Vulnerabilidades en Google Cloud

53 resultados
Análisis Vexday

Google Cloud registra 40 vulnerabilidades na base Vexday, das quais 11 são críticas, mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é autorização inadequada (CWE-862), e 9 CVEs foram publicadas nos últimos 90 dias, indicando risco recente que demanda atenção nas camadas de controle de acesso.

CVE-2026-3259HIGHSensitive Data Disclosure in BigQuery via Materialized View Error MessagesEPSS 0.4%CVE-2026-13745HIGHArbitrary Code Execution in Gemini CLI via Untrusted Local .env Files Overriding GEMINI_CLI_HOMEEPSS 0.4%CVE-2025-12952HIGHPrivilege Escalation in Dialogflow CX via Webhook Admin RoleEPSS 0.4%CVE-2026-2264CRITICALServer-Side Request Forgery and Credential Exfiltration in Google Cloud Apigee via SetIntegrationRequest Policy.EPSS 0.4%CVE-2026-12715HIGHMissing Authorization in Firebase Studio allows Cross-Tenant Source Code TheftEPSS 0.4%CVE-2026-4644HIGHImproper Authorization in Google Cloud Integration Connectors Leads to Project TakeoverEPSS 0.4%CVE-2026-14934CRITICALCross-Tenant Repository Takeover via Improper Access Control in BigQuery, Dataform and Colab EnterpriseEPSS 0.4%CVE-2026-4764CRITICALPrivilege Escalation in Dialogflow CX via Playbook ImportEPSS 0.4%CVE-2026-15623CRITICALAuthenticated Blind SQL Injection in Google Cloud SecOps SOAR Dashboard Widget Query ServiceEPSS 0.3%CVE-2025-13428HIGHRCE in SecOps SOAR server via user-provided Python packagesEPSS 0.3%CVE-2025-11915MEDIUMHTTP Desynchronisation in Vertex AI for certain third-party modelsEPSS 0.3%CVE-2025-12397HIGHSQL Injection in Looker StudioEPSS 0.3%CVE-2025-12739HIGHCross-Site Scripting (XSS) in Looker's Extension Loader leading to Admin Account CompromiseEPSS 0.3%CVE-2026-12879MEDIUMCross-Tenant Data Exfiltration in Apigee via BigQuery Confused DeputyEPSS 0.3%CVE-2025-12743MEDIUMSQL Injection in Looker Project Generation Endpoint Allows Access to Internal MySQL DatabaseEPSS 0.3%CVE-2025-13292HIGHImproper access control in Google Cloud Apigee-X allows cross-tenant Analytics modification and log data access.EPSS 0.3%CVE-2026-19486HIGHSSRF in Gemini Enterprise Agent Platform App BuilderEPSS 0.3%CVE-2026-1727CRITICALInformation Disclosure via Bucket Squatting in Google Cloud Agentspace.EPSS 0.3%CVE-2025-0982CRITICALSandbox Escape in Google Cloud Application Integration's JavaScript Task (Rhino Engine)EPSS 0.3%CVE-2025-12405HIGHUnauthorized access through stored credentials in Looker StudioEPSS 0.3%