Browse vulnerabilities
173 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2023-44487 | Act now | 100.0% | 7.5 | ● | The HTTP/2 protocol allows a denial of service (server resource consumption) because reque… |
| CVE-2026-44181 | High | 0.8% | 10.0 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clu… | |
| CVE-2026-44180 | High | 0.7% | 9.8 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clu… | |
| CVE-2026-22872 | High | 0.7% | 9.1 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controll… | |
| CVE-2026-44182 | High | 0.6% | 10.0 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clu… | |
| CVE-2026-44881 | High | 0.6% | 9.9 | Portainer Community Edition is a lightweight service delivery platform for containerized a… | |
| CVE-2026-42880 | High | 0.6% | 9.6 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.… | |
| CVE-2026-54526 | High | 0.6% | 9.9 | Argo Workflows is an open source container-native workflow engine for orchestrating parall… | |
| CVE-2026-85594 | High | 0.5% | 9.8 | Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the t… | |
| CVE-2026-85596 | High | 0.4% | 9.8 | Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernet… | |
| CVE-2026-66297 | Medium | 2.4% | 8.0 | Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) v… | |
| CVE-2024-21400 | Medium | 2.2% | 9.0 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerabi… | |
| CVE-2024-21403 | Medium | 1.3% | 9.0 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerabi… | |
| CVE-2024-5154 | Medium | 1.2% | 8.1 | A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary f… | |
| CVE-2024-21376 | Medium | 1.2% | 9.0 | Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerabil… | |
| CVE-2026-44495 | Medium | 1.0% | 7.0 | Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.… | |
| CVE-2026-33105 | Medium | 0.9% | 10.0 | Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attack… | |
| CVE-2026-56163 | Medium | 0.9% | 10.0 | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows … | |
| CVE-2026-18951 | Medium | 0.9% | 8.8 | A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. Th… | |
| CVE-2026-73667 | Medium | 0.9% | 8.8 | OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1… | |
| CVE-2026-80352 | Medium | 0.8% | 9.8 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K.… | |
| CVE-2026-50516 | Medium | 0.8% | 9.4 | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows … | |
| CVE-2026-66793 | Medium | 0.8% | 8.8 | A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced C… | |
| CVE-2026-49298 | Medium | 0.8% | 8.8 | A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to auth… | |
| CVE-2026-73841 | Medium | 0.8% | 8.8 | OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.1.6 an… | |
| CVE-2026-18982 | Medium | 0.8% | 8.8 | A flaw was found in the RHOAI training-operator. This vulnerability allows a user with sta… | |
| CVE-2026-54680 | Medium | 0.8% | 9.9 | Logging operator automates the deployment and configuration of Kubernetes logging pipeline… | |
| CVE-2026-42294 | Medium | 0.7% | 7.5 | Argo Workflows is an open source container-native workflow engine for orchestrating parall… | |
| CVE-2026-34045 | Medium | 0.7% | 8.2 | Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1… | |
| CVE-2026-18608 | Medium | 0.7% | 8.7 | A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole… | |
| CVE-2026-14450 | Medium | 0.7% | 9.9 | A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to … | |
| CVE-2026-73666 | Medium | 0.7% | 8.2 | OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the O… | |
| CVE-2026-67309 | Medium | 0.7% | 7.5 | Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kub… | |
| CVE-2026-92574 | Medium | 0.7% | 8.8 | A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a mali… | |
| CVE-2026-73263 | Medium | 0.7% | 9.9 | Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection … | |
| CVE-2026-88877 | Medium | 0.6% | 9.8 | Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, t… | |
| CVE-2026-10059 | Medium | 0.6% | 9.1 | A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A te… | |
| CVE-2026-54745 | Medium | 0.6% | 10.0 | Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning w… | |
| CVE-2026-66794 | Medium | 0.6% | 9.3 | A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kuberne… | |
| CVE-2026-10090 | Medium | 0.6% | 9.0 | A flaw was found in the Application Subscription controller (multicluster-operators-subscr… | |
| CVE-2026-59762 | Medium | 0.6% | 7.5 | When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause a… | |
| CVE-2026-17107 | Medium | 0.6% | 8.5 | A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Clu… | |
| CVE-2024-53095 | Medium | 0.6% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-… | |
| CVE-2026-9165 | Medium | 0.5% | 7.7 | A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does… | |
| CVE-2026-39429 | Medium | 0.5% | 8.2 | kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes an… | |
| CVE-2026-62440 | Medium | 0.5% | 9.1 | Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plug… | |
| CVE-2026-52831 | Medium | 0.5% | 8.0 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to vers… | |
| CVE-2026-55848 | Medium | 0.5% | 8.6 | mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to… | |
| CVE-2026-15378 | Medium | 0.5% | 9.3 | A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remo… | |
| CVE-2026-42297 | Medium | 0.5% | 8.3 | Argo Workflows is an open source container-native workflow engine for orchestrating parall… |
Page 1 of 4
Next →