canonical

4,226 tracked vulnerabilities.

CVE-2025-54292 MEDIUM
Canonical LXD 5.0.0-5.21.4 - Authenticated Path Traversal via URL Path Resource Names
Oct 02, 2025
CVSS 4.6
EPSS 0.00
CVE-2025-54291 MEDIUM
Canonical LXD < 5.21.4 - Unauthenticated Information Disclosure via Images API
Oct 02, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-54290 MEDIUM
Canonical LXD < 5.21.4 - Unauthenticated Information Disclosure via Image Export API
Oct 02, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-54289 HIGH
Canonical LXD < 5.21.4 - Privilege Escalation via WebSocket Connection Hijacking
Oct 02, 2025
CVSS 8.1
EPSS 0.00
CVE-2025-54288 MEDIUM
Canonical LXD 4.0-5.21.4 - Authenticated Information Spoofing via Process Name
Oct 02, 2025
CVSS 6.8
EPSS 0.00
CVE-2025-54287 MEDIUM
Canonical LXD >=4.0 - Info Disclosure
Oct 02, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-54286 HIGH
Canonical LXD >=5.0 <5.0.5 - Cross-Site Request Forgery via Client Certificate Authentication
Oct 02, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-5199 HIGH
Canonical Multipass <= 1.15.1 - Privilege Escalation via Launch Daemon File Modification
Jul 12, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-0928 HIGH
Juju < 2.9.52 and < 3.6.8 - Authenticated Arbitrary Agent Binary Upload
Jul 08, 2025
CVSS 8.8
EPSS 0.02
CVE-2025-53513 HIGH
Juju < 2.9.52 - Path Traversal via Malicious Charm Upload
Jul 08, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-53512 MEDIUM
Juju < 2.9.52 - Unauthenticated Sensitive Information Exposure via /log Endpoint
Jul 08, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-6224 MEDIUM
juju/utils 4.0.0-4.0.4 - Cleartext Storage of Sensitive Information in Certificate Generation
Jul 01, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-32463 CRITICAL KEVNUCLEI
Sudo <1.9.17p1 - Privilege Escalation
Jun 30, 2025
CVSS 9.3
EPSS 0.57
CVE-2025-5689 HIGH
authd < 0.5.4 - Improper Privilege Management
Jun 16, 2025
CVSS 8.5
EPSS 0.00
CVE-2025-5054 MEDIUM
Canonical apport <2.32.0 - Info Disclosure
May 30, 2025
CVSS 4.7
EPSS 0.00
CVE-2025-24375 MEDIUM
Charmed MySQL K8s Operator <221 - SQL Injection
Apr 09, 2025
CVSS 5.0
EPSS 0.00
CVE-2025-31479 HIGH
canonical/get-workflow-version-action < 1.0.1 - Sensitive Information Disclosure in Exception Output
Apr 02, 2025
CVSS 8.2
EPSS 0.00
CVE-2025-26466 MEDIUM
OpenSSH - Denial of Service via Ping Packet Memory Exhaustion
Feb 28, 2025
CVSS 5.9
EPSS 0.62
CVE-2024-6107 CRITICAL
Canonical Metal as a Service 3.1.0-3.1.3 - Unauthenticated RPC Command Execution via Malicious Client
Jul 21, 2025
CVSS 9.6
EPSS 0.00
CVE-2024-6174 HIGH
cloud-init < 25.1.3 - Unauthenticated Root Access via Hardcoded Local IP URL
Jun 26, 2025
CVSS 8.8
EPSS 0.00
CVE-2024-11584 MEDIUM
cloud-init <25.1.2 - Privilege Escalation
Jun 26, 2025
CVSS 5.9
EPSS 0.00
CVE-2024-6219 LOW
LXD < 5.21.1 - Improper Certificate Validation in PKI Mode
Dec 06, 2024
CVSS 3.8
EPSS 0.00
CVE-2024-6156 LOW
LXD < 5.21.2 - Improper Certificate Validation in PKI Mode
Dec 06, 2024
CVSS 3.8
EPSS 0.00
CVE-2024-9312 HIGH
Authd <0.3.6 - Privilege Escalation
Oct 10, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-9313 HIGH
Authd PAM <0.3.5 - Privilege Escalation
Oct 03, 2024
CVSS 8.8
EPSS 0.00