Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Kubernetes

Kubernetesоткрытое программное обеспечение для оркестровки контейнеризированных приложений — автоматизации их развёртывания, масштабирования и координации в условиях кластера.

Релизный цикл, информация об уязвимостях

Продукт: Kubernetes
Вендор: kubernetes

График релизов

1.341.351.362025202620272028

Недавние уязвимости Kubernetes

Количество 335

github логотип

GHSA-j3v3-cjmx-765g

23 дня назад

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-6rrr-4jqj-5947

23 дня назад

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-13020

23 дня назад

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-13019

23 дня назад

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-rvfx-c797-vvhx

3 месяца назад

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-33519

3 месяца назад

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-qv83-wx6q-j989

6 месяцев назад

A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secrets.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2026-22549

6 месяцев назад

A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secrets.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.9
EPSS: Низкий
fstec логотип

BDU:2026-03571

8 месяцев назад

Уязвимость программного средства управления кластерами виртуальных машин Kubernetes, связанная с недостаточной проверкой поступающих запросов, позволяющая нарушителю осуществить ssrf-атаку

CVSS3: 5.8
EPSS: Низкий
fstec логотип

BDU:2025-13412

9 месяцев назад

Уязвимость сервера ArcGIS Server, связанная с непринятием мер по защите структуры запроса SQL, позволяющая нарушителю выполнить произвольные SQL-команды

CVSS3: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-j3v3-cjmx-765g

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.

CVSS3: 8.1
0%
Низкий
23 дня назад
github логотип
GHSA-6rrr-4jqj-5947

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.

CVSS3: 9.8
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-13020

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.

CVSS3: 8.1
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-13019

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.

CVSS3: 9.8
0%
Низкий
23 дня назад
github логотип
GHSA-rvfx-c797-vvhx

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.

CVSS3: 9.8
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-33519

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.

CVSS3: 9.8
0%
Низкий
3 месяца назад
github логотип
GHSA-qv83-wx6q-j989

A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secrets.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.9
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-22549

A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secrets.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.9
0%
Низкий
6 месяцев назад
fstec логотип
BDU:2026-03571

Уязвимость программного средства управления кластерами виртуальных машин Kubernetes, связанная с недостаточной проверкой поступающих запросов, позволяющая нарушителю осуществить ssrf-атаку

CVSS3: 5.8
0%
Низкий
8 месяцев назад
fstec логотип
BDU:2025-13412

Уязвимость сервера ArcGIS Server, связанная с непринятием мер по защите структуры запроса SQL, позволяющая нарушителю выполнить произвольные SQL-команды

CVSS3: 10
1%
Низкий
9 месяцев назад

Уязвимостей на страницу


Поделиться