Vulnerabilidades em Google Cloud

42 resultados
Análise Vexday

Google Cloud registra 40 vulnerabilidades na base Vexday, das quais 11 são críticas, mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é autorização inadequada (CWE-862), e 9 CVEs foram publicadas nos últimos 90 dias, indicando risco recente que demanda atenção nas camadas de controle de acesso.

CVE-2026-15810HIGHCross-Site Scripting (XSS) in Looker allows Admin Account TakeoverEPSS 0.3%CVE-2025-12743MEDIUMSQL Injection in Looker Project Generation Endpoint Allows Access to Internal MySQL DatabaseEPSS 0.3%CVE-2025-12405HIGHUnauthorized access through stored credentials in Looker StudioEPSS 0.3%CVE-2025-0982CRITICALSandbox Escape in Google Cloud Application Integration's JavaScript Task (Rhino Engine)EPSS 0.3%CVE-2026-1727CRITICALInformation Disclosure via Bucket Squatting in Google Cloud Agentspace.EPSS 0.3%CVE-2025-12409HIGHSQL Injection in Looker StudioEPSS 0.3%CVE-2025-12472HIGHRemote Code Execution in Looker due to Improperly Validated Directory DeletionEPSS 0.2%CVE-2026-2244HIGHSensitive Data Exposure in Google Cloud Vertex AI WorkbenchEPSS 0.2%CVE-2025-12740HIGHRemote Command Execution in Looker via IBM DB2 JDBC driveEPSS 0.2%CVE-2025-12741HIGHArbitrary File Write in Denodo dialect of Looker allows Remote Code ExecutionEPSS 0.2%CVE-2026-7428CRITICALInsecure default administrative credentials in AlloyDB for PostgreSQLEPSS 0.2%CVE-2025-12742HIGHRemote Code Execution in Looker via Teradata JDBC DriverEPSS 0.2%CVE-2026-14934CRITICALCross-Tenant Repository Takeover via Improper Access Control in BigQuery, Dataform and Colab EnterpriseEPSS 0.2%CVE-2026-3259HIGHSensitive Data Disclosure in BigQuery via Materialized View Error MessagesEPSS 0.2%CVE-2026-12715HIGHMissing Authorization in Firebase Studio allows Cross-Tenant Source Code TheftEPSS 0.2%CVE-2026-4764CRITICALPrivilege Escalation in Dialogflow CX via Playbook ImportEPSS 0.2%CVE-2025-4600HIGHHTTP Request Smuggling in Google Cloud Classic Application Load Balancer due to Improper Chunked Encoding ValidationEPSS 0.2%CVE-2026-12879MEDIUMCross-Tenant Data Exfiltration in Apigee via BigQuery Confused DeputyEPSS 0.2%CVE-2026-15587CRITICALPrivilege Escalation in Google SecOps (Chronicle SOAR) via Crafted Authentication HeaderEPSS 0.2%CVE-2024-5166MEDIUMInsecure Direct Object Reference In LookerEPSS 0.2%