|
222981
|
6.5 |
MEDIUM
Network
|
cisco
|
sd-wan_firmware
|
A vulnerability in the vManage web-based UI (web UI) of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected …
|
CWE-352
Origin Validation Error
|
CVE-2019-16002
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222982
|
5.3 |
MEDIUM
Local
|
cisco
|
webex_meetings webex_teams
|
A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Webex Teams for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-16001
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222983
|
5.3 |
MEDIUM
Network
|
cisco
|
ios_xr
|
A vulnerability in the access-control logic of the NETCONF over Secure Shell (SSH) of Cisco IOS XR Software may allow connections despite an access control list (ACL) that is configured to deny acces…
|
CWE-862
Missing Authorization
|
CVE-2019-15998
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222984
|
6.7 |
MEDIUM
Local
|
cisco
|
dna_spaces\
|
A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to perform a command injection attack and execute arbitrary commands on the underlying operating system as …
|
CWE-78
OS Command
|
CVE-2019-15997
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222985
|
6.7 |
MEDIUM
Local
|
cisco
|
dna_spaces\
|
A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. The vulner…
|
CWE-78
OS Command
|
CVE-2019-15996
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222986
|
6.5 |
MEDIUM
Network
|
cisco
|
dna_spaces\
|
A vulnerability in the web UI of Cisco DNA Spaces: Connector could allow an authenticated, remote attacker to execute arbitrary SQL queries. The vulnerability exists because the web UI does not prope…
|
CWE-89
SQL Injection
|
CVE-2019-15995
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222987
|
6.1 |
MEDIUM
Network
|
cisco
|
stealthwatch_enterprise
|
A vulnerability in the web-based management interface of Cisco Stealthwatch Enterprise could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of…
|
CWE-79
Cross-site Scripting
|
CVE-2019-15994
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222988
|
5.3 |
MEDIUM
Network
|
cisco
|
rv016_multi-wan_vpn_firmware rv042_dual_wan_vpn_firmware rv042g_dual_gigabit_wan_vpn_firmware rv082_dual_wan_vpn_firmware
|
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an unauthenticated, remote attacker to view information displayed in the web-based …
|
NVD-CWE-Other
|
CVE-2019-15990
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222989
|
5.3 |
MEDIUM
Network
|
cisco
|
email_security_appliance_firmware
|
A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation f…
|
CWE-20
Improper Input Validation
|
CVE-2019-15988
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222990
|
5.3 |
MEDIUM
Network
|
cisco
|
webex_meetings_server webex_meetings_online webex_training_center webex_meeting_center webex_event_center webex_support_center
|
A vulnerability in web interface of the Cisco Webex Event Center, Cisco Webex Meeting Center, Cisco Webex Support Center, and Cisco Webex Training Center could allow an unauthenticated, remote attack…
|
CWE-287
Improper Authentication
|
CVE-2019-15987
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|