1018 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2013-5573
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
1.6%
2013 4 PoCs

Cross-site scripting (XSS) vulnerability in the default markup formatter in Jenkins 1.523 allows remote attackers to inject arbitrary web script or HTML via the Description field in the user configuration.

CVE-2022-23126
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
1.0%
2022 1 PoC

TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles, start Keyless Driving, and interfere with vehicle operation en route. This occurs because an attacker can leverage Grafana login access to obtain a token for Tesla API calls.

CVE-2021-24751
GenerateBlocks DevOps Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The GenerateBlocks WordPress plugin before 1.4.0 does not validate the generateblocks/container block's tagName attribute, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.

CVE-2022-2260
GiveWP – Donation Plugin and Fundraising Platform DevOps Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-352 1 PoC

The GiveWP WordPress plugin before 2.21.3 does not have CSRF in place when exporting data, and does not validate the exporting parameters such as dates, which could allow attackers to make a logged in admin DoS the web server via a CSRF attack as the plugin will try to retrieve data from the database many times which leads to overwhelm the target's CPU.

CVE-2022-34960
Software Genérico DevOps Networking
N/A
UNKNOWN
EPSS
0.5%
2022 2 PoCs

The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic links, which resolve to locations on the host device. This allows the attacker to mount any arbitrary file to any location on the host.

CVE-2022-1435
WPCargo Track & Trace DevOps Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitize and escapes some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2022-24331
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.

CVE-2022-1436
WPCargo Track & Trace DevOps Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitise and escape the wpcargo_tracking_number parameter before outputting it back in the page, which could allow attackers to perform reflected Cross-Site Scripting attacks.

CVE-2022-25175
Jenkins Pipeline: Multibranch Plugin DevOps Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses the same checkout directories for distinct SCMs for the readTrusted step, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.

CVE-2021-45414
Software Genérico DevOps
N/A
UNKNOWN
EPSS
2.6%
2021 1 PoC

A Remote Code Execution (RCE) vulnerability exists in DataRobot through 2021-10-28 because it allows submission of a Docker environment or Java driver.

CVE-2021-20208
cifs-utils DevOps Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-266 1 PoC

A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity.

CVE-2022-26148
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.2%
2022 0 PoCs

An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.

CVE-2021-0339
Android DevOps
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In loadAnimation of WindowContainer.java, there is a possible way to keep displaying a malicious app while a target app is brought to the foreground. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-8.1 Android-9Android ID: A-145728687

CVE-2022-20617
Jenkins Docker Commons Plugin DevOps
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability exploitable by attackers with Item/Configure permission or able to control the contents of a previously configured job's SCM repository.

CVE-2013-4583
GitLab DevOps
N/A
UNKNOWN
EPSS
0.3%
2013 1 PoC

The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to gain privileges and clone arbitrary repositories.

CVE-2021-45482
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In WebKitGTK before 2.32.4, there is a use-after-free in WebCore::ContainerNode::firstChild, a different vulnerability than CVE-2021-30889.

CVE-2022-24348
Software Genérico DevOps
N/A
UNKNOWN
EPSS
3.9%
2022 1 PoC

Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related to Helm charts because of an error in helmTemplate in repository.go. For example, an attacker may be able to discover credentials stored in a YAML file.

CVE-2021-33923
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

Insecure permissions in Confluent Ansible (cp-ansible) 5.5.0, 5.5.1, 5.5.2 and 6.0.0 allows local attackers to access some sensitive information (private keys, state database).

CVE-2021-27886
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
22.4%
2021 1 PoC

rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request. NOTE: this is NOT a Docker, Inc. product.

CVE-2022-20007
Android DevOps
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In startActivityForAttachedApplicationIfNeeded of RootWindowContainer.java, there is a possible way to overlay an app that believes it's still in the foreground, when it is not, due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-211481342