Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.5 CVE-2026-13325 A flaw was found in KubeVirt's migration proxy. When spec.configuration.migrations.disableTLS is set to true on the KubeVirt custom resource, the tar… Kubevirt after 4.22.0 Fix from $1,9502026-06-26 MEDIUM 6.4 CVE-2026-13318 A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-forward request to a VirtualM… Kubevirt after 4.22.0 Fix from $1,6002026-06-26 HIGH 7.3 CVE-2026-13201 A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor … Kubevirt after 4.22.0 Fix from $1,9502026-06-24 MEDIUM 6.5 CVE-2026-13208 A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity … Kubevirt after 4.22.0 Fix from $1,6002026-06-24 HIGH 7.7 CVE-2025-64324 KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a host file or directory owned by … Kubevirt 1.6.1+ Fix from $1,9502025-11-18 MEDIUM 5.3 CVE-2025-64436 KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, su… Kubevirt after 1.6.1 Fix from $1,6002025-11-07 MEDIUM 5.0 CVE-2025-64437 KubeVirt is a virtual machine management add-on for Kubernetes. In versions before 1.5.3 and 1.6.1, the virt-handler does not verify whether the laun… Kubevirt 1.5.3+ Fix from $1,6002025-11-07 MEDIUM 6.5 CVE-2025-64433 KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, a vulnerability was discovered that allows a VM to read arb… Kubevirt 1.5.3+ Fix from $1,6002025-11-07 MEDIUM 6.3 CVE-2025-64434 KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, due to the peer verification logic in virt-handler (via ver… Kubevirt 1.5.3+ Fix from $1,6002025-11-07 MEDIUM 5.3 CVE-2025-64435 KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.7.0-beta.0, a logic flaw in the virt-controller allows an attacker to disr… Kubevirt after 1.6.3 Fix from $1,6002025-11-07 MEDIUM 5.9 CVE-2024-33394 An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component. Kubevirt after 1.2.0 Fix from $1,6002024-05-02 HIGH 8.2 CVE-2023-26484 KubeVirt is a virtual machine management add-on for Kubernetes. In versions 0.59.0 and prior, if a malicious user has taken over a Kubernetes node wh… Kubevirt after 0.59.0 Fix from $1,9502023-03-15 MEDIUM 6.5 CVE-2022-1798 A path traversal vulnerability in KubeVirt versions up to 0.56 (and 0.55.1) on all platforms allows a user able to configure the kubevirt to read arb… Kubevirt 0.55.1+ Fix from $1,6002022-09-15 MEDIUM 6.5 CVE-2020-1701 A flaw was found in the KubeVirt main virt-handler versions before 0.26.0 regarding the access permissions of virt-handler. An attacker with access t… Kubevirt 0.26.0+ Fix from $1,6002021-05-27 CRITICAL 9.9 CVE-2020-14316 A flaw was found in kubevirt 0.29 and earlier. Virtual Machine Instances (VMIs) can be used to gain access to the host's filesystem. Successful explo… Kubevirt after 0.29 Fix from $2,3002020-07-29 MEDIUM 6.5 CVE-2019-10175 A flaw was found in the containerized-data-importer in virt-cdi-cloner, version 1.4, where the host-assisted cloning feature does not determine wheth… Containerized Data Importer Mitigation only Fix from $1,6002019-06-28 MEDIUM 6.8 CVE-2019-3841 Kubevirt/virt-cdi-importer, versions 1.4.0 to 1.5.3 inclusive, were reported to disable TLS certificate validation when importing data into PVCs from… Containerized Data Importer after 1.5.3 Fix from $1,6002019-03-25