|
223271
|
8.2 |
HIGH
Local
|
cisco
|
firepower_threat_defense firepower_9300_firmware firepower_4115_firmware firepower_4125_firmware firepower_4145_firmware firepower_4110_firmware firepower_4120_firmware firepower…
|
Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2019-12674
|
2024-11-21 13:23 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223272
|
7.5 |
HIGH
Network
|
cisco
|
adaptive_security_appliance adaptive_security_appliance_software firepower_threat_defense
|
A vulnerability in the FTP inspection engine of Cisco Adaptive Security (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a den…
|
CWE-20
Improper Input Validation
|
CVE-2019-12673
|
2024-11-21 13:23 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223273
|
6.1 |
MEDIUM
Network
|
cisco
|
identity_services_engine
|
A vulnerability in the web-based guest portal of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of …
|
CWE-79
Cross-site Scripting
|
CVE-2019-12631
|
2024-11-21 13:23 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223274
|
9.8 |
CRITICAL
Network
|
cisco
|
security_manager
|
A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerabil…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-12630
|
2024-11-21 13:23 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223275
|
6.1 |
MEDIUM
Network
|
dnnsoftware
|
dotnetnuke
|
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to per…
|
CWE-79
Cross-site Scripting
|
CVE-2019-12562
|
2024-11-21 13:23 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223276
|
2.7 |
LOW
Network
|
silverstripe
|
silverstripe
|
In SilverStripe through 4.3.3, there is access escalation for CMS users with limited access through permission cache pollution.
|
NVD-CWE-noinfo
|
CVE-2019-12617
|
2024-11-21 13:23 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223277
|
7.8 |
HIGH
Local
|
cisco
|
nx-os
|
A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linu…
|
CWE-78
OS Command
|
CVE-2019-12717
|
2024-11-21 13:23 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223278
|
6.7 |
MEDIUM
Local
|
cisco
|
ios_xr
|
A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an authenticated, local attac…
|
CWE-78
OS Command
|
CVE-2019-12709
|
2024-11-21 13:23 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223279
|
6.8 |
MEDIUM
Physics
|
cisco
|
ios
|
A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker with physical access to an affected device to execute arbitrary code on the underlying operatin…
|
CWE-59
Link Following
|
CVE-2019-12672
|
2024-11-21 13:23 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223280
|
7.8 |
HIGH
Local
|
cisco
|
ios_xe
|
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execute commands on the underlying operating system (OS…
|
CWE-863
Incorrect Authorization
|
CVE-2019-12671
|
2024-11-21 13:23 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|