|
247661
|
6.7 |
MEDIUM
Local
|
cisco
|
ios_xe
|
A vulnerability in the shell access request mechanism of Cisco IOS XE Software could allow an authenticated, local attacker to bypass authentication and gain unrestricted access to the root shell of …
|
CWE-287
Improper Authentication
|
CVE-2018-15371
|
2024-11-21 12:50 |
2018-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247662
|
6.8 |
MEDIUM
Physics
|
cisco
|
ios_rom_monitor
|
A vulnerability in Cisco IOS ROM Monitor (ROMMON) Software for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, local attacker to bypass Cisco Secure Boot validation checks and loa…
|
NVD-CWE-noinfo
|
CVE-2018-15370
|
2024-11-21 12:50 |
2018-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247663
|
6.8 |
MEDIUM
Network
|
cisco
|
ios_xe ios
|
A vulnerability in the TACACS+ client subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a d…
|
CWE-20
Improper Input Validation
|
CVE-2018-15369
|
2024-11-21 12:50 |
2018-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247664
|
6.7 |
MEDIUM
Local
|
cisco
|
ios_xe
|
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary comman…
|
CWE-78
OS Command
|
CVE-2018-15368
|
2024-11-21 12:50 |
2018-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247665
|
5.4 |
MEDIUM
Network
|
trendmicro
|
deep_discovery_inspector
|
A Reflected Cross-Site Scripting (XSS) vulnerability in Trend Micro Deep Discovery Inspector 3.85 and below could allow an attacker to bypass CSRF protection and conduct an attack on vulnerable insta…
|
CWE-79
Cross-site Scripting
|
CVE-2018-15365
|
2024-11-21 12:50 |
2018-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247666
|
9.8 |
CRITICAL
Network
|
isweb
|
isweb
|
CMS ISWEB 3.5.3 is vulnerable to directory traversal and local file download, as demonstrated by moduli/downloadFile.php?file=oggetto_documenti/../.././inc/config.php (one can take the control of the…
|
CWE-22
Path Traversal
|
CVE-2018-14957
|
2024-11-21 12:50 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247667
|
9.8 |
CRITICAL
Network
|
isweb
|
isweb
|
CMS ISWEB 3.5.3 is vulnerable to multiple SQL injection flaws. An attacker can inject malicious queries into the application and obtain sensitive information.
|
CWE-89
SQL Injection
|
CVE-2018-14956
|
2024-11-21 12:50 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247668
|
7.8 |
HIGH
Local
|
vectra
|
cognito
|
Management Console in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local privilege escalation vulnerability.
|
NVD-CWE-noinfo
|
CVE-2018-14891
|
2024-11-21 12:50 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247669
|
5.4 |
MEDIUM
Network
|
vectra
|
cognito
|
Vectra Networks Cognito Brain and Sensor before 4.2 contains a cross-site scripting (XSS) vulnerability in the Web Management Console.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14890
|
2024-11-21 12:50 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247670
|
7.8 |
HIGH
Local
|
apache
|
couchdb
|
CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability.
|
CWE-20
Improper Input Validation
|
CVE-2018-14889
|
2024-11-21 12:50 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|