CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
wsl-pro-service: Ubuntu Pro token exposed via process command-line arguments
LXD client recursive file pull allows directory escape via malicious VM agent
Arbitrary file write on LXD host via symlink in migration stream
Incorrect authorization in LXD storage volume API allows reading volumes from other projects
Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root
Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD
LXD Cross-Project Private Image Theft via Unsanitized GetImageFromAnyProject Local Reuse
CLI Path Traversal via Content-Disposition in LXD Image Export/Copy
Instance template path traversal allows arbitrary host file write as root
Path Traversal Vulnerability in apport-unpack
accountsservice: shell injection via attacker-controlled ~/.pam_environment in Ubuntu language helper scripts
accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scripts
Arbitrary file read+write on host via templates/ symlink in malicious image
Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE
Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root
Root RCE via image backup.yaml symlink
Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated`
Project restriction bypass via instance migration config override
Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge
LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration
Storage volume cross-project move and snapshot restore bypass project disk limits
Cross-project cluster migration bypasses project restrictions via cluster notification flag
Cross-project instance move bypasses all project restrictions allowing host command execution
ubuntu-pro-client Local Privilege Escalation and Information Disclosure via Symlink Arbitrary File Read in collect-logs
ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code Execution
Showing 1 to 25 CVEs · page 1 (more available)