Search CVE reports


Toggle filters

1061 – 1070 of 43643 results

Status is adjusted based on your filters.


CVE-2026-6726

Medium priority
Needs evaluation

An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an...

1 affected package

libtpms

Package 24.04 LTS
libtpms Needs evaluation
Show less packages

CVE-2026-66898

Medium priority

Not in release

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume...

1 affected package

lxd

Package 24.04 LTS
lxd Not in release
Show less packages

CVE-2026-66379

Medium priority

Not in release

An authenticated user may view private Puppet module metadata without repository read access.

1 affected package

puppet

Package 24.04 LTS
puppet Not in release
Show less packages

CVE-2026-6426

Medium priority
Needs evaluation

A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size is stored as a uint64_t but read by the VMS_VBUFFER load path as a signed int32_t. On little-endian hosts, a...

1 affected package

qemu

Package 24.04 LTS
qemu Needs evaluation
Show less packages

CVE-2026-63622

Medium priority
Vulnerable

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within...

1 affected package

libvirt

Package 24.04 LTS
libvirt Vulnerable
Show less packages

CVE-2026-63300

Medium priority

Not in release

An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level...

1 affected package

lxd

Package 24.04 LTS
lxd Not in release
Show less packages

CVE-2026-63299

Medium priority

Not in release

An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations:...

1 affected package

lxd

Package 24.04 LTS
lxd Not in release
Show less packages

CVE-2026-63297

Medium priority

Not in release

An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance...

1 affected package

lxd

Package 24.04 LTS
lxd Not in release
Show less packages

CVE-2026-63296

Medium priority

Not in release

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides...

1 affected package

lxd

Package 24.04 LTS
lxd Not in release
Show less packages

CVE-2026-63295

Medium priority

Not in release

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing...

1 affected package

lxd

Package 24.04 LTS
lxd Not in release
Show less packages