Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2025-7044
An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user…
Maas
3.3.11 / 3.4.9+
MEDIUM 6.5
CVE-2025-54293
Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on …
Lxd
5.21.4 / 6.5+
HIGH 8.1
CVE-2025-54289
Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or consol…
Lxd
5.21.4 / 6.5+
MEDIUM 5.3
CVE-2025-54290
Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence wi…
Lxd
5.21.4 / 6.5+
MEDIUM 5.3
CVE-2025-54291
Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine pro…
Lxd
5.21.4 / 6.5+
HIGH 8.8
CVE-2025-54286
Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances with…
Lxd
5.0.5 / 5.21.4+
MEDIUM 6.8
CVE-2025-54288
Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attackers with root privileges with…
Lxd
5.21.4 / 6.5+
MEDIUM 6.5
CVE-2025-54287
Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration
permissions to r…
Lxd
5.21.4 / 6.5+
CRITICAL 9.8
CVE-2024-6107
Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has…
Metal As A Service
3.1.4 / 3.2.11+
HIGH 7.8
CVE-2025-5199
In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by mo…
Multipass
1.16.0+
HIGH 8.8
CVE-2025-0928
In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent binaries to any model or to the c…
Juju
2.9.52 / 3.6.8+
MEDIUM 6.5
CVE-2025-53512
The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access debug messages that could contai…
Juju
2.9.52 / 3.6.8+
MEDIUM 6.5
CVE-2025-53513
The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a cha…
Juju
2.9.52 / 3.6.8+
MEDIUM 6.5
CVE-2025-6224
Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If this certificate were then transferred ove…
Juju\/utils
4.0.4+
HIGH 7.8
CVE-2025-32463 KEVEPSS 56%
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot o…
Ubuntu Linux
1.9.17+
HIGH 8.8
CVE-2024-6174
When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default co…
Cloud Init
25.1.3+
MEDIUM 5.3
CVE-2024-11584
cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it…
Cloud Init
25.1.3+
HIGH 8.5
CVE-2025-5689
A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to…
Authd
0.5.4+
HIGH 7.5
CVE-2023-0881
Running DDoS on tcp port 22 will trigger a kernel crash. This issue is introduced by the backport of a commit regarding nft_lookup without the subseq…
Linux Bluefield
5.4.0-1058.64+
MEDIUM 5.5
CVE-2022-1804
accountsservice no longer drops permissions when writting .pam_environment
Accountsservice
22.07.5-2ubuntu1.3+
MEDIUM 5.9
CVE-2025-26466EPSS 40%
A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a …
Ubuntu Linux
Mitigation only
CRITICAL 9.8
CVE-2022-1736
Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.
Ubuntu Linux
Mitigation only
HIGH 7.5
CVE-2022-28653
Users can consume unlimited disk space in /var/crash
Apport
2.21.0+
MEDIUM 6.4
CVE-2024-9312
Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions. A local attacker who can register user names could spoof…
Authd
0.3.6+
HIGH 8.8
CVE-2024-9313
Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM ope…
Authd
0.3.5+
HIGH 8.0
CVE-2024-7558
JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged u…
Juju
2.9.51 / 3.1.10+
MEDIUM 6.5
CVE-2024-8037
Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to t…
Juju
2.9.51 / 3.1.10+
MEDIUM 5.5
CVE-2024-8038
Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authenti…
Juju
2.9.51 / 3.1.10+
HIGH 7.5
CVE-2024-8287
Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attac…
Anbox Cloud
1.23.1+
HIGH 7.3
CVE-2024-29069
In snapd versions prior to 2.62, snapd failed to properly check the
destination of symbolic links when extracting a snap. The snap format
is a squas…
Snapd
2.62+