24 Total CVEs
24 AI Analyzed
0 CISA KEV
14 Critical

Profile

0% ended up actively exploited 0 of 24 added to CISA KEV
58% rated critical (CVSS 9.0+) 14 critical, 10 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

21 CVEs in the last 12 months

Products

  • LXD13
  • Juju2
  • allows local1
  • ADSys1
  • Ubuntu1

5 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-24 of 24 CVEs
CVE-2026-66898
Analyzed
9.9
Canonical LXD

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations, potentially lead...

2026-08-13
CVE-2026-66897
Analyzed
9.9
Canonical LXD

A path traversal vulnerability in Canonical LXD allows authenticated users to escape container confinement and achieve host root code execution by ove...

2026-08-25
CVE-2026-63300
Analyzed
9.9
Canonical LXD

LXD fails to validate instance configurations during migration, allowing an authenticated attacker to bypass project-level security restrictions and e...

2026-08-13
CVE-2026-63298
Analyzed
8.7
Canonical LXD

An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to injec...

2026-08-14
CVE-2026-63297
Analyzed
9.9
Canonical LXD

A time-of-check to time-of-use race condition in Canonical LXD allows authenticated users to bypass project security restrictions during cross-project...

2026-08-13
CVE-2026-63296
Analyzed
9.9
Canonical LXD

An authorization bypass in Canonical LXD allows authenticated users to move instances into restricted projects while bypassing enforced configuration...

2026-08-13
CVE-2026-63294
Analyzed
9.9
Canonical LXD

A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system by providing a malicious archive with a...

2026-08-13
CVE-2026-63293
Analyzed
9.9
Canonical LXD

A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system by providing a crafted...

2026-08-13
CVE-2026-62420
Analyzed
9.9
Canonical LXD

An authorization bypass in Canonical LXD allows authenticated attackers to skip project security checks during cross-project migrations by masqueradin...

2026-08-13
CVE-2026-5412
Analyzed
9.9
Canonical Juju

Juju contains an authorization flaw in the Controller facade that allows authenticated users to extract sensitive cloud credentials.

2026-04-11
CVE-2026-49238
Analyzed
8.4
Canonical Multiple Products

An issue was discovered in Canonical Multipass before version 1

2026-05-29
CVE-2026-4370
Analyzed
10
Canonical Juju

Juju's internal Dqlite database fails to validate TLS certificates, allowing unauthenticated attackers to join the cluster and gain full read/write ac...

2026-04-02
CVE-2026-3888
Analyzed
7.8
Canonical allows local

Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tm...

2026-03-18
CVE-2026-34179
Analyzed
9.1
Canonical LXD

Canonical LXD versions 4.12 through 6.7 contain a privilege escalation vulnerability where restricted TLS certificate users can elevate to cluster adm...

2026-04-09
CVE-2026-34178
Analyzed
9.1
Canonical LXD

A backup import validation flaw in Canonical LXD allows authenticated remote attackers to bypass project restrictions and achieve full host compromise...

2026-04-09
CVE-2026-34177
Analyzed
9.1
Canonical LXD

An incomplete denylist in Canonical LXD allows a restricted project user to inject AppArmor and QEMU configurations, facilitating privilege escalation...

2026-04-09
CVE-2026-32693
Analyzed
8.8
Canonical Multiple Products

In Juju from version 3

2026-03-19
CVE-2026-32692
Analyzed
7.6
Canonical Multiple Products

An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3

2026-03-19
CVE-2026-12411
Analyzed
8.4
Canonical LXD

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another gue...

2026-06-27
CVE-2026-12249
Analyzed
8.3
Canonical ADSys

An issue was discovered in Canonical ADSys upstream versions through v0

2026-06-23
CVE-2026-10037
Analyzed
8.8
Canonical Ubuntu

A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu

2026-07-09
CVE-2025-53513
Analyzed
8.8
Canonical Multiple Products

The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a char...

2025-07-10
CVE-2025-0928
Analyzed
8.8
Canonical Multiple Products

In Juju versions prior to 3

2025-07-10
CVE-2024-6107
Analyzed
9.6
Canonical Multiple Products

Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has...

2025-07-22