Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2026-4342
A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can …
Nginx Ingress Controller
1.13.9 / 1.14.5+
HIGH 8.8
CVE-2026-3288EPSS 6%
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject conf…
Ingress Nginx
1.13.8 / 1.14.4+
HIGH 8.1
CVE-2024-5154
A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw…
Cri O
Mitigation only
HIGH 8.8
CVE-2023-5528
A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes may be able to escalate to ad…
Kubernetes
1.25.16 / 1.26.11+
HIGH 8.2
CVE-2022-3172
A security issue was discovered in kube-apiserver that allows an
aggregated API server to redirect client traffic to any URL. This could
lead to t…
Apiserver
1.22.14 / 1.23.11+
HIGH 8.8
CVE-2023-3893
A security issue was discovered in Kubernetes where a user that can
create pods on Windows nodes running kubernetes-csi-proxy may be able to
escala…
Csi Proxy
after 1.1.2
HIGH 8.8
CVE-2023-3676EPSS 12%
A security issue was discovered in Kubernetes where a user
that can create pods on Windows nodes may be able to escalate to admin
privileges on tho…
Kubernetes
1.24.17 / 1.25.13+
HIGH 8.8
CVE-2023-3955
A security issue was discovered in Kubernetes where a user
that can create pods on Windows nodes may be able to escalate to admin
privileges on tho…
Kubernetes
1.24.17 / 1.25.13+
MEDIUM 6.3
CVE-2021-25736
Kube-proxy
on Windows can unintentionally forward traffic to local processes
listening on the same port (“spec.ports[*].port”) as a LoadBalancer
S…
Kubernetes
1.18.18 / 1.19.10+
HIGH 8.8
CVE-2023-5043
Ingress nginx annotation injection causes arbitrary command execution.
Ingress Nginx
1.9.0+
HIGH 8.8
CVE-2023-5044EPSS 57%
Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.
Ingress Nginx
1.9.0+
MEDIUM 6.5
CVE-2022-4886
Ingress-nginx `path` sanitization can be bypassed with `log_format` directive.
Ingress Nginx
1.8.0+
HIGH 8.8
CVE-2023-1943
Privilege Escalation in kOps using GCE/GCP Provider in Gossip Mode.
Operations
1.25.4 / 1.26.2+
HIGH 7.8
CVE-2022-4318
A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment vari…
Cri O
Mitigation only
HIGH 8.0
CVE-2023-1260
An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given p…
Kube Apiserver
Mitigation only
MEDIUM 5.3
CVE-2022-3466
The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-20…
Cri O
Mitigation only
MEDIUM 6.5
CVE-2023-2727
Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters ar…
Kubernetes
after 1.27.2
MEDIUM 6.5
CVE-2023-2728
Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral …
Kubernetes
after 1.27.2
MEDIUM 5.5
CVE-2023-2431
A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profi…
Kubernetes
1.24.14 / 1.25.10+
MEDIUM 5.5
CVE-2023-2878
Kubernetes secrets-store-csi-driver in versions before 1.3.3 discloses service account tokens in logs.
Secrets Store Csi Driver
1.3.3+
CRITICAL 9.8
CVE-2023-1174
This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected remote access to the minikube …
Minikube
Mitigation only
HIGH 7.8
CVE-2021-25749
Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true.
Kubernetes
1.22.14 / 1.23.11+
HIGH 7.8
CVE-2023-1944
This vulnerability enables ssh access to minikube container using a default password.
Minikube
after 1.29.0
MEDIUM 6.5
CVE-2021-25748
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the san…
Ingress Nginx
1.2.1+
HIGH 8.8
CVE-2022-3294
Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node ob…
Kubernetes
1.22.16 / 1.23.14+
MEDIUM 6.5
CVE-2022-3162
Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API g…
Kubernetes
after 1.25.3
HIGH 7.1
CVE-2022-2995
Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modifica…
Cri O
Patch available
HIGH 8.8
CVE-2022-2385
A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privile…
Aws Iam Authenticator
0.5.9+
HIGH 7.5
CVE-2022-1708
A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync reque…
Cri O
1.19.7 / 1.20.8+
HIGH 8.1
CVE-2021-25745
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path fi…
Ingress Nginx
1.2.0+