Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kubevirt HIGH 8.5
CVE-2026-13325

A flaw was found in KubeVirt's migration proxy. When spec.configuration.migrations.disableTLS is set to true on the KubeVirt custom resource, the tar…

Fix: after 4.22.0
Fix from $1,950 2026-06-26
Kubevirt MEDIUM 6.4
CVE-2026-13318

A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-forward request to a VirtualM…

Fix: after 4.22.0
Fix from $1,600 2026-06-26
Kubevirt HIGH 7.3
CVE-2026-13201

A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor …

Fix: after 4.22.0
Fix from $1,950 2026-06-24
Kubevirt MEDIUM 6.5
CVE-2026-13208

A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity …

Fix: after 4.22.0
Fix from $1,600 2026-06-24
Kubevirt HIGH 7.7
CVE-2025-64324

KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a host file or directory owned by …

Fix: 1.6.1+
Fix from $1,950 2025-11-18
Kubevirt MEDIUM 5.3
CVE-2025-64436

KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, su…

Fix: after 1.6.1
Fix from $1,600 2025-11-07
Kubevirt MEDIUM 5.0
CVE-2025-64437

KubeVirt is a virtual machine management add-on for Kubernetes. In versions before 1.5.3 and 1.6.1, the virt-handler does not verify whether the laun…

Fix: 1.5.3+
Fix from $1,600 2025-11-07
Kubevirt MEDIUM 6.5
CVE-2025-64433

KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, a vulnerability was discovered that allows a VM to read arb…

Fix: 1.5.3+
Fix from $1,600 2025-11-07
Kubevirt MEDIUM 6.3
CVE-2025-64434

KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, due to the peer verification logic in virt-handler (via ver…

Fix: 1.5.3+
Fix from $1,600 2025-11-07
Kubevirt MEDIUM 5.3
CVE-2025-64435

KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.7.0-beta.0, a logic flaw in the virt-controller allows an attacker to disr…

Fix: after 1.6.3
Fix from $1,600 2025-11-07
Kubevirt MEDIUM 5.9
CVE-2024-33394

An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

Fix: after 1.2.0
Fix from $1,600 2024-05-02
Kubevirt HIGH 8.2
CVE-2023-26484

KubeVirt is a virtual machine management add-on for Kubernetes. In versions 0.59.0 and prior, if a malicious user has taken over a Kubernetes node wh…

Fix: after 0.59.0
Fix from $1,950 2023-03-15
Kubevirt MEDIUM 6.5
CVE-2022-1798

A path traversal vulnerability in KubeVirt versions up to 0.56 (and 0.55.1) on all platforms allows a user able to configure the kubevirt to read arb…

Fix: 0.55.1+
Fix from $1,600 2022-09-15
Kubevirt MEDIUM 6.5
CVE-2020-1701

A flaw was found in the KubeVirt main virt-handler versions before 0.26.0 regarding the access permissions of virt-handler. An attacker with access t…

Fix: 0.26.0+
Fix from $1,600 2021-05-27
Kubevirt CRITICAL 9.9
CVE-2020-14316

A flaw was found in kubevirt 0.29 and earlier. Virtual Machine Instances (VMIs) can be used to gain access to the host's filesystem. Successful explo…

Fix: after 0.29
Fix from $2,300 2020-07-29
Containerized Data Importer MEDIUM 6.5
CVE-2019-10175

A flaw was found in the containerized-data-importer in virt-cdi-cloner, version 1.4, where the host-assisted cloning feature does not determine wheth…

Mitigation only
Fix from $1,600 2019-06-28
Containerized Data Importer MEDIUM 6.8
CVE-2019-3841

Kubevirt/virt-cdi-importer, versions 1.4.0 to 1.5.3 inclusive, were reported to disable TLS certificate validation when importing data into PVCs from…

Fix: after 1.5.3
Fix from $1,600 2019-03-25