Search CVE reports


Toggle filters

1151 – 1160 of 56955 results

Status is adjusted based on your filters.


CVE-2026-55622

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name...

2 affected packages

incus, lxd

Package 16.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-55621

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the...

2 affected packages

incus, lxd

Package 16.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-48769

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead...

2 affected packages

incus, lxd

Package 16.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-48756

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateCustomVolumeFromBackup` in `internal/server/storage/backend.go` contains an unguarded `*time.Time` dereference on the `ExpiresAt`...

2 affected packages

incus, lxd

Package 16.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-48755

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an...

2 affected packages

incus, lxd

Package 16.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-48752

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command...

2 affected packages

incus, lxd

Package 16.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-48751

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing...

2 affected packages

incus, lxd

Package 16.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-48750

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the...

2 affected packages

incus, lxd

Package 16.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-48749

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version...

2 affected packages

incus, lxd

Package 16.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-77806

Medium priority
Needs evaluation

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by...

1 affected package

spip

Package 16.04 LTS
spip Needs evaluation
Show less packages