29 Total CVEs
25 AI Analyzed
0 CISA KEV
12 Critical
All Vendors
Showing 1-29 of 29 CVEs
CVE-2026-23881
Analyzed
7.7
Kubernetes Multiple Products

Kyverno is a policy engine designed for cloud native platform engineering teams

2026-01-28
CVE-2026-22806
Analyzed
9.1
Kubernetes Multiple Products

vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to versions 4.6.0, 4.5.4, 4....

2026-01-30
CVE-2026-22771
Analyzed
8.8
Kubernetes Multiple Products

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

2026-01-13
CVE-2026-22039
Analyzed
9.9
Kubernetes Multiple Products

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization bou...

2026-01-28
CVE-2026-1531
Analyzed
8.1
Kubernetes Multiple Products

A flaw was found in foreman_kubevirt

2026-02-02
CVE-2026-1530
Analyzed
8.1
Kubernetes Multiple Products

A flaw was found in fog-kubevirt

2026-02-02
CVE-2025-9276
Analyzed
9.8
Kubernetes Multiple Products

Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability. This vulnerability could allow remote attackers to...

2025-09-02
CVE-2025-7342
Analyzed
7.5
Kubernetes Multiple Products

A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the image build process

2025-08-18
CVE-2025-66626
8.1
Kubernetes Multiple Products

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes

2025-12-10
CVE-2025-66623
7.4
Kubernetes Multiple Products

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations

2025-12-06
CVE-2025-64709
Analyzed
9.6
Kubernetes Multiple Products

Typebot is an open-source chatbot builder. In versions prior to 3.13.1, a Server-Side Request Forgery (SSRF) vulnerability in the Typebot webhook bloc...

2025-11-14
CVE-2025-62156
8.1
Kubernetes Multiple Products

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes

2025-10-14
CVE-2025-61688
Analyzed
8.6
Kubernetes Multiple Products

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud

2025-10-13
CVE-2025-59823
Analyzed
9.9
Kubernetes Multiple Products

Project Gardener implements the automated management and operation of Kubernetes clusters as a service. Code injection may be possible in Gardener Ext...

2025-09-25
CVE-2025-59538
Analyzed
7.5
Kubernetes Multiple Products

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes

2025-10-01
CVE-2025-59537
Analyzed
7.5
Kubernetes Multiple Products

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes

2025-10-01
CVE-2025-59531
Analyzed
7.5
Kubernetes Multiple Products

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes

2025-10-01
CVE-2025-59361
Analyzed
9.8
Kubernetes Multiple Products

The cleanIptables mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthen...

2025-09-15
CVE-2025-59360
Analyzed
9.8
Kubernetes Multiple Products

The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthen...

2025-09-15
CVE-2025-59359
Analyzed
9.8
Kubernetes Multiple Products

The cleanTcs mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthentica...

2025-09-15
CVE-2025-59358
Analyzed
7.5
Kubernetes Multiple Products

The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kubernetes cluster, which provides...

2025-09-15
CVE-2025-55205
Analyzed
9
Kubernetes Multiple Products

Capsule is a multi-tenancy and policy-based framework for Kubernetes. A namespace label injection vulnerability in Capsule v0.10.3 and earlier allows...

2025-08-19
CVE-2025-55190
Analyzed
9.9
Kubernetes Multiple Products

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.0...

2025-09-05
CVE-2025-54469
Analyzed
9.9
Kubernetes Multiple Products

A vulnerability was identified in NeuVector, where the enforcer used environment variables CLUSTER_RPC_PORT and CLUSTER_LAN_PORT to generate a command...

2025-10-30
CVE-2025-53547
8.5
Kubernetes Multiple Products

Helm is a package manager for Charts for Kubernetes

2025-07-08
CVE-2025-53542
Analyzed
7.7
Kubernetes Multiple Products

Headlamp is an extensible Kubernetes web UI

2025-07-11
CVE-2025-41240
Analyzed
10
Kubernetes Multiple Products

Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document ro...

2025-07-25
CVE-2025-14459
Analyzed
8.5
Kubernetes Multiple Products

A flaw was found in KubeVirt Containerized Data Importer (CDI)

2026-01-27
CVE-2024-58259
Analyzed
8.2
Kubernetes Multiple Products

A vulnerability has been identified within Rancher Manager in which it did not enforce request body size limits on certain public (unauthenticated)...

2025-09-02