|
222291
|
7.1 |
HIGH
Local
|
cisco
|
anyconnect_secure_mobility_client
|
A vulnerability in the inter-service communication of Cisco AnyConnect Secure Mobility Client for Android could allow an unauthenticated, local attacker to perform a service hijack attack on an affec…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-16007
|
2024-11-21 13:29 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222292
|
4.4 |
MEDIUM
Local
|
cisco
|
umbrella_roaming_client
|
A vulnerability in the automatic update process of Cisco Umbrella Roaming Client for Windows could allow an authenticated, local attacker to install arbitrary, unapproved applications on a targeted d…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-16000
|
2024-11-21 13:29 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222293
|
7.2 |
HIGH
Network
|
cisco
|
adaptive_security_appliance adaptive_security_appliance_software firepower_management_center firepower_threat_defense
|
A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authentica…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-15992
|
2024-11-21 13:29 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222294
|
5.3 |
MEDIUM
Network
|
cisco
|
sg250x-24_firmware sg250x-24p_firmware sg250x-48_firmware sg250x-48p_firmware sg250-08_firmware sg250-08hp_firmware sg250-10p_firmware sg250-18_firmware sg250-26_firmware s…
|
A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information. The vulnerability exists because the software la…
|
CWE-287
Improper Authentication
|
CVE-2019-15993
|
2024-11-21 13:29 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222295
|
6.1 |
MEDIUM
Network
|
cisco
|
managed_services_accelerator
|
A vulnerability in the web interface of Cisco Managed Services Accelerator (MSX) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due t…
|
CWE-20
Improper Input Validation
|
CVE-2019-15974
|
2024-11-21 13:29 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222296
|
6.1 |
MEDIUM
Network
|
cisco
|
web_security_appliance
|
A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a use…
|
CWE-79
Cross-site Scripting
|
CVE-2019-15969
|
2024-11-21 13:29 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222297
|
6.5 |
MEDIUM
Network
|
cisco
|
unified_communications_manager
|
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitive information in the web-based management i…
|
NVD-CWE-noinfo
|
CVE-2019-15963
|
2024-11-21 13:29 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222298
|
6.6 |
MEDIUM
Physics
|
cisco
|
spa500_series_ip_phones_firmware
|
A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the device. The vulnerability is due to the presence of de…
|
CWE-20
Improper Input Validation
|
CVE-2019-15959
|
2024-11-21 13:29 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222299
|
7.2 |
HIGH
Network
|
cisco
|
rv016_multi-wan_vpn_firmware rv042_dual_wan_vpn rv042g_dual_gigabit_wan_vpn_firmware rv082_dual_wan_vpn_router_firmware rv320_firmware rv325_firmware
|
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker with administrative privileges to inject arbitrar…
|
CWE-20
Improper Input Validation
|
CVE-2019-15957
|
2024-11-21 13:29 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222300
|
6.5 |
MEDIUM
Network
|
fortinet
|
fortiap-s fortiap-w2 fortiap-u
|
An improper input validation in FortiAP-S/W2 6.2.0 to 6.2.2, 6.0.5 and below, FortiAP-U 6.0.1 and below CLI admin console may allow unauthorized administrators to overwrite system files via specially…
|
CWE-20
Improper Input Validation
|
CVE-2019-15709
|
2024-11-21 13:29 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|