92 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2021-25003
WPCargo Track & Trace DevOps Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
91.6%
2021 CWE-94 2 PoCs

The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE

CVE-2021-28147
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.5%
2021 2 PoCs

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn't supposed to have.

CVE-2021-24751
GenerateBlocks DevOps Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The GenerateBlocks WordPress plugin before 1.4.0 does not validate the generateblocks/container block's tagName attribute, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.

CVE-2021-45414
Software Genérico DevOps
N/A
UNKNOWN
EPSS
2.6%
2021 1 PoC

A Remote Code Execution (RCE) vulnerability exists in DataRobot through 2021-10-28 because it allows submission of a Docker environment or Java driver.

CVE-2021-20208
cifs-utils DevOps Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-266 1 PoC

A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity.

CVE-2021-0339
Android DevOps
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In loadAnimation of WindowContainer.java, there is a possible way to keep displaying a malicious app while a target app is brought to the foreground. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-8.1 Android-9Android ID: A-145728687

CVE-2021-45482
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In WebKitGTK before 2.32.4, there is a use-after-free in WebCore::ContainerNode::firstChild, a different vulnerability than CVE-2021-30889.

CVE-2021-33923
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

Insecure permissions in Confluent Ansible (cp-ansible) 5.5.0, 5.5.1, 5.5.2 and 6.0.0 allows local attackers to access some sensitive information (private keys, state database).

CVE-2021-27886
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
22.4%
2021 1 PoC

rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request. NOTE: this is NOT a Docker, Inc. product.

CVE-2021-0595
Android DevOps
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profile PIN, after logging in. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-177457096

CVE-2021-37573
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
51.9%
2021 3 PoCs

A reflected cross-site scripting (XSS) vulnerability in the web server TTiny Java Web Server and Servlet Container (TJWS) <=1.115 allows an adversary to inject malicious code on the server's "404 Page not Found" error page

CVE-2021-21660
Jenkins Markdown Formatter Plugin DevOps Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Jenkins Markdown Formatter Plugin 0.1.0 and earlier does not sanitize crafted link target URLs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to edit any description rendered using the configured markup formatter.