cloud PoCs
subscribe (RSS)Proof-of-concept research filed under the cloud category.
Entries
21
in cloud
CISA KEV
0
exploited in the wild
Ransomware
0
known campaign use
Unpatched
7
no vendor fix
Critical
9
43% of listed
21 entries
Severity
Exploitation signals
Patch status
Date range
→
Sort
21 result(s)
CLOUD LIST
21 shown · 21 indexed
| PoC title | CVE | Category | Severity | Patch | Date |
|---|---|---|---|---|---|
| Apache Polaris — Cross-Tenant Credential Vending Before Location Validation in Iceberg REST Register (CVE-2026-64640)
CVE-2026-64640
cloud
Patched | CVE-2026-64640 | cloud | HIGH 8.1 | Patched | 2026-08-09 |
| tj-actions/branch-names GitHub Actions Command Injection (CVE-2025-54416)
CVE-2025-54416
cloud
Patched | CVE-2025-54416 | cloud | CRITICAL 9.1 | Patched | 2026-07-06 |
| RustFS Hardcoded gRPC Authentication Token Leading to Full Node Compromise (CVE-2025-68926)
EPSS 31% CVE-2025-68926
cloud
Patched | CVE-2025-68926 | cloud | CRITICAL 9.8 | Patched | 2026-07-06 |
| IngressNightmare: Kubernetes ingress-nginx Admission Controller Shared-Library Injection RCE (CVE-2025-1974)
EPSS 100% CVE-2025-1974
cloud
Unverified | CVE-2025-1974 | cloud | CRITICAL 9.8 | Unverified | 2026-07-06 |
| Supply Chain Command Injection in AWS CDK's NodejsFunction — CVE-2026-11417
CVE-2026-11417
cloud
Patched | CVE-2026-11417 | cloud | HIGH 3.1 | Patched | 2026-07-05 |
| Spinnaker Clouddriver — Git Clone Shell Injection RCE (CVE-2026-32604)
CVE-2026-32604 (CWE-78)
cloud
Patched | CVE-2026-32604 | cloud | CRITICAL 10 | Patched | 2026-07-05 |
| Sherlock CI `pull_request_target` Command Injection → GitHub Actions Secret Exfiltration (CVE-2026-44590)
CVE-2026-44590
cloud
Patched | CVE-2026-44590 | cloud | CRITICAL 9.3 | Patched | 2026-07-05 |
| RustFS — Presigned POST Policy Condition Bypass (CVE-2026-27607)
CVE-2026-27607 (GHSA-w5fh-f8xh-5x3p)
cloud
Patched | CVE-2026-27607 | cloud | HIGH | Patched | 2026-07-05 |
| Plunk SSRF via Unvalidated AWS SNS SubscriptionConfirmation — CVE-2026-32096
CVE-2026-32096
cloud
Patched | CVE-2026-32096 | cloud | CRITICAL 9.3 | Patched | 2026-07-05 |
| OS Command Injection in KubeAI via Model URL (CVE-2026-34940)
CVE-2026-34940
cloud
Patched | CVE-2026-34940 | cloud | HIGH 8.7 | Patched | 2026-07-05 |
| OpenLearnX Unauthenticated RCE via Container Volume Mount (CVE-2026-41900)
CVE-2026-41900 (GHSA-8h25-q488-4hxw)
cloud
Patched | CVE-2026-41900 | cloud | HIGH 8.6 | Patched | 2026-07-05 |
| Kubernetes `runAsNonRoot` Bypass via UID Integer Overflow (CVE-2026-46680)
CVE-2026-46680
cloud
Patched | CVE-2026-46680 | cloud | HIGH | Patched | 2026-07-05 |
| HashiCorp go-getter Git Pathspec Arbitrary File Read (CVE-2026-4660)
CVE-2026-4660 / HCSEC-2026-04
cloud
Patched | CVE-2026-4660 / HCSEC-2026-04 | cloud | HIGH 7.5 | Patched | 2026-07-05 |
| Apache Flink Kubernetes Operator SSRF via jarURI (CVE-2026-40564)
CVE-2026-40564
cloud
Patched | CVE-2026-40564 | cloud | HIGH | Patched | 2026-07-05 |
| Amazon WorkSpaces Skylight Workspace Config Service Local Privilege Escalation (CVE-2026-7791)
CVE-2026-7791
cloud
Unverified | CVE-2026-7791 | cloud | HIGH | Unverified | 2026-07-05 |
| Nextcloud Federated Share OCM Bearer Token Scope Escalation to Sender WebDAV Access
None assigned as of 2026-07-03
cloud
Unverified | None assigned as of 2026-07-03 | cloud | HIGH | Unverified | 2026-07-03 |
| Gitea act_runner container.options Host Namespace Escape
None assigned as of 2026-07-03
cloud
Unverified | None assigned as of 2026-07-03 | cloud | HIGH | Unverified | 2026-07-03 |
| Floci API Gateway VTL RCE + IAM Scope Bypass
None assigned as of 2026-07-03
cloud
Unverified | None assigned as of 2026-07-03 | cloud | CRITICAL | Unverified | 2026-07-03 |
| Docker cp Copy-Out Destination Escape via Symlink Race
None assigned as of 2026-07-03
cloud
Unverified | None assigned as of 2026-07-03 | cloud | MEDIUM | Unverified | 2026-07-03 |
| IngressNightmare - Kubernetes Ingress-NGINX Unauthenticated RCE
EPSS 100% CVE-2025-1974 (primary); also CVE-2025-1097, CVE-2025-1098, CVE-2025-24514
cloud
Unverified | CVE-2025-1974 | cloud | CRITICAL 9.8 | Unverified | 2026-05-17 |
| Azure Networking Privilege Escalation via Missing Privilege Check
CVE-2025-54914
cloud
Patched | CVE-2025-54914 | cloud | CRITICAL 10 | Patched | 2026-05-17 |
No PoCs match the current filters.