← apache

apache / cloudstack

20 known vulnerabilities in apache cloudstack.

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-61400 Medium 1.5% 8.8 Improper Neutralization of Special Elements used in a Command ('Command Injectio…
CVE-2026-47359 Medium 1.1% 8.8 Improper Neutralization of Special Elements used in an OS Command ('OS Command I…
CVE-2026-50112 Medium 0.5% 8.8 SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a…
CVE-2026-59655 Medium 0.3% 7.5 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apac…
CVE-2026-59780 Medium 0.3% 7.5 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apac…
CVE-2026-61397 Medium 0.3% 7.5 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apac…
CVE-2026-66722 Medium 0.3% 7.2 Improper authorization for CRUD operations on Project Roles and Project Role per…
CVE-2026-59654 Medium 0.3% 7.5 Missing Release of Resource after Effective Lifetime vulnerability in Apache Clo…
CVE-2026-59085 Medium 0.3% 9.1 Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook …
CVE-2026-59799 Medium 0.3% 8.8 Improper Privilege Management vulnerability in Apache CloudStack's Two-factor au…
CVE-2026-61398 Medium 0.3% 9.1 Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI …
CVE-2026-50222 Medium 0.3% 7.5 Missing Authorization, Exposure of Sensitive Information to an Unauthorized Acto…
CVE-2026-62440 Medium 0.3% 9.1 Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service …
CVE-2026-59657 Medium 0.2% 7.5 Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack wi…
CVE-2026-68745 Medium 0.1% 8.1 Certificate validation failures in SAML authentication in Apache CloudStack 4.20…
CVE-2026-61399 Low 0.3% 4.8 Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI …
CVE-2026-66721 Low 0.3% 2.7 Missing authorization issue for domain admins in CloudStack's host tags listing …
CVE-2026-66797 Low 0.3% 5.4 Improper access control in CloudStack's annotation functionality allows unauthor…
CVE-2026-65613 Low 0.3% 4.3 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apac…
CVE-2026-61422 Low 0.2% 4.3 Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template …