Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Open Audit MEDIUM 6.5
CVE-2021-44674

An information exposure issue has been discovered in Opmantek Open-AudIT 4.2.0. The vulnerability allows an authenticated attacker to read file outsi…

Patch available
Fix from $1,600 2022-01-03
Open Audit CRITICAL 9.8
CVE-2021-40612

An issue was discovered in Opmantek Open-AudIT after 3.5.0. Without authentication, a vulnerability in code_igniter/application/controllers/util.php …

Fix: 4.3.0+
Fix from $2,300 2021-12-22
Open Audit MEDIUM 6.1
CVE-2021-44916

Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad value is passed to the routi…

Fix: after 4.2.0
Fix from $1,600 2021-12-20
Open Audit MEDIUM 6.1
CVE-2021-3333

Opmantek Open-AudIT 4.0.1 is affected by cross-site scripting (XSS). When outputting SQL statements for debugging, a maliciously crafted query can tr…

Patch available
Fix from $1,600 2021-02-05
Open Audit MEDIUM 5.9
CVE-2021-3130

Within the Open-AudIT up to version 3.5.3 application, the web interface hides SSH secrets, Windows passwords, and SNMP strings from users using HTML…

Fix: after 4.0.2
Fix from $1,600 2021-01-20
Open Audit CRITICAL 9.8
CVE-2020-11942

An issue was discovered in Open-AudIT 3.2.2. There are Multiple SQL Injections.

No fix yet
Fix from $2,300 2020-04-29
Open Audit HIGH 8.8
CVE-2020-11943EPSS 24%

An issue was discovered in Open-AudIT 3.2.2. There is Arbitrary file upload.

No fix yet
Fix from $1,950 2020-04-29
Open Audit MEDIUM 5.4
CVE-2020-12261

Open-AudIT 3.3.0 allows an XSS attack after login.

No fix yet
Fix from $1,600 2020-04-28
Open Audit HIGH 8.8
CVE-2020-12078EPSS 10%

An issue was discovered in Open-AudIT 3.3.1. There is shell metacharacter injection via attributes to an open-audit/configuration/ URI. An attacker c…

Patch available
Fix from $1,950 2020-04-28
Open Audit HIGH 8.8
CVE-2020-11941

An issue was discovered in Open-AudIT 3.2.2. There is OS Command injection in Discovery.

No fix yet
Fix from $1,950 2020-04-27
Open Audit HIGH 8.8
CVE-2019-16293

The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a…

Fix: 3.2.0+
Fix from $1,950 2019-09-13
Open Audit MEDIUM 5.4
CVE-2018-16607

Cross-site scripting (XSS) vulnerability in the Orgs Page in Open-AudIT Professional edition in 2.2.7 allows remote attackers to inject arbitrary web…

No fix yet
Fix from $1,600 2018-09-19
Open Audit MEDIUM 6.1
CVE-2018-14493EPSS 40%

Cross-site scripting (XSS) vulnerability in the Groups Page in Open-Audit Community 2.2.6 allows remote attackers to inject arbitrary web script or H…

No fix yet
Fix from $1,600 2018-07-25
Open Audit MEDIUM 5.4
CVE-2018-11124

Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows remote attackers to inject a…

Fix: 2.2.2+
Fix from $1,600 2018-07-06
Open Audit MEDIUM 5.4
CVE-2018-10314

Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted n…

No fix yet
Fix from $1,600 2018-05-10
Network Management Information System HIGH 7.5
CVE-2016-6534

Opmantek NMIS before 4.3.7c has command injection via man, finger, ping, trace, and nslookup in the tools.pl CGI script. Versions before 8.5.12G migh…

Fix: after 8.5.10g
Fix from $1,950 2017-04-10
Network Management Information System MEDIUM 5.4
CVE-2016-5642

Opmantek NMIS before 8.5.12G has XSS via SNMP.

Fix: after 8.5.10g
Fix from $1,600 2017-04-10