|
246941
|
5.4 |
MEDIUM
Network
|
cisco
|
videoscape_anyres_live
|
A vulnerability in the web-based management interface of Cisco Videoscape AnyRes Live could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of th…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0220
|
2024-11-21 12:37 |
2018-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246942
|
6.1 |
MEDIUM
Network
|
cisco
|
unified_computing_system_director
|
A vulnerability in the web-based management interface of Cisco Unified Computing System (UCS) Director could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack a…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0219
|
2024-11-21 12:37 |
2018-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246943
|
3.3 |
LOW
Local
|
cisco
|
secure_access_control_server_solution_engine
|
A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain informati…
|
CWE-611
XXE
|
CVE-2018-0218
|
2024-11-21 12:37 |
2018-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246944
|
6.7 |
MEDIUM
Local
|
cisco
|
asr_5000_firmware asr_5700_firmware asr_5500_firmware
|
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to perform a command injection atta…
|
CWE-78
OS Command
|
CVE-2018-0217
|
2024-11-21 12:37 |
2018-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246945
|
5.4 |
MEDIUM
Network
|
cisco
|
identity_services_engine
|
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and…
|
CWE-352
Origin Validation Error
|
CVE-2018-0216
|
2024-11-21 12:37 |
2018-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246946
|
6.3 |
MEDIUM
Network
|
cisco
|
identity_services_engine
|
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and…
|
CWE-352
Origin Validation Error
|
CVE-2018-0215
|
2024-11-21 12:37 |
2018-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246947
|
5.3 |
MEDIUM
Local
|
cisco
|
identity_services_engine
|
A vulnerability in certain CLI commands of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with the privil…
|
CWE-78
OS Command
|
CVE-2018-0214
|
2024-11-21 12:37 |
2018-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246948
|
8.8 |
HIGH
Network
|
cisco
|
identity_services_engine
|
A vulnerability in the credential reset functionality for Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to gain elevated privileges. The vulnerability is due to a…
|
CWE-20
Improper Input Validation
|
CVE-2018-0213
|
2024-11-21 12:37 |
2018-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246949
|
6.1 |
MEDIUM
Network
|
cisco
|
identity_services_engine
|
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a …
|
CWE-79
Cross-site Scripting
|
CVE-2018-0212
|
2024-11-21 12:37 |
2018-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246950
|
4.4 |
MEDIUM
Local
|
cisco
|
identity_services_engine
|
A vulnerability in specific CLI commands for the Cisco Identity Services Engine could allow an authenticated, local attacker to cause a denial of service (DoS) condition. The device may need to be ma…
|
CWE-20
Improper Input Validation
|
CVE-2018-0211
|
2024-11-21 12:37 |
2018-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|