apache / cloudstack
20 known vulnerabilities in apache cloudstack.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-61400 | Medium | 1.5% | 8.8 | Improper Neutralization of Special Elements used in a Command ('Command Injectio… | |
| CVE-2026-47359 | Medium | 1.1% | 8.8 | Improper Neutralization of Special Elements used in an OS Command ('OS Command I… | |
| CVE-2026-50112 | Medium | 0.5% | 8.8 | SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a… | |
| CVE-2026-59655 | Medium | 0.3% | 7.5 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apac… | |
| CVE-2026-59780 | Medium | 0.3% | 7.5 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apac… | |
| CVE-2026-61397 | Medium | 0.3% | 7.5 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apac… | |
| CVE-2026-66722 | Medium | 0.3% | 7.2 | Improper authorization for CRUD operations on Project Roles and Project Role per… | |
| CVE-2026-59654 | Medium | 0.3% | 7.5 | Missing Release of Resource after Effective Lifetime vulnerability in Apache Clo… | |
| CVE-2026-59085 | Medium | 0.3% | 9.1 | Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook … | |
| CVE-2026-59799 | Medium | 0.3% | 8.8 | Improper Privilege Management vulnerability in Apache CloudStack's Two-factor au… | |
| CVE-2026-61398 | Medium | 0.3% | 9.1 | Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI … | |
| CVE-2026-50222 | Medium | 0.3% | 7.5 | Missing Authorization, Exposure of Sensitive Information to an Unauthorized Acto… | |
| CVE-2026-62440 | Medium | 0.3% | 9.1 | Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service … | |
| CVE-2026-59657 | Medium | 0.2% | 7.5 | Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack wi… | |
| CVE-2026-68745 | Medium | 0.1% | 8.1 | Certificate validation failures in SAML authentication in Apache CloudStack 4.20… | |
| CVE-2026-61399 | Low | 0.3% | 4.8 | Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI … | |
| CVE-2026-66721 | Low | 0.3% | 2.7 | Missing authorization issue for domain admins in CloudStack's host tags listing … | |
| CVE-2026-66797 | Low | 0.3% | 5.4 | Improper access control in CloudStack's annotation functionality allows unauthor… | |
| CVE-2026-65613 | Low | 0.3% | 4.3 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apac… | |
| CVE-2026-61422 | Low | 0.2% | 4.3 | Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template … |