Browse vulnerabilities
173 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-65601 | Medium | 0.5% | 8.8 | Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Ku… | |
| CVE-2026-55765 | Medium | 0.5% | 8.5 | CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes envi… | |
| CVE-2026-77180 | Medium | 0.5% | 8.3 | When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnera… | |
| CVE-2026-42296 | Medium | 0.5% | 8.1 | Argo Workflows is an open source container-native workflow engine for orchestrating parall… | |
| CVE-2025-2241 | Medium | 0.5% | 8.2 | A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Ma… | |
| CVE-2026-73843 | Medium | 0.5% | 9.6 | OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 an… | |
| CVE-2026-71327 | Medium | 0.5% | 8.1 | Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 an… | |
| CVE-2026-44882 | Medium | 0.5% | 8.1 | Portainer Community Edition is a lightweight service delivery platform for containerized a… | |
| CVE-2026-8715 | Medium | 0.5% | 9.6 | Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and crede… | |
| CVE-2026-47701 | Medium | 0.5% | 7.7 | The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior… | |
| CVE-2025-22021 | Medium | 0.5% | 10.0 | In the Linux kernel, the following vulnerability has been resolved: netfilter: socket: Lo… | |
| CVE-2026-44883 | Medium | 0.5% | 7.5 | Portainer Community Edition is a lightweight service delivery platform for containerized a… | |
| CVE-2026-16745 | Medium | 0.5% | 8.8 | A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOA… | |
| CVE-2026-54725 | Medium | 0.4% | 9.6 | vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection … | |
| CVE-2026-44848 | Medium | 0.4% | 8.8 | Portainer Community Edition is a lightweight service delivery platform for containerized a… | |
| CVE-2026-44849 | Medium | 0.4% | 8.8 | Portainer Community Edition is a lightweight service delivery platform for containerized a… | |
| CVE-2026-85781 | Medium | 0.4% | 8.7 | Unverified ownership of a storage access point in the volume deletion component of the Ama… | |
| CVE-2026-15416 | Medium | 0.4% | 8.9 | A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that… | |
| CVE-2026-53713 | Medium | 0.4% | 9.1 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubern… | |
| CVE-2026-60402 | Medium | 0.4% | 9.9 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Data… | |
| CVE-2026-47237 | Medium | 0.4% | 8.0 | Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubern… | |
| CVE-2026-45760 | Medium | 0.4% | 8.1 | (Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass T… | |
| CVE-2026-61682 | Medium | 0.4% | 9.9 | kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes an… | |
| CVE-2026-75889 | Medium | 0.4% | 7.7 | Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create… | |
| CVE-2026-32193 | Medium | 0.4% | 8.8 | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsof… | |
| CVE-2026-62246 | Medium | 0.4% | 8.5 | Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji de… | |
| CVE-2026-11769 | Medium | 0.4% | 8.8 | We have released version 5.24.0 of the Grafana Operator. This patch includes a MEDIUM seve… | |
| CVE-2026-12564 | Medium | 0.3% | 9.6 | A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes… | |
| CVE-2026-53714 | Medium | 0.3% | 7.4 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubern… | |
| CVE-2026-61672 | Medium | 0.3% | 7.1 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, For… | |
| CVE-2026-65602 | Medium | 0.3% | 8.8 | Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderName… | |
| CVE-2025-2843 | Medium | 0.3% | 8.8 | A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with… | |
| CVE-2026-18381 | Medium | 0.3% | 7.6 | A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostMa… | |
| CVE-2026-44850 | Medium | 0.3% | 8.5 | Portainer Community Edition is a lightweight service delivery platform for containerized a… | |
| CVE-2026-49478 | Medium | 0.3% | 8.7 | Fulcio is a certificate authority for issuing code signing certificates for an OpenID Conn… | |
| CVE-2026-13201 | Medium | 0.3% | 7.3 | A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow f… | |
| CVE-2026-73842 | Medium | 0.3% | 9.0 | OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1… | |
| CVE-2026-19274 | Medium | 0.2% | 9.6 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Ope… | |
| CVE-2026-27173 | Medium | 0.2% | 8.7 | JWT tokens that were used by workers in Kubernetes Executors have been exposed to users wh… | |
| CVE-2026-10079 | Medium | 0.2% | 8.5 | A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When process… | |
| CVE-2026-4740 | Medium | 0.2% | 8.2 | A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advan… | |
| CVE-2026-71474 | Medium | 0.2% | 7.1 | A flaw was found in insights-client. When the application receives a non-200 response, it … | |
| CVE-2026-45726 | Medium | 0.1% | 7.6 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1… | |
| CVE-2026-62290 | Medium | 0.1% | 7.3 | cert-manager adds certificates and certificate issuers as resource types in Kubernetes clu… | |
| CVE-2021-27075 | Low | 1.4% | 6.8 | Azure Virtual Machine Information Disclosure Vulnerability | |
| CVE-2026-73298 | Low | 1.0% | — | The Microsoft Container Migration Solution Accelerator is a multi-service application that… | |
| CVE-2026-44885 | Low | 0.8% | 5.5 | Portainer Community Edition is a lightweight service delivery platform for containerized a… | |
| CVE-2026-55769 | Low | 0.8% | — | CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes envi… | |
| CVE-2026-53716 | Low | 0.7% | 6.5 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubern… | |
| CVE-2026-53717 | Low | 0.7% | 6.5 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubern… |