First CVE: Sep 14, 2017Active for: 9 years
101
CVEs Published
More CVEs Published than 70% of tracked CNAs
10.1
Avg CVEs / Year
More Avg CVEs / Year than 55% of tracked CNAs
6.8
Avg CVSS Score
Higher Avg CVSS Score than 34% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by [email protected] over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 14, 2017
8 years ago
Most Recent CVE
Jul 23, 2026
1 day ago
Top CVEs
All CVEs published by [email protected] as a CNA, regardless of affected vendor or product.
101 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-1974CRITICAL A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the | Mar 25, 2025 | 9.8 | 92 | NO | YES |
CVE-2025-1098HIGH A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mirror-host` Ingress annotations can be used to inject | Mar 25, 2025 | 8.8 | 87 | NO | YES |
CVE-2018-1002105CRITICAL In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafte | Dec 5, 2018 | 9.8 | 85 | NO | YES |
CVE-2019-11248HIGH The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's healthz port. This debugging endpo | Aug 29, 2019 | 8.2 | 72 | NO | YES |
CVE-2025-1097HIGH A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration | Mar 25, 2025 | 8.8 | 68 | NO | YES |
CVE-2025-24514HIGH A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to inject configuration into ngin | Mar 25, 2025 | 8.8 | 67 | NO | YES |
CVE-2023-5044HIGH Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation. | Oct 25, 2023 | 8.8 | 60 | NO | NO |
CVE-2019-11253HIGH Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious | Oct 17, 2019 | 7.5 | 52 | NO | YES |
CVE-2024-7646HIGH A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `extensions` API group) can bypass annotati | Aug 16, 2024 | 8.8 | 43 | NO | NO |
CVE-2026-3288HIGH A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject configuration into nginx. This can | Mar 9, 2026 | 8.8 | 36 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA101 CVEs
9%
50%
35%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local18 (17.8%)
Network79 (78.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network4 (4.0%)
Attack Complexity
Low83 (82.2%)
High18 (17.8%)
Unknown0 (0.0%)
User Interaction
None88 (87.1%)
Unknown0 (0.0%)
Required13 (12.9%)
Privileges Required
Low59 (58.4%)
High19 (18.8%)
None23 (22.8%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (101 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
6 CVEs
5.9% of CVEs· 94th percentile
ExploitDB
5 CVEs
5.0% of CVEs· 95th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by [email protected] as a CNA.
Media Mentions
Media articles that mention a CVE ID published by [email protected] as a CNA — matched by CVE ID, not by organization name.