Vulnerabilidades en Google Cloud
53 resultadosAnálisis Vexday
Google Cloud registra 40 vulnerabilidades na base Vexday, das quais 11 são críticas, mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é autorização inadequada (CWE-862), e 9 CVEs foram publicadas nos últimos 90 dias, indicando risco recente que demanda atenção nas camadas de controle de acesso.
CVE-2026-4810CRITICALRemote Code Execution in Google Agent Development Kit (ADK)EPSS 2.2%CVE-2025-12155HIGHCommand Injection in LookerEPSS 1.3%CVE-2026-79696CRITICALRemote Code Execution in Google ADK for Python via Incomplete Standard Library DenylistEPSS 0.7%CVE-2026-79707HIGHArbitrary File Read in Google Agent Development Kit (ADK)EPSS 0.7%CVE-2025-9118CRITICALDataform Path TraversalEPSS 0.6%CVE-2025-9918HIGHZip Slip in Google SecOps SOAR allows for Remote Code ExecutionEPSS 0.6%CVE-2026-2472HIGHStored Cross-Site Scripting (XSS) in Vertex AI Python SDK VisualizationEPSS 0.5%CVE-2026-2031CRITICALGoogle Cloud Application Integration: Exposed internal APIs allow Information Disclosure and Remote Code Execution.EPSS 0.5%CVE-2026-19407HIGHGCS Bucket Squatting leading to RCE in Gemini Enterprise Agent Platform Python SDKEPSS 0.5%CVE-2026-8934MEDIUMCross-Project Information Leakage in Google App Engine UIEPSS 0.5%CVE-2025-13427MEDIUMAuthentication Bypass in Dialogflow CX MessengerEPSS 0.5%CVE-2025-12414CRITICALLooker account compromise via punycode homograph attackEPSS 0.5%CVE-2026-2473HIGHBucket Squatting in Vertex AI Experiments leads to RCE and Model Theft.EPSS 0.5%CVE-2026-15810HIGHCross-Site Scripting (XSS) in Looker allows Admin Account TakeoverEPSS 0.5%CVE-2026-12717CRITICALRemote Code Execution in BigQuery Data Transfer Service via JDBC Connection String InjectionEPSS 0.5%CVE-2025-9571HIGHArbitrary Code Execution in Google Cloud Data Fusion via Malicious Artifact UploadEPSS 0.4%CVE-2025-13426HIGHImproper Sandboxing in Google Apigee's JavaCallout Policy Allows for Remote Code ExecutionEPSS 0.4%CVE-2026-12710CRITICALMissing Authorization in Application Integration QueryEngineTaskEPSS 0.4%CVE-2026-7428CRITICALInsecure default administrative credentials in AlloyDB for PostgreSQLEPSS 0.4%CVE-2026-3136HIGHGoogle Cloud Build Comment Control BypassEPSS 0.4%