CVE-2023-5043 Kubernetes Official CVE Feed 1 year 9 months ago Ingress nginx annotation injection causes arbitrary command execution
CVE-2022-4886 Kubernetes Official CVE Feed 1 year 9 months ago ingress-nginx path sanitization can be bypassed
CVE-2023-3955 Kubernetes Official CVE Feed 2 years ago Insufficient input sanitization on Windows nodes leads to privilege escalation
CVE-2023-3893 Kubernetes Official CVE Feed 2 years ago Insufficient input sanitization on kubernetes-csi-proxy leads to privilege escalation
CVE-2023-3676 Kubernetes Official CVE Feed 2 years ago Insufficient input sanitization on Windows nodes leads to privilege escalation
CVE-2023-2727 Kubernetes Official CVE Feed 2 years 1 month ago Bypassing policies imposed by the ImagePolicyWebhook and bypassing mountable secrets policy imposed by the ServiceAccount admission plugin
CVE-2023-2728 Kubernetes Official CVE Feed 2 years 1 month ago Bypassing policies imposed by the ImagePolicyWebhook and bypassing mountable secrets policy imposed by the ServiceAccount admission plugin
CVE-2023-2878 Kubernetes Official CVE Feed 2 years 2 months ago secrets-store-csi-driver discloses service account tokens in logs
CVE-2022-3294 Kubernetes Official CVE Feed 2 years 8 months ago Node address isn't always verified when proxying
CVE-2022-3162 Kubernetes Official CVE Feed 2 years 8 months ago Unauthorized read of Custom Resources
CVE-2022-3172 Kubernetes Official CVE Feed 2 years 10 months ago Aggregated API server can cause clients to be redirected (SSRF)
CVE-2021-25749 Kubernetes Official CVE Feed 2 years 11 months ago `runAsNonRoot` logic bypass for Windows containers
CVE-2021-25748 Kubernetes Official CVE Feed 3 years 1 month ago Ingress-nginx `path` sanitization can be bypassed with newline character
CVE-2021-25746 Kubernetes Official CVE Feed 3 years 3 months ago Ingress-nginx directive injection via annotations
CVE-2021-25745 Kubernetes Official CVE Feed 3 years 3 months ago Ingress-nginx `path` can be pointed to service account token file
CVE-2021-25742 Kubernetes Official CVE Feed 3 years 9 months ago Ingress-nginx custom snippets allows retrieval of ingress-nginx serviceaccount token and secrets across all namespaces
CVE-2021-25741 Kubernetes Official CVE Feed 3 years 10 months ago Symlink Exchange Can Allow Host Filesystem Access
CVE-2021-25737 Kubernetes Official CVE Feed 4 years 2 months ago Holes in EndpointSlice Validation Enable Host Network Hijack
CVE-2021-3121 Kubernetes Official CVE Feed 4 years 3 months ago Processes may panic upon receipt of malicious protobuf messages