Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-41647 Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error handling could lead an authenticated Incus user to c… Incus 7.0.0+ Fix from $1,6002026-05-07 MEDIUM 6.5 CVE-2026-41684 Incus is a system container and virtual machine manager. Prior to version 7.0.0, backup.GetInfo() trusts the inline backup/index.yaml config when pre… Incus 7.0.0+ Fix from $1,6002026-05-07 MEDIUM 5.0 CVE-2026-41648 Incus is a system container and virtual machine manager. Prior to version 7.0.0, user provided image and backup tarballs would be unpacked and YAML f… Incus 7.0.0+ Fix from $1,6002026-05-07 MEDIUM 6.5 CVE-2026-40251 Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows… Incus 7.0.0+ Fix from $1,6002026-05-06 MEDIUM 6.5 CVE-2026-40195 Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage bucket import logic allows… Incus 7.0.0+ Fix from $1,6002026-05-06 MEDIUM 6.5 CVE-2026-40197 Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows… Incus 7.0.0+ Fix from $1,6002026-05-06 MEDIUM 6.5 CVE-2026-39402 lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_line() function that allows an… Lxc 7.0.0+ Fix from $1,6002026-05-05 MEDIUM 5.0 CVE-2026-35527 Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues an outbound HEAD request to a… Incus 7.0.0+ Fix from $1,6002026-05-05 CRITICAL 9.6 CVE-2026-33945 Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For container… Incus 6.23.0+ Fix from $2,3002026-03-27 HIGH 8.8 CVE-2026-33898 Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the a… Incus 6.23.0+ Fix from $1,9502026-03-27 CRITICAL 9.9 CVE-2026-33897 Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to cause arbitrary read or writ… Incus 6.23.0+ Fix from $2,3002026-03-26 HIGH 7.8 CVE-2026-33711 Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API relies on the use of a temporary … Incus 6.23.0+ Fix from $1,9502026-03-26 MEDIUM 6.5 CVE-2026-33743 Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user wi… Incus 6.23.0+ Fix from $1,6002026-03-26 HIGH 8.7 CVE-2026-23953 Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch a container with a custom YA… Incus 6.21.0+ Fix from $1,9502026-01-22 HIGH 8.7 CVE-2026-23954 Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom … Incus 6.21.0+ Fix from $1,9502026-01-22 HIGH 7.8 CVE-2025-64507 Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment wher… Incus 6.0.6 / 6.19.0+ Fix from $1,9502025-11-10 HIGH 8.1 CVE-2017-18641 In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers. Lxc Patch available Fix from $1,9502020-02-10 HIGH 8.1 CVE-2015-1340 LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the Filepath.Walk() function. A … Lxd Patch available Fix from $1,9502019-04-22 CRITICAL 9.1 CVE-2016-8649 lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptor, of th… Lxc 1.0.9 / 2.0.6+ Fix from $2,3002017-05-01 HIGH 8.6 CVE-2016-10124 An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the p… Lxc after 2.0.0 Fix from $1,9502017-01-09 HIGH 7.2 CVE-2013-6441 The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows local user… Lxc after 0.9.0 Fix from $1,9502014-02-14