Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Maas MEDIUM 6.5
CVE-2025-7044

An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user…

Fix: 3.3.11 / 3.4.9+
Fix from $1,600 2025-12-03
Lxd MEDIUM 6.5
CVE-2025-54293

Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on …

Fix: 5.21.4 / 6.5+
Fix from $1,600 2025-10-02
Lxd HIGH 8.1
CVE-2025-54289

Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or consol…

Fix: 5.21.4 / 6.5+
Fix from $1,950 2025-10-02
Lxd MEDIUM 5.3
CVE-2025-54290

Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence wi…

Fix: 5.21.4 / 6.5+
Fix from $1,600 2025-10-02
Lxd MEDIUM 5.3
CVE-2025-54291

Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine pro…

Fix: 5.21.4 / 6.5+
Fix from $1,600 2025-10-02
Lxd HIGH 8.8
CVE-2025-54286

Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances with…

Fix: 5.0.5 / 5.21.4+
Fix from $1,950 2025-10-02
Lxd MEDIUM 6.8
CVE-2025-54288

Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attackers with root privileges with…

Fix: 5.21.4 / 6.5+
Fix from $1,600 2025-10-02
Lxd MEDIUM 6.5
CVE-2025-54287

Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to r…

Fix: 5.21.4 / 6.5+
Fix from $1,600 2025-10-02
Metal As A Service CRITICAL 9.8
CVE-2024-6107

Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has…

Fix: 3.1.4 / 3.2.11+
Fix from $2,300 2025-07-21
Multipass HIGH 7.8
CVE-2025-5199

In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by mo…

Fix: 1.16.0+
Fix from $1,950 2025-07-12
Juju HIGH 8.8
CVE-2025-0928

In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent binaries to any model or to the c…

Fix: 2.9.52 / 3.6.8+
Fix from $1,950 2025-07-08
Juju MEDIUM 6.5
CVE-2025-53512

The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access debug messages that could contai…

Fix: 2.9.52 / 3.6.8+
Fix from $1,600 2025-07-08
Juju MEDIUM 6.5
CVE-2025-53513

The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a cha…

Fix: 2.9.52 / 3.6.8+
Fix from $1,600 2025-07-08
Juju\/utils MEDIUM 6.5
CVE-2025-6224

Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If this certificate were then transferred ove…

Fix: 4.0.4+
Fix from $1,600 2025-07-01
Ubuntu Linux HIGH 7.8
CVE-2025-32463 KEVEPSS 56%

Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot o…

Fix: 1.9.17+
Fix from $1,950 2025-06-30
Cloud Init HIGH 8.8
CVE-2024-6174

When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default co…

Fix: 25.1.3+
Fix from $1,950 2025-06-26
Cloud Init MEDIUM 5.3
CVE-2024-11584

cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it…

Fix: 25.1.3+
Fix from $1,600 2025-06-26
Authd HIGH 8.5
CVE-2025-5689

A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to…

Fix: 0.5.4+
Fix from $1,950 2025-06-16
Linux Bluefield HIGH 7.5
CVE-2023-0881

Running DDoS on tcp port 22 will trigger a kernel crash. This issue is introduced by the backport of a commit regarding nft_lookup without the subseq…

Fix: 5.4.0-1058.64+
Fix from $1,950 2025-03-31
Accountsservice MEDIUM 5.5
CVE-2022-1804

accountsservice no longer drops permissions when writting .pam_environment

Fix: 22.07.5-2ubuntu1.3+
Fix from $1,600 2025-03-25
Ubuntu Linux MEDIUM 5.9
CVE-2025-26466EPSS 40%

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a …

Mitigation only
Fix from $1,600 2025-02-28
Ubuntu Linux CRITICAL 9.8
CVE-2022-1736

Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.

Mitigation only
Fix from $2,300 2025-01-31
Apport HIGH 7.5
CVE-2022-28653

Users can consume unlimited disk space in /var/crash

Fix: 2.21.0+
Fix from $1,950 2025-01-31
Authd MEDIUM 6.4
CVE-2024-9312

Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions. A local attacker who can register user names could spoof…

Fix: 0.3.6+
Fix from $1,600 2024-10-10
Authd HIGH 8.8
CVE-2024-9313

Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM ope…

Fix: 0.3.5+
Fix from $1,950 2024-10-03
Juju HIGH 8.0
CVE-2024-7558

JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged u…

Fix: 2.9.51 / 3.1.10+
Fix from $1,950 2024-10-02
Juju MEDIUM 6.5
CVE-2024-8037

Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to t…

Fix: 2.9.51 / 3.1.10+
Fix from $1,600 2024-10-02
Juju MEDIUM 5.5
CVE-2024-8038

Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authenti…

Fix: 2.9.51 / 3.1.10+
Fix from $1,600 2024-10-02
Anbox Cloud HIGH 7.5
CVE-2024-8287

Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attac…

Fix: 1.23.1+
Fix from $1,950 2024-09-18
Snapd HIGH 7.3
CVE-2024-29069

In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a squas…

Fix: 2.62+
Fix from $1,950 2024-07-25