CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-41685 MEDIUM

Incus: Unbounded binary import disk exhaustion

CVSS 4.3 EPSS 0.39% May 7, 2026
Go
CVE-2026-41684 MEDIUM

Incus: Nil Dereferences on Restore via Malformed YAML

CVSS 6.5 EPSS 0.47% May 7, 2026
Go
CVE-2026-41648 MEDIUM

Incus: Unbounded YAML Metadata Decode via Parsing

CVSS 5.3 EPSS 0.39% May 7, 2026
Go
CVE-2026-41647 MEDIUM

Incus: Nil-Pointer Dereference via S3 Bucket Import

CVSS 6.5 EPSS 0.47% May 7, 2026
Go
CVE-2026-40251 HIGH

Incus out-of-bounds panic in snapshot metadata handling allows denial of service

CVSS 7.1 EPSS 0.47% May 6, 2026
Go
CVE-2026-40243 LOW

Incus OVN TLS verification accepts peer-supplied roots and permits endpoint impersonation

CVSS 2.3 EPSS 0.22% May 6, 2026
Go
CVE-2026-40197 HIGH

Incus nil-pointer dereference in custom volume import allows denial of service

CVSS 7.1 EPSS 0.44% May 6, 2026
Go
CVE-2026-40195 HIGH

Incus nil-pointer dereference in storage bucket import allows denial of service

CVSS 7.1 EPSS 0.44% May 6, 2026
Go
CVE-2026-39402 MEDIUM

lxc lxc-user-nic insufficient ownership validation allows cross-tenant OVS port deletion

CVSS 4.3 EPSS 0.14% May 5, 2026
CVE-2026-35527 MEDIUM

Incus blind SSRF via image import preflight HEAD request

CVSS 5.3 EPSS 0.29% May 5, 2026
Go
CVE-2026-33945 CRITICAL

Abitrary file write through systemd-creds option

CVSS 10.0 EPSS 0.53% Mar 26, 2026
Go
CVE-2026-33898 HIGH

Local Incus UI web server vulnerable to nuthentication bypass

CVSS 8.8 EPSS 0.48% Mar 26, 2026
Go
CVE-2026-33897 CRITICAL

Incus vulnerable to arbitrary file read and write through pongo templates

CVSS 10.0 EPSS 0.53% Mar 26, 2026
Go
CVE-2026-33743 MEDIUM

Incus vulnerable to denial of source through crafted bucket backup file

CVSS 6.5 EPSS 0.44% Mar 26, 2026
Go
CVE-2026-33711 MEDIUM

Incus vulnerable to local privilege escalation through VM screenshot path

CVSS 4.7 EPSS 0.18% Mar 26, 2026
Go
CVE-2026-33542 HIGH

Incus does not verify combined fingerprint when downloading images from simplestreams servers

CVSS 7.0 EPSS 0.20% Mar 26, 2026
Go
CVE-2026-23954 HIGH

Incus container image templating arbitrary host file read and write

CVSS 8.7 EPSS 0.79% Jan 22, 2026
Go
CVE-2026-23953 HIGH

Incus container environment configuration newline injection

CVSS 8.7 EPSS 0.50% Jan 22, 2026
Go
CVE-2025-64507 HIGH

Incus vulnerable to local privilege escalation through custom storage volumes

CVSS 8.6 EPSS 0.17% Nov 10, 2025
Go
CVE-2022-47952 LOW

lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree,…

CVSS 3.3 EPSS 0.70% Jan 1, 2023
CVE-2017-18641 HIGH

In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.

CVSS 8.1 EPSS 1.35% Feb 10, 2020
CVE-2015-1340 HIGH

chmod race in doUidshiftIntoContainer

CVSS 8.1 EPSS 0.90% Apr 22, 2019
Go
CVE-2019-5736 HIGH

runc: Execution of malicious containers allows for container escape and access to host filesystem

CVSS 8.6 EPSS 98.45% Feb 11, 2019
CVE-2018-6556 LOW

The lxc-user-nic component of LXC allows unprivileged users to open arbitrary files

CVSS 3.3 EPSS 0.33% Aug 10, 2018
CVE-2016-8649 CRITICAL

lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptor, of the host's /…

CVSS 9.1 EPSS 2.81% May 1, 2017

Showing 1 to 25 CVEs · page 1 (more available)