|
222731
|
6.5 |
MEDIUM
Network
|
cisco
|
identity_services_engine
|
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access sensitive information re…
|
NVD-CWE-Other
|
CVE-2019-15255
|
2024-11-21 13:28 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222732
|
6.5 |
MEDIUM
Network
|
control-webpanel
|
webpanel
|
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.864 allows an attacker to get a victim's session file name from /home/[USERNAME]/tmp/session/sess_xxxxxx, and the victim's token value from /usr/l…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-15235
|
2024-11-21 13:28 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222733
|
8.8 |
HIGH
Network
|
centreon
|
centreon_web
|
A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Administration/parameters/ldap/xml/ldap_host.php. The arId parameter is not properly…
|
CWE-89
SQL Injection
|
CVE-2019-15300
|
2024-11-21 13:28 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222734
|
8.8 |
HIGH
Network
|
centreon
|
centreon_web
|
A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/traps-mibs/formMibs.php. This page is called from the…
|
CWE-78
OS Command
|
CVE-2019-15298
|
2024-11-21 13:28 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222735
|
8.8 |
HIGH
Network
|
cisco
|
telepresence_collaboration_endpoint telepresence_codec roomos
|
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE), Cisco TelePresence Codec (TC), and Cisco RoomOS Software could allow an authenticated, remote attacker to escalate privil…
|
CWE-20
Improper Input Validation
|
CVE-2019-15288
|
2024-11-21 13:28 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222736
|
7.8 |
HIGH
Local
|
cisco
|
webex_business_suite webex_meetings_online webex_meetings_server
|
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected sy…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-15286
|
2024-11-21 13:28 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222737
|
7.8 |
HIGH
Local
|
cisco
|
webex_business_suite webex_meetings_online webex_meetings_server
|
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected sy…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-15284
|
2024-11-21 13:28 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222738
|
6.5 |
MEDIUM
Network
|
cisco
|
wireless_lan_controller_software
|
A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service (DoS) condition on an affected…
|
CWE-20
Improper Input Validation
|
CVE-2019-15276
|
2024-11-21 13:28 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222739
|
8.8 |
HIGH
Network
|
cisco
|
rv016_multi-wan_vpn_firmware rv042_dual_wan_vpn_firmware rv042g_dual_gigabit_wan_vpn_firmware rv082_dual_wan_vpn_firmware
|
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privilege…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-15271
|
2024-11-21 13:28 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222740
|
7.8 |
HIGH
Local
|
gog
|
galaxy
|
An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an attacker can send unauthenticated local TCP packe…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-15511
|
2024-11-21 13:28 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|