|
223161
|
4.8 |
MEDIUM
Network
|
cisco
|
unified_contact_center_express
|
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS…
|
CWE-79
Cross-site Scripting
|
CVE-2019-12626
|
2024-11-21 13:23 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223162
|
8.8 |
HIGH
Network
|
cisco
|
ios_xe
|
A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery…
|
CWE-352
Origin Validation Error
|
CVE-2019-12624
|
2024-11-21 13:23 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223163
|
4.3 |
MEDIUM
Network
|
cisco
|
enterprise_network_functions_virtualization_infrastructure
|
A vulnerability in the web server functionality of Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform file enum…
|
CWE-538
File and Directory Information Exposure
|
CVE-2019-12623
|
2024-11-21 13:23 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223164
|
5.5 |
MEDIUM
Local
|
cisco
|
telepresence_codec_c40_firmware telepresence_codec_c60_firmware telepresence_codec_c90_firmware roomos
|
A vulnerability in Cisco RoomOS Software could allow an authenticated, local attacker to write files to the underlying filesystem with root privileges. The vulnerability is due to insufficient permis…
|
NVD-CWE-Other
|
CVE-2019-12622
|
2024-11-21 13:23 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223165
|
7.4 |
HIGH
Network
|
cisco
|
hyperflex_hx220c_m5_firmware hyperflex_hx240c_m5_firmware hyperflex_hx220c_af_m5_firmware hyperflex_hx240c_af_m5_firmware hyperflex_hx220c_edge_m5_firmware
|
A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack. The vulnerability is due to insufficient key management. An attacker…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-12621
|
2024-11-21 13:23 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223166
|
6.5 |
MEDIUM
Network
|
otrs debian
|
otrs debian_linux
|
An issue was discovered in Open Ticket Request System (OTRS) Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. A user logged into OTRS as an agent might unknowingly disclose their sess…
|
CWE-200
Information Exposure
|
CVE-2019-12746
|
2024-11-21 13:23 |
2019-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223167
|
7.0 |
HIGH
Local
|
sailpoint
|
desktop_password_reset
|
An unauthenticated privilege escalation exists in SailPoint Desktop Password Reset 7.2. A user with local access to only the Windows logon screen can escalate their privileges to NT AUTHORITY\System.…
|
CWE-269
Improper Privilege Management
|
CVE-2019-12889
|
2024-11-21 13:23 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223168
|
8.8 |
HIGH
Network
|
vestacp
|
control_panel
|
A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root.
|
CWE-78
OS Command
|
CVE-2019-12792
|
2024-11-21 13:23 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223169
|
8.8 |
HIGH
Network
|
vestacp
|
control_panel
|
A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root via the password reset form.
|
CWE-22
Path Traversal
|
CVE-2019-12791
|
2024-11-21 13:23 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223170
|
8.8 |
HIGH
Network
|
yes24
|
viewer_activex
|
Yes24ViewerX ActiveX Control 1.0.327.50126 and earlier versions contains a vulnerability that could allow remote attackers to download and execute arbitrary files by setting the arguments to the Acti…
|
NVD-CWE-noinfo
|
CVE-2019-12809
|
2024-11-21 13:23 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|