|
224151
|
6.1 |
MEDIUM
Network
|
cisco
|
finesse unified_contact_center_express
|
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to bypass authorization and access sensitive information related to the device. …
|
CWE-79
Cross-site Scripting
|
CVE-2019-15278
|
2024-11-21 13:28 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224152
|
6.5 |
MEDIUM
Network
|
cisco
|
identity_services_engine
|
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access sensitive information re…
|
NVD-CWE-Other
|
CVE-2019-15255
|
2024-11-21 13:28 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224153
|
6.5 |
MEDIUM
Network
|
control-webpanel
|
webpanel
|
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.864 allows an attacker to get a victim's session file name from /home/[USERNAME]/tmp/session/sess_xxxxxx, and the victim's token value from /usr/l…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-15235
|
2024-11-21 13:28 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224154
|
8.8 |
HIGH
Network
|
centreon
|
centreon_web
|
A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Administration/parameters/ldap/xml/ldap_host.php. The arId parameter is not properly…
|
CWE-89
SQL Injection
|
CVE-2019-15300
|
2024-11-21 13:28 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224155
|
8.8 |
HIGH
Network
|
centreon
|
centreon_web
|
A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/traps-mibs/formMibs.php. This page is called from the…
|
CWE-78
OS Command
|
CVE-2019-15298
|
2024-11-21 13:28 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224156
|
8.8 |
HIGH
Network
|
cisco
|
telepresence_collaboration_endpoint telepresence_codec roomos
|
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE), Cisco TelePresence Codec (TC), and Cisco RoomOS Software could allow an authenticated, remote attacker to escalate privil…
|
CWE-20
Improper Input Validation
|
CVE-2019-15288
|
2024-11-21 13:28 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224157
|
7.8 |
HIGH
Local
|
cisco
|
webex_business_suite webex_meetings_online webex_meetings_server
|
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected sy…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-15286
|
2024-11-21 13:28 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224158
|
7.8 |
HIGH
Local
|
cisco
|
webex_business_suite webex_meetings_online webex_meetings_server
|
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected sy…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-15284
|
2024-11-21 13:28 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224159
|
6.5 |
MEDIUM
Network
|
cisco
|
wireless_lan_controller_software
|
A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service (DoS) condition on an affected…
|
CWE-20
Improper Input Validation
|
CVE-2019-15276
|
2024-11-21 13:28 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224160
|
8.8 |
HIGH
Network
|
cisco
|
rv016_multi-wan_vpn_firmware rv042_dual_wan_vpn_firmware rv042g_dual_gigabit_wan_vpn_firmware rv082_dual_wan_vpn_firmware
|
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privilege…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-15271
|
2024-11-21 13:28 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|