|
222991
|
6.7 |
MEDIUM
Local
|
cisco
|
unity_express
|
A vulnerability in the CLI of Cisco Unity Express could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. To exploit this vulnerability, an a…
|
CWE-20
Improper Input Validation
|
CVE-2019-15986
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222992
|
8.8 |
HIGH
Network
|
cisco
|
unified_communications_manager
|
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The…
|
CWE-89
SQL Injection
|
CVE-2019-15972
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222993
|
4.3 |
MEDIUM
Network
|
cisco
|
email_security_appliance_firmware
|
A vulnerability in the MP3 detection engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on …
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-15971
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222994
|
5.4 |
MEDIUM
Network
|
cisco
|
unified_communications_domain_manager hosted_collaboration_solution
|
A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager (Unified CDM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS…
|
CWE-79
Cross-site Scripting
|
CVE-2019-15968
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222995
|
6.1 |
MEDIUM
Network
|
cisco
|
network_level_service industrial_network_director
|
A vulnerability in the web-based management interface of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against…
|
CWE-79
Cross-site Scripting
|
CVE-2019-15973
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222996
|
4.4 |
MEDIUM
Local
|
cisco
|
telepresence_collaboration_endpoint roomos
|
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an authenticated, local attacker to enable audio recording without notifying users. …
|
NVD-CWE-Other
|
CVE-2019-15967
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222997
|
5.4 |
MEDIUM
Network
|
cisco
|
webex_meetings
|
A vulnerability in the Webex Network Recording Admin page of Cisco Webex Meetings could allow an authenticated, remote attacker to elevate privileges in the context of the affected page. To exploit t…
|
NVD-CWE-Other
|
CVE-2019-15960
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222998
|
9.8 |
CRITICAL
Network
|
cisco
|
prime_infrastructure evolved_programmable_network_manager
|
A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote attacker to execute arbitrary code with …
|
CWE-20
Improper Input Validation
|
CVE-2019-15958
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222999
|
8.8 |
HIGH
Network
|
cisco
|
asyncos web_security_appliance
|
A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform an unauthorized system reset …
|
NVD-CWE-Other
|
CVE-2019-15956
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223000
|
8.8 |
HIGH
Network
|
ui
|
unifi_video_controller
|
A privilege escalation exists in UniFi Video Controller =<3.10.6 that would allow an attacker on the local machine to run arbitrary commands.
|
NVD-CWE-noinfo
|
CVE-2019-15595
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|