Apache / Apache Cloudstack
51 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-66171 | Apache CloudStack: Any user can create a new VM from backups they should not have access to | MEDIUM | 6.5 | May 8, 2026 |
| CVE-2025-66170 | Apache CloudStack: Any user can list backups that they should not have access to | MEDIUM | 6.5 | May 8, 2026 |
| CVE-2025-59302 | Apache CloudStack: Potential remote code execution on Javascript engine defined rules | MEDIUM | 4.7 | Nov 27, 2025 |
| CVE-2025-59454 | Apache CloudStack: Lack of user permission validation leading to data leak for few APIs | MEDIUM | 4.3 | Nov 27, 2025 |
| CVE-2025-30675 | Apache CloudStack: Unauthorised template/ISO list access to the domain/resource admins | MEDIUM | 4.7 | Jun 10, 2025 |
| CVE-2025-22829 | Apache CloudStack: Unauthorised access to dedicated resources in Quota plugin | LOW | 2.3 | Jun 10, 2025 |
| CVE-2025-26521 | Apache CloudStack: CKS cluster in project exposes user API keys | HIGH | 8.1 | Jun 10, 2025 |
| CVE-2025-47849 | Apache CloudStack: Insecure access of user's API/Secret Keys in the same domain | HIGH | 8.8 | Jun 10, 2025 |
| CVE-2025-47713 | Apache CloudStack: Domain Admin can reset Admin password in Root Domain | HIGH | 8.8 | Jun 10, 2025 |
| CVE-2025-22828 | Apache CloudStack: Unauthorised access to annotations | MEDIUM | 4.3 | Jan 13, 2025 |
| CVE-2024-50386 | Apache CloudStack: Directly downloaded templates can be used to abuse KVM-based infrastructure | CRITICAL | 9.9 | Nov 12, 2024 |
| CVE-2024-45219 | Apache CloudStack: Uploaded and registered templates and volumes can be used to abuse KVM-based infrastructure | HIGH | 8.5 | Oct 16, 2024 |
| CVE-2024-45462 | Apache CloudStack: Incomplete session invalidation on web interface logout | HIGH | 7.1 | Oct 16, 2024 |
| CVE-2024-45693 | Apache CloudStack: Request origin validation bypass makes account takeover possible | HIGH | 8.8 | Oct 16, 2024 |
| CVE-2024-42062 | Apache CloudStack: User Key Exposure to Domain Admins | HIGH | 7.2 | Aug 7, 2024 |
| CVE-2024-42222 | Apache CloudStack: Unauthorised Network List Access | MEDIUM | 4.3 | Aug 7, 2024 |
| CVE-2024-41107 | Apache CloudStack: SAML Signature Exclusion | HIGH | 8.1 | Jul 19, 2024 |
| CVE-2024-38346 | Apache CloudStack: Unauthenticated cluster service port leads to remote execution | CRITICAL | 9.8 | Jul 5, 2024 |
| CVE-2024-39864 | Apache CloudStack: Integration API service uses dynamic port when disabled | CRITICAL | 9.8 | Jul 5, 2024 |
| CVE-2024-29008 | Apache CloudStack: The extraconfig feature can be abused to load hypervisor resources on a VM instance | MEDIUM | 6.4 | Apr 4, 2024 |
| CVE-2024-29007 | Apache CloudStack: When downloading templates or ISOs, the management server and SSVM follow HTTP redirects with potentially dangerous consequences | HIGH | 7.3 | Apr 4, 2024 |
| CVE-2024-29006 | Apache CloudStack: x-forwarded-for HTTP header parsed by default | CRITICAL | 9.8 | Apr 4, 2024 |
| CVE-2022-35741 | Apache CloudStack SAML Single Sign-On XXE | CRITICAL | 9.8 | Jul 18, 2022 |
| CVE-2022-26779 | Apache Cloudstack insecure random number generation affects project email invitation | HIGH | 7.5 | Mar 15, 2022 |
| CVE-2016-6813 | Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious user is able to det… | CRITICAL | 9.8 | Feb 6, 2018 |
Showing 26 to 50 of 51 CVEs