1018 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2025-27410
pwndoc DevOps
6.5
MEDIUM
EPSS
16.5%
2025 CWE-23 1 PoC

PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality is vulnerable to path traversal in the TAR entry's name, allowing an attacker to overwrite any file on the system with their content. By overwriting an included `.js` file and restarting the container, this allows for Remote Code Execution as an administrator. The remote code execution occurs because any user with the `backups:create` and `backups:update` (only administrators by default) is able to overwrite any file on the system. Version 1.2.0 fixes the issue.

CVE-2020-35557
Software Genérico DevOps
6.5
MEDIUM
EPSS
0.3%
2020 1 PoC

An issue in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 allows a logged in user to see devices in the account he should not have access to due to improper use of access validation.

CVE-2024-55963
Software Genérico DevOps Web
6.5
MEDIUM
EPSS
37.2%
2024 1 PoC

An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on Appsmith, causing a server restart. This is still within the Appsmith container, and the impact is limited to Appsmith's own server only, but there is a denial of service because it can be continually restarted. This is due to incorrect access control checks, which should check for super user permissions on the incoming request.

CVE-2024-3959
GitLab DevOps
6.5
MEDIUM
EPSS
0.0%
2024 CWE-285 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows private job artifacts can be accessed by any user.

CVE-2019-11248
Kubernetes DevOps ⚡ nuclei
6.5
MEDIUM
EPSS
91.0%
2019 CWE-419 1 PoC

The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's healthz port. This debugging endpoint can potentially leak sensitive information such as internal Kubelet memory addresses and configuration, or for limited denial of service. Versions prior to 1.15.0, 1.14.4, 1.13.8, and 1.12.10 are affected. The issue is of medium severity, but not exposed by the default configuration.

CVE-2026-1458
GitLab DevOps
6.5
MEDIUM
EPSS
0.0%
2026 CWE-770 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an unauthenticated user to cause denial of service by uploading malicious files.

CVE-2024-1963
GitLab DevOps
6.5
MEDIUM
EPSS
0.2%
2024 CWE-1333 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.4 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. A vulnerability in GitLab's Asana integration allowed an attacker to potentially cause a regular expression denial of service by sending specially crafted requests.

CVE-2022-1185
GitLab DevOps
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and 14.9.0 to 14.9.2 allows an attacker to crash the GitLab web application with a maliciously crafted RDoc file

CVE-2020-13324
GitLab DevOps Web
6.5
MEDIUM
EPSS
0.1%
2020 1 PoC

A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the private activity of a user could be exposed via the API.

CVE-2020-13351
GitLab CE/EE DevOps Web
6.5
MEDIUM
EPSS
0.3%
2020 2 PoCs

Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on projects visible to the attacker. Affected versions are >=13.0, <13.3.9,>=13.4.0, <13.4.5,>=13.5.0, <13.5.2.

CVE-2024-41454
Software Genérico DevOps Web
6.5
MEDIUM
EPSS
0.6%
2024 2 PoCs

An arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitrary code via uploading a crafted PHP or HTML file.

CVE-2026-1456
GitLab DevOps
6.5
MEDIUM
EPSS
0.0%
2026 CWE-770 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through CPU exhaustion by submitting specially crafted markdown files that trigger exponential processing in markdown preview.

CVE-2024-4210
GitLab DevOps
6.5
MEDIUM
EPSS
0.1%
2024 CWE-400 1 PoC

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 12.6 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause a denial of service using crafted adoc files.

CVE-2024-10219
GitLab DevOps Web
6.5
MEDIUM
EPSS
0.0%
2024 CWE-863 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users to bypass access controls and download private artifacts by accessing specific API endpoints.

CVE-2023-2069
GitLab DevOps
6.4
MEDIUM
EPSS
0.5%
2023 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD variables.

CVE-2019-10206
Ansible DevOps
6.4
MEDIUM
EPSS
0.3%
2019 CWE-522 1 PoC

ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.

CVE-2022-2326
GitLab DevOps
6.4
MEDIUM
EPSS
0.2%
2022 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible to gain access to a private project through an email invite by using other user's email address as an unverified secondary email.

CVE-2022-4138
GitLab DevOps
6.4
MEDIUM
EPSS
0.2%
2022 1 PoC

A Cross Site Request Forgery issue has been discovered in GitLab CE/EE affecting all versions before 15.6.7, all versions starting from 15.7 before 15.7.6, and all versions starting from 15.8 before 15.8.1. An attacker could take over a project if an Owner or Maintainer uploads a file to a malicious project.

CVE-2024-9387
GitLab DevOps Web
6.4
MEDIUM
EPSS
0.1%
2024 CWE-601 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could potentially perform an open redirect against a given releases API endpoint.

CVE-2020-8559
Kubernetes DevOps Web
6.4
MEDIUM
EPSS
51.2%
2020 CWE-601 3 PoCs

The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.