|
222571
|
6.1 |
MEDIUM
Network
|
cisco
|
network_registrar
|
A vulnerability in the web-based management interface of Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of…
|
CWE-79
Cross-site Scripting
|
CVE-2019-1852
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222572
|
5.3 |
MEDIUM
Network
|
cisco
|
email_security_appliance
|
A vulnerability in certain attachment detection mechanisms of the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of an affe…
|
CWE-20
Improper Input Validation
|
CVE-2019-1844
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222573
|
5.4 |
MEDIUM
Network
|
cisco
|
application_policy_infrastructure_controller
|
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS…
|
CWE-79
Cross-site Scripting
|
CVE-2019-1838
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222574
|
7.1 |
HIGH
Local
|
cisco
|
nx-os
|
A vulnerability in the system shell for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to use symbolic links to …
|
CWE-59
Link Following
|
CVE-2019-1836
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222575
|
7.5 |
HIGH
Network
|
cisco
|
web_security_appliance
|
A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition …
|
CWE-20
Improper Input Validation
|
CVE-2019-1817
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222576
|
7.8 |
HIGH
Local
|
cisco
|
web_security_appliance
|
A vulnerability in the log subscription subsystem of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. T…
|
CWE-20
Improper Input Validation
|
CVE-2019-1816
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222577
|
8.8 |
HIGH
Network
|
cisco
|
umbrella
|
A vulnerability in the session management functionality of the web UI for the Cisco Umbrella Dashboard could allow an authenticated, remote attacker to access the Dashboard via an active, user sessio…
|
CWE-384
Session Fixation
|
CVE-2019-1807
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222578
|
9.8 |
CRITICAL
Network
|
cisco
|
nexus_9332pq_firmware nexus_93180yc-ex_firmware nexus_93128tx_firmware nexus_93120tx_firmware nexus_93108tc-ex_firmware nexus_9516_firmware nexus_9508_firmware nexus_9504_firmwar…
|
A vulnerability in the SSH key management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, remote attacker to connect to t…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2019-1804
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222579
|
6.7 |
MEDIUM
Local
|
cisco
|
nexus_9000_series_application_centric_infrastructure
|
A vulnerability in the filesystem management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an authenticated, local attacker with administra…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-1803
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222580
|
8.8 |
HIGH
Network
|
cisco
|
rv325_dual_wan_gigabit_vpn_router_firmware rv320_dual_gigabit_wan_vpn_router_software
|
A vulnerability in the session management functionality of the web-based interface for Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacke…
|
CWE-287
Improper Authentication
|
CVE-2019-1724
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|