Every published CVE from the last 120 days with CVSS score, vendor and product, cross-referenced against CISA's Known Exploited Vulnerabilities catalog. 10 added to KEV in the last 7 days.
| CVE | CVSS | Severity | Vendor / product | Summary | Published |
|---|---|---|---|---|---|
| CVE-2026-65602 | 8.8 | high | traefik / traefik | Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for Ing | 45d ago |
| CVE-2026-65601 | 8.8 | high | traefik / traefik | Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API pro | 45d ago |
| CVE-2026-54762 | 8.6 | high | traefik / traefik | Traefik is an HTTP reverse proxy and load balancer. | 74d ago |
| CVE-2026-54765 | 8.5 | high | traefik / traefik | Traefik is an open source HTTP reverse proxy and load balancer. | 61d ago |
| CVE-2023-54365 | 7.5 | high | traefik / traefik | Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling | 74d ago |
| CVE-2026-54761 | 7.1 | high | traefik / traefik | Traefik is an HTTP reverse proxy and load balancer. | 74d ago |
Sources: NIST National Vulnerability Database (descriptions, CVSS, CPE) and CISA Known Exploited Vulnerabilities catalog (exploitation status). Both are United States government works in the public domain. Data refreshes daily; KEV hourly.