Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Lxd MEDIUM 5.0
CVE-2026-28385

In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import functionality allows authenticated…

Fix: after 6.9
Fix from $1,600 2026-06-26
Lxd HIGH 7.2
CVE-2026-9640

A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of projec…

Fix: 5.0.7 / 5.21.5+
Fix from $1,950 2026-06-26
Lxd MEDIUM 6.5
CVE-2026-9639

Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_stora…

Fix: 5.21.5 / 6.9+
Fix from $1,600 2026-06-26
Lxd CRITICAL 9.6
CVE-2026-12411

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another gu…

Fix: 6.9+
Fix from $2,300 2026-06-26
Ubuntu Linux HIGH 7.8
CVE-2026-47333

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a …

Patch available
Fix from $1,950 2026-05-28
Ubuntu Linux MEDIUM 5.5
CVE-2026-47334

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug…

Patch available
Fix from $1,600 2026-05-28
Ubuntu Linux MEDIUM 5.5
CVE-2026-47335

Ubuntu Linux 6.8 contains SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered …

Mitigation only
Fix from $1,600 2026-05-28
Ubuntu Linux HIGH 7.8
CVE-2026-47331

Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivileged local user could trigger …

Patch available
Fix from $1,950 2026-05-28
Ubuntu Linux MEDIUM 5.5
CVE-2026-47332

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-boun…

Patch available
Fix from $1,600 2026-05-28
Ubuntu Linux MEDIUM 6.1
CVE-2026-47328

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while …

Patch available
Fix from $1,600 2026-05-28
Ubuntu Linux MEDIUM 5.5
CVE-2026-47326

Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be tr…

Patch available
Fix from $1,600 2026-05-28
Multipass HIGH 8.4
CVE-2026-49238

An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root pr…

Fix: 1.16.3+
Fix from $1,950 2026-05-28
Multipass HIGH 7.8
CVE-2026-49237

An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version…

Fix: 1.16.3+
Fix from $1,950 2026-05-28
Pdfunite MEDIUM 5.5
CVE-2018-25306

PDFunite 0.41.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by processing malformed PDF files durin…

No fix yet
Fix from $1,600 2026-04-29
Livepatch Client MEDIUM 5.5
CVE-2026-6369

An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a…

Fix: 10.15.0+
Fix from $1,600 2026-04-20
Juju MEDIUM 6.4
CVE-2026-5774

Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possi…

Fix: 2.9.57 / 3.6.21+
Fix from $1,600 2026-04-10
Juju MEDIUM 6.5
CVE-2026-5412

In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API…

Fix: 2.9.57 / 3.6.21+
Fix from $1,600 2026-04-10
Ubuntu Desktop Provision CRITICAL 9.1
CVE-2025-15480

In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a use…

Patch available
Fix from $2,300 2026-04-09
Ubuntu Subiquity HIGH 8.1
CVE-2025-14551

In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a b…

Patch available
Fix from $1,950 2026-04-09
Lxd CRITICAL 9.1
CVE-2026-34177

Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omit…

Fix: after 6.7
Fix from $2,300 2026-04-09
Lxd CRITICAL 9.1
CVE-2026-34178

In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates …

Fix: after 6.7
Fix from $2,300 2026-04-09
Lxd CRITICAL 9.1
CVE-2026-34179

In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PU…

Fix: after 6.7
Fix from $2,300 2026-04-09
Juju MEDIUM 6.5
CVE-2025-68153

Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special ope…

Fix: after 3.6.18
Fix from $1,600 2026-04-03
Juju CRITICAL 10.0
CVE-2026-4370

A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster f…

Fix: 3.6.20 / 4.0.5+
Fix from $2,300 2026-04-01
Juju MEDIUM 6.6
CVE-2026-32694

In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret owner relies exclusively on a …

Fix: 3.6.19+
Fix from $1,600 2026-03-18
Juju HIGH 8.8
CVE-2026-32693

In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update th…

Fix: 3.6.19+
Fix from $1,950 2026-03-18
Juju MEDIUM 6.5
CVE-2026-32692

An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit…

Fix: 3.6.19+
Fix from $1,600 2026-03-18
Juju MEDIUM 5.3
CVE-2026-32691

A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit agent to claim ownership of a…

Fix: 3.6.19+
Fix from $1,600 2026-03-18
Ubuntu Linux HIGH 7.8
CVE-2026-3888

Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-t…

Mitigation only
Fix from $1,950 2026-03-17
Ubuntu Linux HIGH 7.5
CVE-2026-3497

Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Lin…

Mitigation only
Fix from $1,950 2026-03-12