Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2025-7044 An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user… Maas 3.3.11 / 3.4.9+ Fix from $1,6002025-12-03 MEDIUM 6.5 CVE-2025-54293 Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on … Lxd 5.21.4 / 6.5+ Fix from $1,6002025-10-02 HIGH 8.1 CVE-2025-54289 Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or consol… Lxd 5.21.4 / 6.5+ Fix from $1,9502025-10-02 MEDIUM 5.3 CVE-2025-54290 Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence wi… Lxd 5.21.4 / 6.5+ Fix from $1,6002025-10-02 MEDIUM 5.3 CVE-2025-54291 Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine pro… Lxd 5.21.4 / 6.5+ Fix from $1,6002025-10-02 HIGH 8.8 CVE-2025-54286 Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances with… Lxd 5.0.5 / 5.21.4+ Fix from $1,9502025-10-02 MEDIUM 6.8 CVE-2025-54288 Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attackers with root privileges with… Lxd 5.21.4 / 6.5+ Fix from $1,6002025-10-02 MEDIUM 6.5 CVE-2025-54287 Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to r… Lxd 5.21.4 / 6.5+ Fix from $1,6002025-10-02 CRITICAL 9.8 CVE-2024-6107 Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has… Metal As A Service 3.1.4 / 3.2.11+ Fix from $2,3002025-07-21 HIGH 7.8 CVE-2025-5199 In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by mo… Multipass 1.16.0+ Fix from $1,9502025-07-12 HIGH 8.8 CVE-2025-0928 In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent binaries to any model or to the c… Juju 2.9.52 / 3.6.8+ Fix from $1,9502025-07-08 MEDIUM 6.5 CVE-2025-53512 The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access debug messages that could contai… Juju 2.9.52 / 3.6.8+ Fix from $1,6002025-07-08 MEDIUM 6.5 CVE-2025-53513 The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a cha… Juju 2.9.52 / 3.6.8+ Fix from $1,6002025-07-08 MEDIUM 6.5 CVE-2025-6224 Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If this certificate were then transferred ove… Juju\/utils 4.0.4+ Fix from $1,6002025-07-01 HIGH 7.8 CVE-2025-32463 KEVEPSS 56% Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot o… Ubuntu Linux 1.9.17+ Fix from $1,9502025-06-30 HIGH 8.8 CVE-2024-6174 When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default co… Cloud Init 25.1.3+ Fix from $1,9502025-06-26 MEDIUM 5.3 CVE-2024-11584 cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it… Cloud Init 25.1.3+ Fix from $1,6002025-06-26 HIGH 8.5 CVE-2025-5689 A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to… Authd 0.5.4+ Fix from $1,9502025-06-16 HIGH 7.5 CVE-2023-0881 Running DDoS on tcp port 22 will trigger a kernel crash. This issue is introduced by the backport of a commit regarding nft_lookup without the subseq… Linux Bluefield 5.4.0-1058.64+ Fix from $1,9502025-03-31 MEDIUM 5.5 CVE-2022-1804 accountsservice no longer drops permissions when writting .pam_environment Accountsservice 22.07.5-2ubuntu1.3+ Fix from $1,6002025-03-25 MEDIUM 5.9 CVE-2025-26466EPSS 40% A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a … Ubuntu Linux Mitigation only Fix from $1,6002025-02-28 CRITICAL 9.8 CVE-2022-1736 Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default. Ubuntu Linux Mitigation only Fix from $2,3002025-01-31 HIGH 7.5 CVE-2022-28653 Users can consume unlimited disk space in /var/crash Apport 2.21.0+ Fix from $1,9502025-01-31 MEDIUM 6.4 CVE-2024-9312 Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions. A local attacker who can register user names could spoof… Authd 0.3.6+ Fix from $1,6002024-10-10 HIGH 8.8 CVE-2024-9313 Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM ope… Authd 0.3.5+ Fix from $1,9502024-10-03 HIGH 8.0 CVE-2024-7558 JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged u… Juju 2.9.51 / 3.1.10+ Fix from $1,9502024-10-02 MEDIUM 6.5 CVE-2024-8037 Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to t… Juju 2.9.51 / 3.1.10+ Fix from $1,6002024-10-02 MEDIUM 5.5 CVE-2024-8038 Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authenti… Juju 2.9.51 / 3.1.10+ Fix from $1,6002024-10-02 HIGH 7.5 CVE-2024-8287 Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attac… Anbox Cloud 1.23.1+ Fix from $1,9502024-09-18 HIGH 7.3 CVE-2024-29069 In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a squas… Snapd 2.62+ Fix from $1,9502024-07-25