Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
audit vulnerabilities and exploits
(subscribe to this query)
4.8
CVSSv3
CVE-2021-24901
The Security Audit WordPress plugin up to and including 1.0.0 does not sanitise and escape the Data Id setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Securemoz Security Audit
NA
CVE-2007-4148
Heap-based buffer overflow in the Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 allows remote malicious users to cause a denial of service (persistent daemon crashes) or execute arbitrary code via a long filename in a "LOG." command.
Visionsoft Audit 12.4.0.0
7.5
CVSSv3
CVE-2007-4150
The Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 uses weak cryptography (XOR) when (1) transmitting passwords, which allows remote malicious users to obtain sensitive information by sniffing the network; and (2) storing passwords in the configuration fi...
Visionsoft Audit 12.4.0.0
NA
CVE-2007-4152
The Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 allows remote malicious users to conduct replay attacks by capturing and resending data from the DETAILS and PROCESS sections of a session that schedules an audit.
Visionsoft Audit 12.4.0.0
6.1
CVSSv3
CVE-2021-44916
Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad value is passed to the routine via a URL, malicious JavaScript code can be executed in the victim's browser.
Opmantek Open-audit
8.8
CVSSv3
CVE-2019-16293
The Create Discoveries feature of Open-AudIT prior to 3.2.0 allows an authenticated malicious user to execute arbitrary OS commands via a crafted value for a URL field.
Opmantek Open-audit
5.9
CVSSv3
CVE-2021-3130
Within the Open-AudIT up to version 3.5.3 application, the web interface hides SSH secrets, Windows passwords, and SNMP strings from users using HTML 'password field' obfuscation. By using Developer tools or similar, it is possible to change the obfuscation so that the ...
Opmantek Open-audit
1 Github repository
NA
CVE-2007-4151
The Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 allows remote malicious users to obtain sensitive information via (1) a LOG.ON command, which reveals the logging pathname in the server response; (2) a VER command, which reveals the version number in th...
Visionsoft Audit 12.4.0.0
6.1
CVSSv3
CVE-2020-2140
Jenkins Audit Trail Plugin 3.2 and previous versions does not escape the error message for the URL Patterns field form validation, resulting in a reflected cross-site scripting vulnerability.
Jenkins Audit Trail
NA
CVE-2007-4149
The Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 does not require authentication for (1) the "LOG." command, which allows remote malicious users to create or overwrite arbitrary files; (2) the SETTINGSFILE command, which allows remote maliciou...
Visionsoft Audit 12.4.0.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23316
SQL injection
type confusion
CVE-2024-20697
CVE-2024-4344
local
CVE-2024-30043
CVE-2024-3821
CVE-2024-5041
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »