|
223301
|
5.3 |
MEDIUM
Network
|
cisco
|
ios_xr
|
A vulnerability in the access-control logic of the NETCONF over Secure Shell (SSH) of Cisco IOS XR Software may allow connections despite an access control list (ACL) that is configured to deny acces…
|
CWE-862
Missing Authorization
|
CVE-2019-15998
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223302
|
6.7 |
MEDIUM
Local
|
cisco
|
dna_spaces\
|
A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to perform a command injection attack and execute arbitrary commands on the underlying operating system as …
|
CWE-78
OS Command
|
CVE-2019-15997
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223303
|
6.7 |
MEDIUM
Local
|
cisco
|
dna_spaces\
|
A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. The vulner…
|
CWE-78
OS Command
|
CVE-2019-15996
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223304
|
6.5 |
MEDIUM
Network
|
cisco
|
dna_spaces\
|
A vulnerability in the web UI of Cisco DNA Spaces: Connector could allow an authenticated, remote attacker to execute arbitrary SQL queries. The vulnerability exists because the web UI does not prope…
|
CWE-89
SQL Injection
|
CVE-2019-15995
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223305
|
6.1 |
MEDIUM
Network
|
cisco
|
stealthwatch_enterprise
|
A vulnerability in the web-based management interface of Cisco Stealthwatch Enterprise could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of…
|
CWE-79
Cross-site Scripting
|
CVE-2019-15994
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223306
|
5.3 |
MEDIUM
Network
|
cisco
|
rv016_multi-wan_vpn_firmware rv042_dual_wan_vpn_firmware rv042g_dual_gigabit_wan_vpn_firmware rv082_dual_wan_vpn_firmware
|
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an unauthenticated, remote attacker to view information displayed in the web-based …
|
NVD-CWE-Other
|
CVE-2019-15990
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223307
|
5.3 |
MEDIUM
Network
|
cisco
|
email_security_appliance_firmware
|
A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation f…
|
CWE-20
Improper Input Validation
|
CVE-2019-15988
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223308
|
5.3 |
MEDIUM
Network
|
cisco
|
webex_meetings_server webex_meetings_online webex_training_center webex_meeting_center webex_event_center webex_support_center
|
A vulnerability in web interface of the Cisco Webex Event Center, Cisco Webex Meeting Center, Cisco Webex Support Center, and Cisco Webex Training Center could allow an unauthenticated, remote attack…
|
CWE-287
Improper Authentication
|
CVE-2019-15987
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223309
|
6.7 |
MEDIUM
Local
|
cisco
|
unity_express
|
A vulnerability in the CLI of Cisco Unity Express could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. To exploit this vulnerability, an a…
|
CWE-20
Improper Input Validation
|
CVE-2019-15986
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223310
|
8.8 |
HIGH
Network
|
cisco
|
unified_communications_manager
|
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The…
|
CWE-89
SQL Injection
|
CVE-2019-15972
|
2024-11-21 13:29 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|