VendorsApachecloudstackany version
Vulnerabilities

Apache Cloudstack any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

56CVEs
CVE-2025-69233
Apache CloudStack: Domain/account resources limits not honored
Published 2026-05-08 · Modified
6.5EPSS 0.004
CVE-2024-29008
Apache CloudStack: The extraconfig feature can be abused to load hypervisor resources on a VM instance
Published 2024-04-04 · Analyzed
6.4EPSS 0.006
CVE-2024-45461
Apache CloudStack Quota plugin: Access checks not enforced in Quota
Published 2024-10-16 · Modified
6.3EPSS 0.008
CVE-2026-66797
Apache CloudStack: Unauthorised comment creation and disclosure
Published 2026-08-21 · Analyzed
5.4EPSS 0.005
CVE-2014-9593
Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts API call.
Published 2015-01-15 · Modified
5.0EPSS 0.032
CVE-2026-61399
Apache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Lock User Function in UI
Published 2026-08-21 · Analyzed
4.8EPSS 0.005
CVE-2025-30675
Apache CloudStack: Unauthorised template/ISO list access to the domain/resource admins
Published 2025-06-10 · Analyzed
4.7EPSS 0.007
CVE-2025-59302
Apache CloudStack: Potential remote code execution on Javascript engine defined rules
Published 2025-11-27 · Analyzed
4.7EPSS 0.005
CVE-2013-2136
Multiple cross-site scripting (XSS) vulnerabilities in Apache CloudStack before 4.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Physical network name to the Zone wizard; (2) New network name, (3) instance name, or (4) group to the Instance wizard; (5) unspecified "multi-edit fields;" and (6) unspecified "list view" edit fields related to global settings.
Published 2013-08-19 · Modified
4.3EPSS 0.041
CVE-2025-22828
Apache CloudStack: Unauthorised access to annotations
Published 2025-01-13 · Analyzed
4.3EPSS 0.020
CVE-2026-65613
Apache CloudStack: Webhook Deliveries Incorrect Access
Published 2026-08-21 · Analyzed
4.3EPSS 0.005
CVE-2026-61422
Apache CloudStack: Authenticated pre-validation SSRF in registerTemplate
Published 2026-08-21 · Analyzed
4.3EPSS 0.004
CVE-2025-59454
Apache CloudStack: Lack of user permission validation leading to data leak for few APIs
Published 2025-11-27 · Analyzed
4.3EPSS 0.004
CVE-2014-0031
The (1) ListNetworkACL and (2) listNetworkACLLists APIs in Apache CloudStack before 4.2.1 allow remote authenticated users to list network ACLS for other users via a crafted request.
Published 2014-01-14 · Modified
4.0EPSS 0.022
CVE-2013-6398
The virtual router in Apache CloudStack before 4.2.1 does not preserve the source restrictions in firewall rules after being restarted, which allows remote attackers to bypass intended restrictions via a request.
Published 2014-01-14 · Modified
2.8EPSS 0.037
CVE-2026-66721
Apache CloudStack: Authorization issue with listHostTags for domain admins
Published 2026-08-21 · Analyzed
2.7EPSS 0.005
← Prev2 / 2