CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-102371 MEDIUM

wsl-pro-service: Ubuntu Pro token exposed via process command-line arguments

CVSS 5.7 EPSS 0.11% Sep 29, 2026
CVE-2026-87798 MEDIUM

LXD client recursive file pull allows directory escape via malicious VM agent

CVSS 5.8 EPSS 0.19% Sep 28, 2026
CVE-2026-87799 CRITICAL

Arbitrary file write on LXD host via symlink in migration stream

CVSS 9.9 EPSS 0.41% Sep 28, 2026
CVE-2026-97335 HIGH

Incorrect authorization in LXD storage volume API allows reading volumes from other projects

CVSS 7.7 EPSS 0.21% Sep 28, 2026
CVE-2026-85185 CRITICAL

Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root

CVSS 9.6 EPSS 0.36% Sep 28, 2026
CVE-2026-85526 CRITICAL

Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD

CVSS 9.9 EPSS 0.52% Sep 28, 2026
CVE-2026-86335 MEDIUM

LXD Cross-Project Private Image Theft via Unsanitized GetImageFromAnyProject Local Reuse

CVSS 6.3 EPSS 0.22% Sep 28, 2026
CVE-2026-86334 MEDIUM

CLI Path Traversal via Content-Disposition in LXD Image Export/Copy

CVSS 4.2 EPSS 0.34% Sep 28, 2026
CVE-2026-66897 CRITICAL

Instance template path traversal allows arbitrary host file write as root

CVSS 9.9 EPSS 0.72% Aug 24, 2026
CVE-2026-77113 MEDIUM

Path Traversal Vulnerability in apport-unpack

CVSS 6.7 EPSS 0.20% Aug 20, 2026
CVE-2026-61898 HIGH

accountsservice: shell injection via attacker-controlled ~/.pam_environment in Ubuntu language helper scripts

CVSS 7.8 EPSS 0.19% Aug 20, 2026
CVE-2026-61897 HIGH

accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scripts

CVSS 7.8 EPSS 0.14% Aug 20, 2026
CVE-2026-16033 HIGH

Arbitrary file read+write on host via templates/ symlink in malicious image

CVSS 8.5 EPSS 0.35% Aug 12, 2026
CVE-2026-66898 CRITICAL

Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE

CVSS 9.9 EPSS 0.59% Aug 12, 2026
CVE-2026-63293 CRITICAL

Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root

CVSS 9.9 EPSS 0.59% Aug 12, 2026
CVE-2026-63294 CRITICAL

Root RCE via image backup.yaml symlink

CVSS 9.9 EPSS 0.88% Aug 12, 2026
CVE-2026-63295 MEDIUM

Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated`

CVSS 4.3 EPSS 0.35% Aug 12, 2026
CVE-2026-63296 CRITICAL

Project restriction bypass via instance migration config override

CVSS 9.9 EPSS 0.44% Aug 12, 2026
CVE-2026-63297 CRITICAL

Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge

CVSS 9.9 EPSS 0.34% Aug 12, 2026
CVE-2026-63298 CRITICAL

LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration

CVSS 9.9 EPSS 0.69% Aug 12, 2026
CVE-2026-63299 CRITICAL

Storage volume cross-project move and snapshot restore bypass project disk limits

CVSS 9.9 EPSS 0.59% Aug 12, 2026
CVE-2026-62420 CRITICAL

Cross-project cluster migration bypasses project restrictions via cluster notification flag

CVSS 9.9 EPSS 0.54% Aug 12, 2026
CVE-2026-63300 CRITICAL

Cross-project instance move bypasses all project restrictions allowing host command execution

CVSS 9.9 EPSS 0.54% Aug 12, 2026
CVE-2026-12391 MEDIUM

ubuntu-pro-client Local Privilege Escalation and Information Disclosure via Symlink Arbitrary File Read in collect-logs

CVSS 5.0 EPSS 0.21% Jul 16, 2026
CVE-2026-11386 CRITICAL

ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code Execution

CVSS 9.0 EPSS 0.53% Jul 16, 2026

Showing 1 to 25 CVEs · page 1 (more available)