Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
audit vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-31890
SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae via the order parameter to the getOrder function.
Enhancesoft Audit Log
1 Github repository
3.5
CVSSv2
CVE-2018-11124
Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition prior to 2.2.2 allows remote malicious users to inject arbitrary web script or HTML via a crafted attribute name of an Attribute.
Opmantek Open-audit
1 EDB exploit
10
CVSSv2
CVE-2007-4149
The Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 does not require authentication for (1) the "LOG." command, which allows remote malicious users to create or overwrite arbitrary files; (2) the SETTINGSFILE command, which allows remote maliciou...
Visionsoft Audit 12.4.0.0
4.3
CVSSv2
CVE-2007-4151
The Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 allows remote malicious users to obtain sensitive information via (1) a LOG.ON command, which reveals the logging pathname in the server response; (2) a VER command, which reveals the version number in th...
Visionsoft Audit 12.4.0.0
9.3
CVSSv2
CVE-2007-4152
The Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 allows remote malicious users to conduct replay attacks by capturing and resending data from the DETAILS and PROCESS sections of a session that schedules an audit.
Visionsoft Audit 12.4.0.0
10
CVSSv2
CVE-2007-4148
Heap-based buffer overflow in the Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 allows remote malicious users to cause a denial of service (persistent daemon crashes) or execute arbitrary code via a long filename in a "LOG." command.
Visionsoft Audit 12.4.0.0
5
CVSSv2
CVE-2007-4150
The Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 uses weak cryptography (XOR) when (1) transmitting passwords, which allows remote malicious users to obtain sensitive information by sniffing the network; and (2) storing passwords in the configuration fi...
Visionsoft Audit 12.4.0.0
5
CVSSv2
CVE-2020-2288
In Jenkins Audit Trail Plugin 3.6 and previous versions, the default regular expression pattern could be bypassed in many cases by adding a suffix to the URL that would be ignored during request handling.
Jenkins Audit Trail
6.8
CVSSv2
CVE-2015-6828
The tweet_info function in class/__functions.php in the SecureMoz Security Audit plugin 1.0.5 and previous versions for WordPress does not use an HTTPS session for downloading serialized data, which allows man-in-the-middle malicious users to conduct PHP object injection attacks ...
Securemoz Security Audit
4.3
CVSSv2
CVE-2021-44916
Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad value is passed to the routine via a URL, malicious JavaScript code can be executed in the victim's browser.
Opmantek Open-audit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »