261 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2024-4835
GitLab DevOps Web
8.0
HIGH
EPSS
7.5%
2024 CWE-79 1 PoC

A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information.

CVE-2024-52550
Jenkins Pipeline: Groovy Plugin DevOps
8.0
HIGH
EPSS
1.4%
2024 1 PoC

Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile) script is no longer approved.

CVE-2025-12029
GitLab DevOps
8.0
HIGH
EPSS
0.1%
2025 CWE-79 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have, under certain circumstances, allowed an unauthenticated user to perform unauthorized actions on behalf of another user by injecting malicious external scripts into the Swagger UI."

CVE-2022-24812
grafana DevOps Web
8.0
HIGH
EPSS
0.3%
2022 CWE-269 1 PoC

Grafana is an open-source platform for monitoring and observability. When fine-grained access control is enabled and a client uses Grafana API Key to make requests, the permissions for that API Key are cached for 30 seconds for the given organization. Because of the way the cache ID is constructed, the consequent requests with any API Key evaluate to the same permissions as the previous requests. This can lead to an escalation of privileges, when for example a first request is made with Admin permissions, and the second request with different API Key is made with Viewer permissions, the second

CVE-2026-0752
GitLab DevOps
8.0
HIGH
EPSS
0.1%
2026 CWE-79 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that under certain circumstances, could have allowed an unauthenticated user to inject arbitrary scripts into the Mermaid sandbox UI.

CVE-2021-33183
Synology Docker DevOps
7.9
HIGH
EPSS
0.1%
2021 CWE-22 1 PoC

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability container volume management component in Synology Docker before 18.09.0-0515 allows local users to read or write arbitrary files via unspecified vectors.

CVE-2025-34207
Print Virtual Appliance Host DevOps Networking
7.9
HIGH
EPSS
0.1%
2025 CWE-522 1 PoC

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 22.0.1049 and Application prior to 20.0.2786 (VA and SaaS deployments) configure the SSH client within Docker instances with the following options: `UserKnownHostsFile=/dev/null`, `StrictHostKeyChecking=no`, and `ForwardAgent yes`. These settings disable verification of the remote host’s SSH key and automatically forward the developer’s SSH‑agent to any host that matches the configured wildcard patterns. As a result, an attacker who can reach a single compromised container can cause the container to connect to a malicious S

CVE-2020-10684
Ansible DevOps
7.9
HIGH
EPSS
0.0%
2020 CWE-94 1 PoC

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.

CVE-2023-30998
Security Access Manager Docker DevOps
7.8
HIGH
EPSS
0.1%
2023 CWE-250 2 PoCs

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254649.

CVE-2023-30997
Security Access Manager Docker DevOps
7.8
HIGH
EPSS
0.1%
2023 CWE-250 2 PoCs

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254638.

CVE-2023-3269
kernel DevOps
7.8
HIGH
EPSS
0.2%
2023 CWE-416 3 PoCs

A vulnerability exists in the memory management subsystem of the Linux kernel. The lock handling for accessing and updating virtual memory areas (VMAs) is incorrect, leading to use-after-free problems. This issue can be successfully exploited to execute arbitrary kernel code, escalate containers, and gain root privileges.

CVE-2023-36723
Windows 10 Version 1809 DevOps Windows
7.8
HIGH
EPSS
7.5%
2023 CWE-59 1 PoC

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2023-20065
Cisco IOS XE Software DevOps Web Networking
7.8
HIGH
EPSS
0.2%
2023 CWE-284 1 PoC

A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient restrictions on the hosted application. An attacker could exploit this vulnerability by logging in to and then escaping the Cisco IOx application container. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.

CVE-2024-22029
Container suse/manager/5.0/x86_64/server:5.0.0-beta1.2.122 DevOps Web
7.8
HIGH
EPSS
0.0%
2024 CWE-732 1 PoC

Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root

CVE-2024-35141
Security Verify Access Docker DevOps
7.8
HIGH
EPSS
0.0%
2024 CWE-250 1 PoC

IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges.

CVE-2019-15752
🔥 KEV Software Genérico DevOps
7.8
HIGH
EPSS
49.3%
2019 2 PoCs

Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low-privilege user, and then waiting for an admin or service user to authenticate with Docker, restart Docker, or run 'docker login' to force the command.

CVE-2021-31168
Windows 10 Version 2004 DevOps Windows
7.8
HIGH
EPSS
0.3%
2021 1 PoC

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2021-31169
Windows 10 Version 2004 DevOps Windows
7.8
HIGH
EPSS
0.3%
2021 1 PoC

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2021-31165
Windows 10 Version 2004 DevOps Windows
7.8
HIGH
EPSS
0.3%
2021 1 PoC

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2021-31167
Windows 10 Version 1809 DevOps Windows
7.8
HIGH
EPSS
0.3%
2021 2 PoCs

Windows Container Manager Service Elevation of Privilege Vulnerability