cloudlinux records
4 published records for vendor cloudlinux.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-214 Invocation of Process Using Visible Sensitive Information1
- CWE-502 Deserialization of Untrusted Data1
- CWE-73 External Control of File Name or Path1
- CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2025-65530No exploit | An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit before v32.7.4 allows attackers to overwrite arbitrary filescloudlinux · ai-bolit · CWE-95 | High8.8 | — | 0.3% | Dec 12, 2025 |
31Monitor | CVE-2021-21956No exploit | A php unserialize vulnerability exists in the Ai-Bolit functionality of CloudLinux Inc Imunify360 5.10.2.cloudlinux · imunify360 · CWE-502 | High7.8 | — | 1.4% | Apr 14, 2022 |
31Monitor | CVE-2020-36771No exploit | CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument.cloudlinux · cagefs · CWE-214 | High7.8 | — | 0.5% | Jan 22, 2024 |
17Monitor | CVE-2020-36772No exploit | CloudLinux CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to the sendmail proxy command.cloudlinux · cagefs · CWE-73 | Medium4.4 | — | 0.4% | Jan 22, 2024 |
- CVE-2025-6553035Monitor
An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit before v32.7.4 allows attackers to overwrite arbitrary files
HighCVSS 8.8No exploitEPSS 0%cloudlinux · ai-bolitDec 12, 2025
- CVE-2021-2195631Monitor
A php unserialize vulnerability exists in the Ai-Bolit functionality of CloudLinux Inc Imunify360 5.10.2.
HighCVSS 7.8No exploitEPSS 1%cloudlinux · imunify360Apr 14, 2022
- CVE-2020-3677131Monitor
CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument.
HighCVSS 7.8No exploitEPSS 0%cloudlinux · cagefsJan 22, 2024
- CVE-2020-3677217Monitor
CloudLinux CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to the sendmail proxy command.
MediumCVSS 4.4No exploitEPSS 0%cloudlinux · cagefsJan 22, 2024