Vulnerability index

Browse CVEs

84 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nginx Ingress Controller HIGH 8.8
CVE-2026-4342

A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can …

Fix: 1.13.9 / 1.14.5+
Fix from $1,950 2026-03-19
Ingress Nginx HIGH 8.8
CVE-2026-3288EPSS 6%

A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject conf…

Fix: 1.13.8 / 1.14.4+
Fix from $1,950 2026-03-09
Cri O HIGH 8.1
CVE-2024-5154

A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw…

Mitigation only
Fix from $1,950 2024-06-12
Kubernetes HIGH 8.8
CVE-2023-5528

A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes may be able to escalate to ad…

Fix: 1.25.16 / 1.26.11+
Fix from $1,950 2023-11-14
Apiserver HIGH 8.2
CVE-2022-3172

A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to t…

Fix: 1.22.14 / 1.23.11+
Fix from $1,950 2023-11-03
Csi Proxy HIGH 8.8
CVE-2023-3893

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escala…

Fix: after 1.1.2
Fix from $1,950 2023-11-03
Kubernetes HIGH 8.8
CVE-2023-3676EPSS 12%

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on tho…

Fix: 1.24.17 / 1.25.13+
Fix from $1,950 2023-10-31
Kubernetes HIGH 8.8
CVE-2023-3955

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on tho…

Fix: 1.24.17 / 1.25.13+
Fix from $1,950 2023-10-31
Kubernetes MEDIUM 6.3
CVE-2021-25736

Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*].port”) as a LoadBalancer S…

Fix: 1.18.18 / 1.19.10+
Fix from $1,600 2023-10-30
Ingress Nginx HIGH 8.8
CVE-2023-5043

Ingress nginx annotation injection causes arbitrary command execution.

Fix: 1.9.0+
Fix from $1,950 2023-10-25
Ingress Nginx HIGH 8.8
CVE-2023-5044EPSS 57%

Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.

Fix: 1.9.0+
Fix from $1,950 2023-10-25
Ingress Nginx MEDIUM 6.5
CVE-2022-4886

Ingress-nginx `path` sanitization can be bypassed with `log_format` directive.

Fix: 1.8.0+
Fix from $1,600 2023-10-25
Operations HIGH 8.8
CVE-2023-1943

Privilege Escalation in kOps using GCE/GCP Provider in Gossip Mode.

Fix: 1.25.4 / 1.26.2+
Fix from $1,950 2023-10-12
Cri O HIGH 7.8
CVE-2022-4318

A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment vari…

Mitigation only
Fix from $1,950 2023-09-25
Kube Apiserver HIGH 8.0
CVE-2023-1260

An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given p…

Mitigation only
Fix from $1,950 2023-09-24
Cri O MEDIUM 5.3
CVE-2022-3466

The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-20…

Mitigation only
Fix from $1,600 2023-09-15
Kubernetes MEDIUM 6.5
CVE-2023-2727

Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters ar…

Fix: after 1.27.2
Fix from $1,600 2023-07-03
Kubernetes MEDIUM 6.5
CVE-2023-2728

Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral …

Fix: after 1.27.2
Fix from $1,600 2023-07-03
Kubernetes MEDIUM 5.5
CVE-2023-2431

A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profi…

Fix: 1.24.14 / 1.25.10+
Fix from $1,600 2023-06-16
Secrets Store Csi Driver MEDIUM 5.5
CVE-2023-2878

Kubernetes secrets-store-csi-driver in versions before 1.3.3 discloses service account tokens in logs.

Fix: 1.3.3+
Fix from $1,600 2023-06-07
Minikube CRITICAL 9.8
CVE-2023-1174

This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected remote access to the minikube …

Mitigation only
Fix from $2,300 2023-05-24
Kubernetes HIGH 7.8
CVE-2021-25749

Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true.

Fix: 1.22.14 / 1.23.11+
Fix from $1,950 2023-05-24
Minikube HIGH 7.8
CVE-2023-1944

This vulnerability enables ssh access to minikube container using a default password.

Fix: after 1.29.0
Fix from $1,950 2023-05-24
Ingress Nginx MEDIUM 6.5
CVE-2021-25748

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the san…

Fix: 1.2.1+
Fix from $1,600 2023-05-24
Kubernetes HIGH 8.8
CVE-2022-3294

Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node ob…

Fix: 1.22.16 / 1.23.14+
Fix from $1,950 2023-03-01
Kubernetes MEDIUM 6.5
CVE-2022-3162

Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API g…

Fix: after 1.25.3
Fix from $1,600 2023-03-01
Cri O HIGH 7.1
CVE-2022-2995

Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modifica…

Patch available
Fix from $1,950 2022-09-19
Aws Iam Authenticator HIGH 8.8
CVE-2022-2385

A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privile…

Fix: 0.5.9+
Fix from $1,950 2022-07-12
Cri O HIGH 7.5
CVE-2022-1708

A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync reque…

Fix: 1.19.7 / 1.20.8+
Fix from $1,950 2022-06-07
Ingress Nginx HIGH 8.1
CVE-2021-25745

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path fi…

Fix: 1.2.0+
Fix from $1,950 2022-05-06