1018 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2022-24331
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.

CVE-2022-1436
WPCargo Track & Trace DevOps Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitise and escape the wpcargo_tracking_number parameter before outputting it back in the page, which could allow attackers to perform reflected Cross-Site Scripting attacks.

CVE-2022-25175
Jenkins Pipeline: Multibranch Plugin DevOps Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses the same checkout directories for distinct SCMs for the readTrusted step, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.

CVE-2022-26148
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.2%
2022 0 PoCs

An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.

CVE-2022-20617
Jenkins Docker Commons Plugin DevOps
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability exploitable by attackers with Item/Configure permission or able to control the contents of a previously configured job's SCM repository.

CVE-2022-24348
Software Genérico DevOps
N/A
UNKNOWN
EPSS
3.9%
2022 1 PoC

Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related to Helm charts because of an error in helmTemplate in repository.go. For example, an attacker may be able to discover credentials stored in a YAML file.

CVE-2022-20007
Android DevOps
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In startActivityForAttachedApplicationIfNeeded of RootWindowContainer.java, there is a possible way to overlay an app that believes it's still in the foreground, when it is not, due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-211481342

CVE-2022-26659
Software Genérico DevOps Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer writes its log file. Starting from version 4.6.0, the Docker Desktop installer, when run elevated, will write its log files to a location not writable by non-administrator users.

CVE-2022-36883
Jenkins Git Plugin DevOps ⚡ nuclei
N/A
UNKNOWN
EPSS
78.6%
2022 0 PoCs

A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.

CVE-2022-22978
Spring Security DevOps Web
N/A
UNKNOWN
EPSS
90.2%
2022 CWE-863 8 PoCs

In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVE-2022-20612
Jenkins DevOps Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.

CVE-2006-0930
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.6%
2006 1 PoC

Directory traversal vulnerability in Webmail in ArGoSoft Mail Server Pro 1.8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the UIDL parameter.

CVE-2006-3590
Software Genérico DevOps
N/A
UNKNOWN
EPSS
36.1%
2006 2 PoCs

mso.dll, as used by Microsoft PowerPoint 2000 through 2003, allows user-assisted attackers to execute arbitrary commands via a malformed shape container in a PPT file that leads to memory corruption, as exploited by Trojan.PPDropper.B, a different issue than CVE-2006-1540 and CVE-2006-3493.

CVE-2006-5296
Software Genérico DevOps
N/A
UNKNOWN
EPSS
67.8%
2006 2 PoCs

PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted PowerPoint (.PPT) file, as demonstrated by Nanika.ppt, and a different vulnerability than CVE-2006-3435, CVE-2006-3876, CVE-2006-3877, and CVE-2006-4694. NOTE: the impact of this issue was originally claimed to be arbitrary code execution, but later analysis demonstrated that this was erroneous.

CVE-2006-5984
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
1.7%
2006 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 allow remote authenticated users to inject arbitrary web script or HTML via the (1) txtCompanyName, (2) txtEmail, or (3) txtUserAccNum parameter to (a) users.asp, or the (4) setThemeColour parameter to (b) default.asp in the Reseller and Admin levels; or the (5) setThemeColour parameter to default.asp in the User level. NOTE: the txtDomainName parameter to domains.asp is covered by CVE-2006-1407, which suggests that this vector is fixed in 3.2.10 stable.

CVE-2006-0978
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.6%
2006 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in the View Headers (aka viewheaders) functionality in ArGoSoft Mail Server Pro 1.8.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the Subject header, (2) the From header, and (3) certain other unspecified headers.

CVE-2004-2197
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.0%
2004 1 PoC

kdocker.cpp in kdocker 0.1 through 0.8 does not properly check the ownership of files, which could allow local users to execute arbitrary programs.

CVE-2019-10310
Jenkins Ansible Tower Plugin DevOps Web
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnection form validation method allowed attackers permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins