Cloud
29 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Cloud, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Cloud CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 1 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 29 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical4
- High9
- Medium15
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Cloud.
- CVE-2025-11919Unprotected temporary directories in Wolfram Cloud may result in privilege escalation9.6
- CVE-2026-20975Improper handling of insufficient permission in Samsung Cloud prior to version 5.6.11 allows local attackers to access specific files in arbitrary path.5.5
- CVE-2024-36982Denial of Service through null pointer reference in “cluster/config” REST endpoint7.5
- CVE-2024-36986Risky command safeguards bypass through Search ID query in Analytics Workspace6.3
- CVE-2024-36989Low-privileged user could create notifications in Splunk Web Bulletin Messages7.1
- CVE-2024-36987Insecure File Upload in the indexing/preview REST endpoint4.3
- CVE-2024-20851Improper access control vulnerability in Samsung Data Store prior to version 5.3.00.4 allows local attackers to launch arbitrary activity with Samsung Data Store privilege.4.4
- CVE-2024-23676Sensitive Information Disclosure of Index Metrics through “mrollup” SPL Command4.6
- CVE-2024-23677Server Response Disclosure in RapidDiag Salesforce.com Log File4.3
- CVE-2024-23675Splunk App Key Value Store (KV Store) Improper Handling of Permissions Leads to KV Store Collection Deletion6.5
- CVE-2023-42578Improper handling of insufficient permissions or privileges vulnerability in Samsung Data Store prior to version 5.2.00.7 allows remote attackers to access location information without permission.6.5
- CVE-2023-46213Cross-site Scripting (XSS) on “Show Syntax Highlighted” View in Search Page4.8
- CVE-2023-46214Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsing8.0
- CVE-2023-32764Fabasoft Cloud Enterprise Client 23.3.0.130 allows a user to escalate their privileges to local administrator.7.8
- CVE-2022-47874Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections via class 'com.jedox.etl.mngr.Connections' and method 'getG...6.5
Product grouping is registry-driven, with AI assist and human review. How it works