: Unauthenticated Command Injection in Direct Download Templates

CVSS 8.8 EPSS 0.73% May 8, 2026
CVE-2025-69233 MEDIUM

Apache CloudStack: Domain/account resources limits not honored

CVSS 6.5 EPSS 0.43% May 8, 2026
CVE-2025-66467 HIGH

Apache CloudStack: MinIO policy remains intact on bucket deletion

CVSS 8.1 EPSS 0.37% May 8, 2026
CVE-2025-66172 HIGH

Apache CloudStack: Any user can attach a volume in their VMs from backups they should not have access to

CVSS 8.1 EPSS 0.51% May 8, 2026

Showing 1 to 25 CVEs · page 1 (more available)