Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.0% | — | Opmantek Open-audit | 3/1/2022 | 9/7/2026 | An information exposure issue has been discovered in Opmantek Open-AudIT 4.2.0. The vulnerability allows an authenticated attacker to read file outside of the restricted directory. | |
| Modificada | Crítica (9.8) | 2.0% | — | Opmantek Open-audit | 22/12/2021 | 17/6/2026 | An issue was discovered in Opmantek Open-AudIT after 3.5.0. Without authentication, a vulnerability in code_igniter/application/controllers/util.php allows an attacker perform command execution without echoes. | |
| Modificada | Media (6.1) | 3.7% | — | Opmantek Open-audit | 20/12/2021 | 17/6/2026 | Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad value is passed to the routine via a URL, malicious JavaScript code can be executed in the victim's browser. | |
| Modificada | Media (6.1) | 0.76% | — | Opmantek Open-audit | 5/2/2021 | 17/6/2026 | Opmantek Open-AudIT 4.0.1 is affected by cross-site scripting (XSS). When outputting SQL statements for debugging, a maliciously crafted query can trigger an XSS attack. This attack only succeeds if the user is already logged in to Open-AudIT before they click the malicious link. | |
| Modificada | Media (5.9) | 1.3% | — | Opmantek Open-audit | 20/1/2021 | 17/6/2026 | Within the Open-AudIT up to version 3.5.3 application, the web interface hides SSH secrets, Windows passwords, and SNMP strings from users using HTML 'password field' obfuscation. By using Developer tools or similar, it is possible to change the obfuscation so that the credentials are visible. | |
| Modificada | Alta (8.8) | 24% | — | Opmantek Open-audit | 29/4/2020 | 17/6/2026 | An issue was discovered in Open-AudIT 3.2.2. There is Arbitrary file upload. | |
| Modificada | Crítica (9.8) | 1.2% | — | Opmantek Open-audit | 29/4/2020 | 17/6/2026 | An issue was discovered in Open-AudIT 3.2.2. There are Multiple SQL Injections. | |
| Modificada | Media (5.4) | 2.6% | — | Opmantek Open-audit | 28/4/2020 | 17/6/2026 | Open-AudIT 3.3.0 allows an XSS attack after login. | |
| Modificada | Alta (8.8) | 10.0% | — | Opmantek Open-audit | 28/4/2020 | 17/6/2026 | An issue was discovered in Open-AudIT 3.3.1. There is shell metacharacter injection via attributes to an open-audit/configuration/ URI. An attacker can exploit this by adding an excluded IP address to the global discovery settings (internally called exclude_ip). This exclude_ip value is passed to the exec function in… | |
| Modificada | Alta (8.8) | 4.6% | — | Opmantek Open-audit | 27/4/2020 | 17/6/2026 | An issue was discovered in Open-AudIT 3.2.2. There is OS Command injection in Discovery. | |
| Modificada | Alta (8.8) | 74% | — | CactiFedoraproject FedoraOpmantek Open-auditOpensuse Suse Package HUB+1 | 22/2/2020 | 17/6/2026 | graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege. | |
| Modificada | Alta (8.8) | 1.6% | — | Opmantek Open-audit | 13/9/2019 | 17/6/2026 | The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field. | |
| Modificada | Media (5.4) | 0.65% | — | Opmantek Open-audit | 19/9/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Orgs Page in Open-AudIT Professional edition in 2.2.7 allows remote attackers to inject arbitrary web script via the Orgs name field. | |
| Modificada | Media (6.1) | 41% | — | Opmantek Open-audit | 25/7/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Groups Page in Open-Audit Community 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the group name. | |
| Modificada | Media (5.4) | 1.9% | — | Opmantek Open-audit | 6/7/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted attribute name of an Attribute. | |
| Modificada | Media (5.4) | 1.8% | — | Opmantek Open-audit | 10/5/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the action parameter in the Discover -> Audit Scripts -> List Scripts -> Download section. | |
| Modificada | Media (6.8) | 2.7% | — | Open-audit | 19/4/2018 | 17/6/2026 | Open-AudIT before 2.2 has CSV Injection. | |
| Modificada | Media (5.4) | 1.1% | — | Open-audit | 12/4/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the Admin->Logs section (with a logs?logs.type= URI) and the Manage->Attributes section (via the "Name (display)" field to the… | |
| Modificada | Media (6.1) | 0.68% | — | Open-audit | 26/3/2018 | 17/6/2026 | An issue was discovered in Open-AudIT Professional 2.1. It is possible to inject a malicious payload in the redirect_url parameter to the /login URI to trigger an open redirect. A "data:text/html;base64," payload can be used with JavaScript code. | |
| Modificada | Alta (8.8) | 1.2% | — | Open-audit | 25/3/2018 | 17/6/2026 | Open-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the credentials URI. | |
| Modificada | Media (5.4) | 0.53% | — | Open-audit | 25/3/2018 | 17/6/2026 | Open-AudIT Professional 2.1 has XSS via a crafted src attribute of an IMG element within a URI. | |
| Modificada | Media (5.4) | 1.6% | — | Open-audit | 22/3/2018 | 17/6/2026 | Open-AudIT Professional 2.1 allows XSS via the Name or Description field on the Credentials screen. |