1018 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2021-20166
Netgear RAX43 DevOps Networking
N/A
UNKNOWN
EPSS
64.2%
2021 1 PoC

Netgear RAX43 version 1.0.3.96 contains a buffer overrun vulnerability. The URL parsing functionality in the cgi-bin endpoint of the router containers a buffer overrun issue that can redirection control flow of the applicaiton.

CVE-2018-20498
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2018 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

CVE-2018-8469
Microsoft Edge DevOps
N/A
UNKNOWN
EPSS
20.3%
2018 1 PoC

An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8463.

CVE-2018-19575
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2018 1 PoC

GitLab CE/EE, versions 10.1 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an insecure direct object reference issue that allows a user to make comments on a locked issue.

CVE-2013-4580
Software Genérico DevOps Web Database
N/A
UNKNOWN
EPSS
0.1%
2013 1 PoC

GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impersonate arbitrary users and bypass authentication via unspecified API calls.

CVE-2015-3631
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2015 1 PoC

Docker Engine before 1.6.1 allows local users to set arbitrary Linux Security Modules (LSM) and docker_t policies via an image that allows volumes to override files in /proc.

CVE-2018-19570
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.1%
2018 1 PoC

GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via unrecognized HTML tags.

CVE-2021-27358
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.0%
2021 0 PoCs

The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.

CVE-2018-15514
Software Genérico DevOps Windows
N/A
UNKNOWN
EPSS
3.2%
2018 2 PoCs

HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests over the \\.\pipe\dockerBackend named pipe without verifying the validity of the deserialized .NET objects. This would allow a malicious user in the "docker-users" group (who may not otherwise have administrator access) to escalate to administrator privileges.

CVE-2018-19359
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.3%
2018 1 PoC

GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.

CVE-2018-18640
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2018 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Information Exposure Through Browser Caching.

CVE-2018-1000195
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.7%
2018 1 PoC

A server-side request forgery vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in ZipExtractionInstaller.java that allows users with Overall/Read permission to have Jenkins submit a HTTP GET request to an arbitrary URL and learn whether the response is successful (200) or not.

CVE-2018-19571
Software Genérico DevOps
N/A
UNKNOWN
EPSS
32.2%
2018 2 PoCs

GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhooks.

CVE-2018-1999007
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.2%
2018 1 PoC

A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers with the ability to control the existence of some URLs in Jenkins to define JavaScript that would be executed in another user's browser when that other user views HTTP 404 error pages while Stapler debug mode is enabled.

CVE-2018-18644
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2018 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows Information Exposure via a Gitlab Prometheus integration.

CVE-2023-40344
Jenkins Delphix Plugin DevOps
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A missing permission check in Jenkins Delphix Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

CVE-2018-12545
Eclipse Jetty DevOps
N/A
UNKNOWN
EPSS
3.5%
2018 CWE-400 2 PoCs

In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to the additional CPU and memory allocations required to handle changed settings.

CVE-2018-18264
Software Genérico DevOps ⚡ nuclei
N/A
UNKNOWN
EPSS
90.8%
2018 0 PoCs

Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster.

CVE-2018-18548
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
2.2%
2018 2 PoCs

ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in File Manager.

CVE-2018-6356
Software Genérico DevOps Windows
N/A
UNKNOWN
EPSS
31.6%
2018 1 PoC

Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files. This allowed users with Overall/Read permission to download files from the Jenkins master they should not have access to. On Windows, any file accessible to the Jenkins master process could be downloaded. On other operating systems, any file within the Jenkins home directory accessible to the Jenkins master process could be downloaded.