I'm not following you here. Surely you could just look them up yourself?
Just look at this enormous list of CVEs in Oracle products (which also includes cloud products), as one example: https://www.oracle.com/security-alerts/public-vuln-to-adviso...
Sure, but you do realize that all of those bugs in their products may have been exploited in their clouds in different ways?
"May" is not what the article linked at the top of the page is talking about.