Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2026-28385 In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import functionality allows authenticated… Lxd after 6.9 Fix from $1,6002026-06-26 HIGH 7.2 CVE-2026-9640 A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of projec… Lxd 5.0.7 / 5.21.5+ Fix from $1,9502026-06-26 MEDIUM 6.5 CVE-2026-9639 Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_stora… Lxd 5.21.5 / 6.9+ Fix from $1,6002026-06-26 CRITICAL 9.6 CVE-2026-12411 Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another gu… Lxd 6.9+ Fix from $2,3002026-06-26 HIGH 7.8 CVE-2026-47333 Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a … Ubuntu Linux Patch available Fix from $1,9502026-05-28 MEDIUM 5.5 CVE-2026-47334 Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug… Ubuntu Linux Patch available Fix from $1,6002026-05-28 MEDIUM 5.5 CVE-2026-47335 Ubuntu Linux 6.8 contains SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered … Ubuntu Linux Mitigation only Fix from $1,6002026-05-28 HIGH 7.8 CVE-2026-47331 Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivileged local user could trigger … Ubuntu Linux Patch available Fix from $1,9502026-05-28 MEDIUM 5.5 CVE-2026-47332 Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-boun… Ubuntu Linux Patch available Fix from $1,6002026-05-28 MEDIUM 6.1 CVE-2026-47328 Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while … Ubuntu Linux Patch available Fix from $1,6002026-05-28 MEDIUM 5.5 CVE-2026-47326 Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be tr… Ubuntu Linux Patch available Fix from $1,6002026-05-28 HIGH 8.4 CVE-2026-49238 An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root pr… Multipass 1.16.3+ Fix from $1,9502026-05-28 HIGH 7.8 CVE-2026-49237 An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version… Multipass 1.16.3+ Fix from $1,9502026-05-28 MEDIUM 5.5 CVE-2018-25306 PDFunite 0.41.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by processing malformed PDF files durin… Pdfunite No fix yet Fix from $1,6002026-04-29 MEDIUM 5.5 CVE-2026-6369 An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a… Livepatch Client 10.15.0+ Fix from $1,6002026-04-20 MEDIUM 6.4 CVE-2026-5774 Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possi… Juju 2.9.57 / 3.6.21+ Fix from $1,6002026-04-10 MEDIUM 6.5 CVE-2026-5412 In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API… Juju 2.9.57 / 3.6.21+ Fix from $1,6002026-04-10 CRITICAL 9.1 CVE-2025-15480 In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a use… Ubuntu Desktop Provision Patch available Fix from $2,3002026-04-09 HIGH 8.1 CVE-2025-14551 In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a b… Ubuntu Subiquity Patch available Fix from $1,9502026-04-09 CRITICAL 9.1 CVE-2026-34177 Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omit… Lxd after 6.7 Fix from $2,3002026-04-09 CRITICAL 9.1 CVE-2026-34178 In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates … Lxd after 6.7 Fix from $2,3002026-04-09 CRITICAL 9.1 CVE-2026-34179 In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PU… Lxd after 6.7 Fix from $2,3002026-04-09 MEDIUM 6.5 CVE-2025-68153 Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special ope… Juju after 3.6.18 Fix from $1,6002026-04-03 CRITICAL 10.0 CVE-2026-4370 A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster f… Juju 3.6.20 / 4.0.5+ Fix from $2,3002026-04-01 MEDIUM 6.6 CVE-2026-32694 In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret owner relies exclusively on a … Juju 3.6.19+ Fix from $1,6002026-03-18 HIGH 8.8 CVE-2026-32693 In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update th… Juju 3.6.19+ Fix from $1,9502026-03-18 MEDIUM 6.5 CVE-2026-32692 An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit… Juju 3.6.19+ Fix from $1,6002026-03-18 MEDIUM 5.3 CVE-2026-32691 A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit agent to claim ownership of a… Juju 3.6.19+ Fix from $1,6002026-03-18 HIGH 7.8 CVE-2026-3888 Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-t… Ubuntu Linux Mitigation only Fix from $1,9502026-03-17 HIGH 7.5 CVE-2026-3497 Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Lin… Ubuntu Linux Mitigation only Fix from $1,9502026-03-12