Google Cloud

First CVE: Aug 25, 2025Active for: 1 year
38
CVEs Published
More CVEs Published than 51% of tracked CNAs
19.0
Avg CVEs / Year
More Avg CVEs / Year than 66% of tracked CNAs
8.1
Avg CVSS Score
Higher Avg CVSS Score than 88% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by Google Cloud over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 25, 2025
10 months ago
Most Recent CVE
Jul 24, 2026
0 days ago

Top CVEs

All CVEs published by Google Cloud as a CNA, regardless of affected vendor or product.

38 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) on Python (OSS), Cloud Run
Apr 13, 20269.344NOYES
A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versions between October 2025 and May
Jul 13, 20269.441NONO
Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22)
Jun 24, 20267.839NONO
An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remote, unauthenticated attacker to
May 15, 202610.039NONO
A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user with specific roles to escalate pr
Jun 11, 20269.435NONO
Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and acc
Jul 17, 20268.534NONO
A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories vi
Aug 25, 202510.034NONO
A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access
May 26, 20269.233NONO
Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have created clusters with an insecure default password which could
May 12, 20269.233NONO
The Agentspace service was affected by a vulnerability that exposed sensitive information due to the use of predictable Google Cloud Storage bucket names. These names were utilized
Feb 6, 20269.130NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA38 CVEs
Severity distribution among all CVEs352,294 CVEs
MediumHighCriticalUnknown
Attack Vector
Local1 (2.6%)
Network36 (94.7%)
Unknown1 (2.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (81.6%)
High6 (15.8%)
Unknown1 (2.6%)
User Interaction
None29 (76.3%)
Unknown1 (2.6%)
Required2 (5.3%)
Privileges Required
Low18 (47.4%)
High5 (13.2%)
None14 (36.8%)
Unknown1 (2.6%)

Exploit Exposure

Signals from CVEs in this cna scope (38 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.6% of CVEs· 88th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Google Cloud as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Google Cloud as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs