1018 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2022-34374
Dell Container Storage Modules DevOps
8.8
HIGH
EPSS
4.9%
2022 CWE-78 1 PoC

Dell Container Storage Modules 1.2 contains an OS command injection in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to to execute arbitrary OS commands on the affected system.

CVE-2022-0071
Hotdog DevOps
8.8
HIGH
EPSS
0.0%
2022 CWE-250 1 PoC

Incomplete fix for CVE-2021-3101. Hotdog, prior to v1.0.2, did not mimic the resource limits, device restrictions, or syscall filters of the target JVM process. This would allow a container to exhaust the resources of the host, modify devices, or make syscalls that would otherwise be blocked.

CVE-2022-34375
Dell Container Storage Modules DevOps
8.8
HIGH
EPSS
0.4%
2022 CWE-22 1 PoC

Dell Container Storage Modules 1.2 contains a path traversal vulnerability in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to unintentional access to path outside of restricted directory.

CVE-2022-38060
OpenStack DevOps
8.8
HIGH
EPSS
0.0%
2022 CWE-269 1 PoC

A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers within a container can lead to increased privileges.

CVE-2022-46074
Software Genérico DevOps Web
8.8
HIGH
EPSS
0.3%
2022 2 PoCs

Helmet Store Showroom 1.0 is vulnerable to Cross Site Request Forgery (CSRF). An unauthenticated user can add an admin account due to missing CSRF protection.

CVE-2022-38065
OpenStack DevOps
8.8
HIGH
EPSS
0.2%
2022 CWE-269 1 PoC

A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead increased privileges.

CVE-2015-10145
Gargoyle Router Management Utility DevOps Networking
8.7
HIGH
EPSS
0.1%
2015 CWE-78 1 PoC

Gargoyle router management utility versions 1.5.x contain an authenticated OS command execution vulnerability in /utility/run_commands.sh. The application fails to properly restrict or validate input supplied via the 'commands' parameter, allowing an authenticated attacker to execute arbitrary shell commands on the underlying system. Successful exploitation may result in full compromise of the device, including unauthorized access to system files and execution of attacker-controlled commands.

CVE-2023-0050
GitLab DevOps Web
8.7
HIGH
EPSS
59.6%
2023 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A specially crafted Kroki diagram could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims.

CVE-2023-53873
SyncBreeze DevOps
8.7
HIGH
EPSS
0.3%
2023 CWE-400 1 PoC

SyncBreeze 15.2.24 contains a denial of service vulnerability in the login authentication mechanism that allows attackers to crash the service. Attackers can send an oversized password parameter with repeated 'password=' values to overwhelm the login endpoint and potentially disrupt service availability.

CVE-2024-58306
minaliC DevOps Web
8.7
HIGH
EPSS
0.3%
2024 CWE-400 1 PoC

minaliC 2.0.0 contains a denial of service vulnerability that allows remote attackers to crash the web server by sending oversized GET requests. Attackers can send crafted HTTP requests with excessive data to overwhelm the server and cause service interruption.

CVE-2024-11274
GitLab DevOps
8.7
HIGH
EPSS
0.4%
2024 CWE-601 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration.

CVE-2021-47713
Hasura GraphQL DevOps
8.7
HIGH
EPSS
0.2%
2021 CWE-770 1 PoC

Hasura GraphQL 1.3.3 contains a denial of service vulnerability that allows attackers to overwhelm the service by crafting malicious GraphQL queries with excessive nested fields. Attackers can send repeated requests with extremely long query strings and multiple threads to consume server resources and potentially crash the GraphQL endpoint.

CVE-2021-47865
ProFTPD DevOps
8.7
HIGH
EPSS
0.0%
2021 CWE-770 1 PoC

ProFTPD 1.3.7a contains a denial of service vulnerability that allows attackers to overwhelm the server by creating multiple simultaneous FTP connections. Attackers can repeatedly establish connections using threading to exhaust server connection limits and block legitimate user access.

CVE-2021-39946
GitLab DevOps Web
8.7
HIGH
EPSS
0.2%
2021 1 PoC

Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis

CVE-2021-22241
GitLab DevOps Web
8.7
HIGH
EPSS
0.2%
2021 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a stored cross-site-scripting via a specifically crafted default branch name.

CVE-2021-47752
AWebServer GhostBuilding DevOps Web Database
8.7
HIGH
EPSS
0.3%
2021 CWE-770 1 PoC

AWebServer GhostBuilding 18 contains a denial of service vulnerability that allows remote attackers to overwhelm the server by sending multiple concurrent HTTP requests. Attackers can generate high-volume requests to multiple endpoints including /mysqladmin to potentially crash or render the service unresponsive.

CVE-2025-9642
GitLab DevOps
8.7
HIGH
EPSS
0.0%
2025 CWE-79 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could allow an attacker to inject malicious content that may lead to account takeover.

CVE-2025-34139
Experience Manager (XM) DevOps Cloud
8.7
HIGH
EPSS
0.2%
2025 CWE-522 1 PoC

A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud that could allow an unauthenticated attacker to read arbitrary files. This vulnerability affects all Experience Platform topologies (XM, XP, XC) from 8.0 Initial Release through 10.4 Initial Release and later. This issue affects Content Management (CM) and standalone instances. PaaS and containerized solutions are also affected.

CVE-2025-34204
Print Virtual Appliance Host DevOps Web
8.7
HIGH
EPSS
0.2%
2025 CWE-269 1 PoC

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) contains multiple Docker containers that run primary application processes (for example PHP workers, Node.js servers and custom binaries) as the root user. This increases the blast radius of a container compromise and enables lateral movement and host compromise when a container is breached.

CVE-2025-4700
GitLab DevOps Web
8.7
HIGH
EPSS
0.1%
2025 CWE-79 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under specific circumstances, could have potentially allowed a successful attacker to trigger unintended content rendering leading to XSS.