We should collect the data of https://github.com/wiz-sec/open-cvdb and https://www.cloudvulndb.org/ by @korniko98 ... They have vulnerabilities known to be exploited at cloud providers. License seems is CC-BY. There are no PURL though.
I also learned from there about https://github.com/piercing-index/cloud-vulnerabilities now tracked at #1510