First CVE: Sep 14, 2017Active for: 9 years
101
CVEs Published
More CVEs Published than 70% of tracked CNAs
10.1
Avg CVEs / Year
More Avg CVEs / Year than 55% of tracked CNAs
6.8
Avg CVSS Score
Higher Avg CVSS Score than 34% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by [email protected] over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 14, 2017
8 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs

All CVEs published by [email protected] as a CNA, regardless of affected vendor or product.

101 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the
Mar 25, 20259.892NOYES
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mirror-host` Ingress annotations can be used to inject
Mar 25, 20258.887NOYES
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafte
Dec 5, 20189.885NOYES
The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's healthz port. This debugging endpo
Aug 29, 20198.272NOYES
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration
Mar 25, 20258.868NOYES
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to inject configuration into ngin
Mar 25, 20258.867NOYES
Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.
Oct 25, 20238.860NONO
Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious
Oct 17, 20197.552NOYES
A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `extensions` API group) can bypass annotati
Aug 16, 20248.843NONO
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject configuration into nginx. This can
Mar 9, 20268.836NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA101 CVEs
Severity distribution among all CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local18 (17.8%)
Network79 (78.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network4 (4.0%)
Attack Complexity
Low83 (82.2%)
High18 (17.8%)
Unknown0 (0.0%)
User Interaction
None88 (87.1%)
Unknown0 (0.0%)
Required13 (12.9%)
Privileges Required
Low59 (58.4%)
High19 (18.8%)
None23 (22.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (101 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
6 CVEs
5.9% of CVEs· 94th percentile
ExploitDB
5 CVEs
5.0% of CVEs· 95th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by [email protected] as a CNA.

Media Mentions

Media articles that mention a CVE ID published by [email protected] as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs