CVE Tools

Cloud

29 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Cloud, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Cloud CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Cloud CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-011
2026-020
2026-030
2026-040
2026-050
2026-061
2026-070
2026-080
2026-090

Severity

How the 29 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical414%
  • High931%
  • Medium1552%
  • Low13%

Latest CVEs

The 15 most recently published vulnerabilities affecting Cloud.

  1. CVE-2025-11919Unprotected temporary directories in Wolfram Cloud may result in privilege escalation9.6
  2. CVE-2026-20975Improper handling of insufficient permission in Samsung Cloud prior to version 5.6.11 allows local attackers to access specific files in arbitrary path.5.5
  3. CVE-2024-36982Denial of Service through null pointer reference in “cluster/config” REST endpoint7.5
  4. CVE-2024-36986Risky command safeguards bypass through Search ID query in Analytics Workspace6.3
  5. CVE-2024-36989Low-privileged user could create notifications in Splunk Web Bulletin Messages7.1
  6. CVE-2024-36987Insecure File Upload in the indexing/preview REST endpoint4.3
  7. CVE-2024-20851Improper access control vulnerability in Samsung Data Store prior to version 5.3.00.4 allows local attackers to launch arbitrary activity with Samsung Data Store privilege.4.4
  8. CVE-2024-23676Sensitive Information Disclosure of Index Metrics through “mrollup” SPL Command4.6
  9. CVE-2024-23677Server Response Disclosure in RapidDiag Salesforce.com Log File4.3
  10. CVE-2024-23675Splunk App Key Value Store (KV Store) Improper Handling of Permissions Leads to KV Store Collection Deletion6.5
  11. CVE-2023-42578Improper handling of insufficient permissions or privileges vulnerability in Samsung Data Store prior to version 5.2.00.7 allows remote attackers to access location information without permission.6.5
  12. CVE-2023-46213Cross-site Scripting (XSS) on “Show Syntax Highlighted” View in Search Page4.8
  13. CVE-2023-46214Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsing8.0
  14. CVE-2023-32764Fabasoft Cloud Enterprise Client 23.3.0.130 allows a user to escalate their privileges to local administrator.7.8
  15. CVE-2022-47874Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections via class 'com.jedox.etl.mngr.Connections' and method 'getG...6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store