Vulnerabilidades en Google Cloud
44 resultadosAnálisis Vexday
Google Cloud registra 40 vulnerabilidades na base Vexday, das quais 11 são críticas, mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é autorização inadequada (CWE-862), e 9 CVEs foram publicadas nos últimos 90 dias, indicando risco recente que demanda atenção nas camadas de controle de acesso.
CVE-2025-12397HIGHSQL Injection in Looker StudioEPSS 0.3%CVE-2025-12739HIGHCross-Site Scripting (XSS) in Looker's Extension Loader leading to Admin Account CompromiseEPSS 0.3%CVE-2025-11915MEDIUMHTTP Desynchronisation in Vertex AI for certain third-party modelsEPSS 0.3%CVE-2026-12879MEDIUMCross-Tenant Data Exfiltration in Apigee via BigQuery Confused DeputyEPSS 0.3%CVE-2025-13292HIGHImproper access control in Google Cloud Apigee-X allows cross-tenant Analytics modification and log data access.EPSS 0.3%CVE-2025-12743MEDIUMSQL Injection in Looker Project Generation Endpoint Allows Access to Internal MySQL DatabaseEPSS 0.3%CVE-2025-0982CRITICALSandbox Escape in Google Cloud Application Integration's JavaScript Task (Rhino Engine)EPSS 0.3%CVE-2025-12405HIGHUnauthorized access through stored credentials in Looker StudioEPSS 0.3%CVE-2025-12472HIGHRemote Code Execution in Looker due to Improperly Validated Directory DeletionEPSS 0.3%CVE-2026-1727CRITICALInformation Disclosure via Bucket Squatting in Google Cloud Agentspace.EPSS 0.3%CVE-2025-12409HIGHSQL Injection in Looker StudioEPSS 0.3%CVE-2026-2244HIGHSensitive Data Exposure in Google Cloud Vertex AI WorkbenchEPSS 0.2%CVE-2025-12740HIGHRemote Command Execution in Looker via IBM DB2 JDBC driveEPSS 0.2%CVE-2025-12741HIGHArbitrary File Write in Denodo dialect of Looker allows Remote Code ExecutionEPSS 0.2%CVE-2026-7428CRITICALInsecure default administrative credentials in AlloyDB for PostgreSQLEPSS 0.2%CVE-2025-12742HIGHRemote Code Execution in Looker via Teradata JDBC DriverEPSS 0.2%CVE-2026-3259HIGHSensitive Data Disclosure in BigQuery via Materialized View Error MessagesEPSS 0.2%CVE-2026-15623CRITICALAuthenticated Blind SQL Injection in Google Cloud SecOps SOAR Dashboard Widget Query ServiceEPSS 0.2%CVE-2026-12537CRITICALUnauthenticated Remote Code Execution in Gemini CLI CI/CD WorkflowsEPSS 0.2%CVE-2026-4764CRITICALPrivilege Escalation in Dialogflow CX via Playbook ImportEPSS 0.2%