Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
auditor vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2018-15513
Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor role.
Totemo Totemomail 6.0.0
4.3
CVSSv2
CVE-2013-1013
XSS Auditor in WebKit in Apple Safari prior to 6.0.5 does not properly rewrite URLs, which allows remote malicious users to trigger unintended form submissions via unspecified vectors.
Apple Safari
Apple Safari 6.0.3
Apple Safari 6.0.2
Apple Safari 6.0
Apple Safari 6.0.1
4
CVSSv2
CVE-2019-14838
A flaw was found in wildfly-core prior to 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server
Redhat Wildfly Core 7.0.0
Redhat Jboss Enterprise Application Platform 7.2.0
Redhat Jboss Enterprise Application Platform 7.2.5
Redhat Jboss Enterprise Application Platform 7.3.0
Redhat Single Sign-on 7.3.5
Redhat Data Grid 7.3.4
Redhat Jboss Enterprise Application Platform 7.2.4
1 Github repository
6
CVSSv2
CVE-2009-0613
Trend Micro InterScan Web Security Suite (IWSS) 3.1 before build 1237 allows remote authenticated Auditor and Report Only users to bypass intended permission settings, and modify the system configuration, via requests to unspecified JSP pages.
Trendmicro Interscan Web Security Suite 3.1
5
CVSSv2
CVE-2016-1864
The XSS auditor in WebKit, as used in Apple iOS prior to 9.3 and Safari prior to 9.1, does not properly handle redirects in block mode, which allows remote malicious users to obtain sensitive information via a crafted URL.
Apple Safari
Apple Iphone Os
NA
CVE-2023-29240
An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
F5 Big-iq Centralized Management
NA
CVE-2023-3511
An issue has been discovered in GitLab EE affecting all versions starting from 8.17 prior to 16.4.4, all versions starting from 16.5 prior to 16.5.4, all versions starting from 16.6 prior to 16.6.2. It was possible for auditor users to fork and submit merge requests to private pr...
Gitlab Gitlab
4
CVSSv2
CVE-2017-6338
Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user with low privileges like 'Reports Only' or 'Auditor' to change FTP Access Control Settings, create or modify r...
Trendmicro Interscan Web Security Virtual Appliance
1 EDB exploit
3.6
CVSSv2
CVE-2006-4991
RSA Keon Certificate Authority (KeonCA) Manager 6.5.1 and 6.6 allows privileged local users to hide malicious Certificate Authority (CA) activities by modifying CA auditor logs without detection by (1) modifying or deleting a <LOG BLOCK> and its signature from the XML log i...
Rsa Keon Certificate Authority Manager 6.6
Rsa Keon Certificate Authority Manager 6.5.1
5.5
CVSSv2
CVE-2021-3039
An information exposure through log file vulnerability exists in the Palo Alto Networks Prisma Cloud Compute Console where a secret used to authorize the role of the authenticated user is logged to a debug log file. Authenticated Operator role and Auditor role users with access t...
Paloaltonetworks Prisma Cloud
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »