|
246881
|
6.1 |
MEDIUM
Network
|
cisco
|
prime_service_catalog
|
A vulnerability in the web-based interface of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of th…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0200
|
2024-11-21 12:37 |
2018-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246882
|
6.1 |
MEDIUM
Network
|
cisco
|
jabber
|
A vulnerability in Cisco Jabber Client Framework (JCF) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected device. The vulnera…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0199
|
2024-11-21 12:37 |
2018-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246883
|
8.8 |
HIGH
Network
|
cisco
|
ucs_director
|
A vulnerability in the web-based management interface of Cisco UCS Director Software and Cisco Integrated Management Controller (IMC) Supervisor Software could allow an unauthenticated, remote attack…
|
CWE-352
Origin Validation Error
|
CVE-2018-0148
|
2024-11-21 12:37 |
2018-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246884
|
5.4 |
MEDIUM
Network
|
cisco
|
data_center_analytics_framework
|
A vulnerability in the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. T…
|
CWE-352
Origin Validation Error
|
CVE-2018-0146
|
2024-11-21 12:37 |
2018-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246885
|
6.1 |
MEDIUM
Network
|
cisco
|
data_center_analytics_framework
|
A vulnerability in the web-based management interface of the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a reflected cross-site script…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0145
|
2024-11-21 12:37 |
2018-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246886
|
8.6 |
HIGH
Network
|
cisco
|
unified_customer_voice_portal
|
A vulnerability in the Interactive Voice Response (IVR) management connection interface for Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause the IVR …
|
NVD-CWE-Other
|
CVE-2018-0139
|
2024-11-21 12:37 |
2018-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246887
|
9.8 |
CRITICAL
Network
|
cisco
|
virtual_managed_services
|
A vulnerability in the use of JSON web tokens by the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to gain administrative acce…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2018-0130
|
2024-11-21 12:37 |
2018-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246888
|
9.8 |
CRITICAL
Network
|
cisco
|
unified_communications_domain_manager
|
A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to bypass security protections, gain elevated privileges, and execute arbitrary code. Th…
|
CWE-320
Key Management Errors
|
CVE-2018-0124
|
2024-11-21 12:37 |
2018-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246889
|
9.8 |
CRITICAL
Network
|
cisco
|
elastic_services_controller virtual_managed_services
|
A vulnerability in the authentication functionality of the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to bypass authenticat…
|
CWE-287
Improper Authentication
|
CVE-2018-0121
|
2024-11-21 12:37 |
2018-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246890
|
7.2 |
HIGH
Network
|
schneider-electric
|
struxureon_gateway
|
A remote code execution vulnerability exists in Schneider Electric's StruxureOn Gateway versions 1.1.3 and prior. Uploading a zip which contains carefully crafted metadata allows for the file to be u…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-9970
|
2024-11-21 12:37 |
2018-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|