- How many CVEs does kubernetes have?
- kubernetes has 135 published CVE records since 2015, including 29 in the last two years.
- How many kubernetes CVEs are in CISA KEV?
- Yes — 1 of kubernetes's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
- Which kubernetes products have the most CVEs?
- The kubernetes products with the most published CVEs are Kubernetes, ingress-nginx, cri-o, github.com/kubernetes/kubernetes, kubelet.
- What are the most common weakness types in kubernetes CVEs?
- kubernetes's CVEs most often map to these CWE weakness types: CWE-20 (Improper Input Validation), CWE-532 (Insertion of Sensitive Information into Log File), CWE-400 (Uncontrolled Resource Consumption), CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')).
- Are there public exploits for kubernetes vulnerabilities?
- Yes — 22 of kubernetes's CVEs have a known public exploit.
- How many critical kubernetes vulnerabilities are there?
- kubernetes has 13 critical and 52 high-severity CVEs.
- What is the average severity of kubernetes CVEs?
- The average CVSS base score across kubernetes's scored CVEs is 7.0.