|
222411
|
3.1 |
LOW
Adjacent
|
apple broadcom
|
iphone_os ipados mac_os_x bcm4389_firmware bcm43012_firmware bcm43013_firmware bcm4375_firmware bcm43752_firmware bcm4356_firmware
|
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper la…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2019-15126
|
2024-11-21 13:28 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222412
|
6.1 |
MEDIUM
Network
|
zimbra
|
collaboration_server
|
In Zimbra Collaboration before 8.8.15 Patch 1, there is a non-persistent XSS vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15313
|
2024-11-21 13:28 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222413
|
6.1 |
MEDIUM
Network
|
cisco
|
finesse unified_contact_center_express
|
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to bypass authorization and access sensitive information related to the device. …
|
CWE-79
Cross-site Scripting
|
CVE-2019-15278
|
2024-11-21 13:28 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222414
|
6.5 |
MEDIUM
Network
|
cisco
|
identity_services_engine
|
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access sensitive information re…
|
NVD-CWE-Other
|
CVE-2019-15255
|
2024-11-21 13:28 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222415
|
6.5 |
MEDIUM
Network
|
control-webpanel
|
webpanel
|
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.864 allows an attacker to get a victim's session file name from /home/[USERNAME]/tmp/session/sess_xxxxxx, and the victim's token value from /usr/l…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-15235
|
2024-11-21 13:28 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222416
|
8.8 |
HIGH
Network
|
centreon
|
centreon_web
|
A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Administration/parameters/ldap/xml/ldap_host.php. The arId parameter is not properly…
|
CWE-89
SQL Injection
|
CVE-2019-15300
|
2024-11-21 13:28 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222417
|
8.8 |
HIGH
Network
|
centreon
|
centreon_web
|
A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/traps-mibs/formMibs.php. This page is called from the…
|
CWE-78
OS Command
|
CVE-2019-15298
|
2024-11-21 13:28 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222418
|
8.8 |
HIGH
Network
|
cisco
|
telepresence_collaboration_endpoint telepresence_codec roomos
|
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE), Cisco TelePresence Codec (TC), and Cisco RoomOS Software could allow an authenticated, remote attacker to escalate privil…
|
CWE-20
Improper Input Validation
|
CVE-2019-15288
|
2024-11-21 13:28 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222419
|
7.8 |
HIGH
Local
|
cisco
|
webex_business_suite webex_meetings_online webex_meetings_server
|
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected sy…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-15286
|
2024-11-21 13:28 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222420
|
7.8 |
HIGH
Local
|
cisco
|
webex_business_suite webex_meetings_online webex_meetings_server
|
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected sy…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-15284
|
2024-11-21 13:28 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|