Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache CloudStack | 4.21.0 ~ 4.22.0 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-66467 | 8.0 HIGH | Apache CloudStack: MinIO policy remains intact on bucket deletion |
| CVE-2025-69233 | 6.5 MEDIUM | Apache CloudStack: Domain/account resources limits not honored |
| CVE-2026-39816 | Apache NiFi: Missing Execute Code Required Permission on TinkerpopClientService | |
| CVE-2026-25077 | Apache CloudStack: Unauthenticated Command Injection in Direct Download Templates | |
| CVE-2025-66172 | Apache CloudStack: Any user can attach a volume in their VMs from backups they should not | |
| CVE-2025-66171 | Apache CloudStack: Any user can create a new VM from backups they should not have access t | |
| CVE-2025-66170 | Apache CloudStack: Any user can list backups that they should not have access to |
No comments yet