Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Policy Reporter Ui MEDIUM 6.1
CVE-2026-44245

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 2.5.2, Vue 3's v-html directive is the framework-documented…

Fix: 2.5.2+
Fix from $1,600 2026-05-12
Kyverno HIGH 7.7
CVE-2026-41485

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.17.2 and 1.16.4, an unchecked type assertion in …

Fix: 1.16.4 / 1.17.2+
Fix from $1,950 2026-04-24
Kyverno CRITICAL 9.1
CVE-2026-41323

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc1, and 1.16.4, Kyverno's apiC…

Fix: 1.16.4 / 1.17.2+
Fix from $2,300 2026-04-24
Kyverno HIGH 7.7
CVE-2026-41068

Kyverno is a policy engine designed for cloud native platform engineering teams. The patch for CVE-2026-22039 fixed cross-namespace privilege escalat…

Fix: 1.17.2+
Fix from $1,950 2026-04-24
Kyverno HIGH 8.1
CVE-2026-40868

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 1.16.4, kyverno’s apiCall servicecall helper implicitly inj…

Fix: 1.16.4+
Fix from $1,950 2026-04-21
Kyverno CRITICAL 9.8
CVE-2026-4789

Kyverno, versions 1.16.0 and later, are vulnerable to SSRF due to unrestricted CEL HTTP functions.

Fix: after 1.17.1
Fix from $2,300 2026-03-30
Kyverno CRITICAL 9.9
CVE-2026-22039

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization bo…

Fix: 1.15.3 / 1.16.3+
Fix from $2,300 2026-01-27
Kyverno MEDIUM 6.5
CVE-2026-23881

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have unbounded memory consumptio…

Fix: 1.15.3 / 1.16.3+
Fix from $1,600 2026-01-27
Kyverno HIGH 7.7
CVE-2025-47281

Kyverno is a policy engine designed for cloud native platform engineering teams. In versions 1.14.1 and below, a Denial of Service (DoS) vulnerabilit…

Fix: 1.14.2+
Fix from $1,950 2025-07-23
Kyverno HIGH 8.2
CVE-2025-46342

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.13.5 and 1.14.0, it may happen that policy rules…

Fix: 1.13.5+
Fix from $1,950 2025-04-30
Kyverno HIGH 8.0
CVE-2025-29778

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyverno ignores subjectRegExp and I…

Fix: 1.13.6+
Fix from $1,950 2025-03-24
Kyverno HIGH 7.1
CVE-2023-47630

Kyverno is a policy engine designed for Kubernetes. An issue was found in Kyverno that allowed an attacker to control the digest of images used by Ky…

Fix: 1.10.5+
Fix from $1,950 2023-11-14
Kyverno HIGH 8.1
CVE-2022-47633

An image signature validation bypass vulnerability in Kyverno 1.8.3 and 1.8.4 allows a malicious image registry (or a man-in-the-middle attacker) to …

Patch available
Fix from $1,950 2022-12-23