Search CVE reports


Toggle filters

1231 – 1240 of 47438 results

Status is adjusted based on your filters.


CVE-2026-54789

Medium priority
Needs evaluation

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte...

1 affected package

libapache2-mod-auth-openidc

Package 20.04 LTS
libapache2-mod-auth-openidc Needs evaluation
Show less packages

CVE-2026-55622

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name...

2 affected packages

incus, lxd

Package 20.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-55621

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the...

2 affected packages

incus, lxd

Package 20.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-48769

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead...

2 affected packages

incus, lxd

Package 20.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-48756

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateCustomVolumeFromBackup` in `internal/server/storage/backend.go` contains an unguarded `*time.Time` dereference on the `ExpiresAt`...

2 affected packages

incus, lxd

Package 20.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-48755

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an...

2 affected packages

incus, lxd

Package 20.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-48752

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command...

2 affected packages

incus, lxd

Package 20.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-48751

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing...

2 affected packages

incus, lxd

Package 20.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-48750

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the...

2 affected packages

incus, lxd

Package 20.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-48749

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version...

2 affected packages

incus, lxd

Package 20.04 LTS
incus
lxd Needs evaluation
Show less packages