1018 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2024-22029
Container suse/manager/5.0/x86_64/server:5.0.0-beta1.2.122 DevOps Web
7.8
HIGH
EPSS
0.0%
2024 CWE-732 1 PoC

Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root

CVE-2022-2002
CIMPLICITY DevOps
7.8
HIGH
EPSS
0.1%
2022 CWE-822 1 PoC

GE CIMPICITY versions 2022 and prior is vulnerable when data from faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, which could allow an attacker to execute arbitrary code.

CVE-2022-25365
Software Genérico DevOps Windows
7.8
HIGH
EPSS
1.2%
2022 1 PoC

Docker Desktop before 4.5.1 on Windows allows attackers to move arbitrary files. NOTE: this issue exists because of an incomplete fix for CVE-2022-23774.

CVE-2022-30164
Windows 10 Version 1809 DevOps Windows
7.8
HIGH
EPSS
0.9%
2022 1 PoC

Kerberos AppContainer Security Feature Bypass Vulnerability

CVE-2021-31168
Windows 10 Version 2004 DevOps Windows
7.8
HIGH
EPSS
0.3%
2021 1 PoC

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2019-15752
🔥 KEV Software Genérico DevOps
7.8
HIGH
EPSS
49.3%
2019 2 PoCs

Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low-privilege user, and then waiting for an admin or service user to authenticate with Docker, restart Docker, or run 'docker login' to force the command.

CVE-2020-2026
Kata Containers DevOps
7.8
HIGH
EPSS
0.3%
2020 CWE-59 1 PoC

A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesystem on any host path, potentially allowing for code execution on the host. This issue affects: Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than 1.10.5; Kata Containers 1.9 and earlier versions.

CVE-2023-49096
jellyfin DevOps
7.7
HIGH
EPSS
1.4%
2023 CWE-88 1 PoC

Jellyfin is a Free Software Media System for managing and streaming media. In affected versions there is an argument injection in the VideosController, specifically the `/Videos/<itemId>/stream` and `/Videos/<itemId>/stream.<container>` endpoints which are present in the current Jellyfin version. Additional endpoints in the AudioController might also be vulnerable, as they differ only slightly in execution. Those endpoints are reachable by an unauthenticated user. In order to exploit this vulnerability an unauthenticated attacker has to guess an itemId, which is a completely random GUID. It’s

CVE-2026-30824
Flowise DevOps Web Networking ⚡ nuclei
7.7
HIGH
EPSS
9.4%
2026 CWE-306 0 PoCs

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NVIDIA NIM router (/api/v1/nvidia-nim/*) is whitelisted in the global authentication middleware, allowing unauthenticated access to privileged container management and token generation endpoints. This issue has been patched in version 3.0.13.

CVE-2025-1908
GitLab DevOps
7.7
HIGH
EPSS
0.1%
2025 CWE-840 1 PoC

An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVE-2024-9183
GitLab DevOps
7.7
HIGH
EPSS
0.0%
2024 CWE-367 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that could have allowed an authenticated user to obtain credentials from higher-privileged users and perform actions in their context under specific conditions.

CVE-2021-39877
GitLab DevOps
7.7
HIGH
EPSS
0.2%
2021 1 PoC

A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.

CVE-2022-0427
GitLab DevOps Web
7.7
HIGH
EPSS
0.1%
2022 1 PoC

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

CVE-2022-1940
GitLab DevOps Web
7.7
HIGH
EPSS
0.2%
2022 1 PoC

A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues

CVE-2024-35140
Security Verify Access Docker DevOps
7.7
HIGH
EPSS
0.0%
2024 CWE-295 1 PoC

IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to improper certificate validation. IBM X-Force ID: 292416.

CVE-2025-4123
Grafana DevOps Web ⚡ nuclei
7.6
HIGH
EPSS
5.3%
2025 CWE-79 10 PoCs

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVE-2023-5044
ingress-nginx DevOps Web
7.6
HIGH
EPSS
10.6%
2023 CWE-20 3 PoCs

Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.

CVE-2023-26031
Apache Hadoop DevOps Web
7.5
HIGH
EPSS
9.3%
2023 CWE-426 3 PoCs

Relative library resolution in linux container-executor binary in Apache Hadoop 3.3.1-3.3.4 on Linux allows local user to gain root privileges. If the YARN cluster is accepting work from remote (authenticated) users, this MAY permit remote users to gain root privileges. Hadoop 3.3.0 updated the " YARN Secure Containers https://hadoop.apache.org/docs/stable/hadoop-yarn/hadoop-yarn-site/SecureContainer.html " to add a feature for executing user-submitted applications in isolated linux containers. The native binary HADOOP_HOME/bin/container-executor is used to launch these containers; it must b

CVE-2020-35558
Software Genérico DevOps Database
7.5
HIGH
EPSS
0.3%
2020 1 PoC

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. There is an SSRF in the in the MySQL access check, allowing an attacker to scan for open ports and gain some information about possible credentials.

CVE-2020-13270
GitLab DevOps Web
7.5
HIGH
EPSS
0.4%
2020 1 PoC

Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API