|
246901
|
6.1 |
MEDIUM
Network
|
cisco
|
data_center_analytics_framework
|
A vulnerability in the web-based management interface of Cisco Data Center Analytics Framework could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0129
|
2024-11-21 12:37 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246902
|
6.1 |
MEDIUM
Network
|
cisco
|
data_center_analytics_framework
|
A vulnerability in the web-based management interface of Cisco Data Center Analytics Framework could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack ag…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0128
|
2024-11-21 12:37 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246903
|
9.8 |
CRITICAL
Network
|
cisco
|
rv132w_firmware rv134w_firmware
|
A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to view configuration…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2018-0127
|
2024-11-21 12:37 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246904
|
9.8 |
CRITICAL
Network
|
cisco
|
rv132w_firmware rv134w_firmware
|
A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code and g…
|
CWE-20
Improper Input Validation
|
CVE-2018-0125
|
2024-11-21 12:37 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246905
|
5.5 |
MEDIUM
Local
|
cisco
|
ios_xe ios
|
A Path Traversal vulnerability in the diagnostic shell for Cisco IOS and IOS XE Software could allow an authenticated, local attacker to use certain diagnostic shell commands that can overwrite syste…
|
CWE-22
Path Traversal
|
CVE-2018-0123
|
2024-11-21 12:37 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246906
|
4.4 |
MEDIUM
Local
|
cisco
|
staros
|
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to overwrite system files that are …
|
CWE-78
OS Command
|
CVE-2018-0122
|
2024-11-21 12:37 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246907
|
4.3 |
MEDIUM
Network
|
cisco
|
unified_communications_manager
|
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct an SQL injection attack against an affected system. The vulnerabi…
|
CWE-89
SQL Injection
|
CVE-2018-0120
|
2024-11-21 12:37 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246908
|
4.7 |
MEDIUM
Network
|
cisco
|
conference_director
|
A vulnerability in certain authentication controls in the account services of Cisco Spark could allow an authenticated, remote attacker to interact with and view information on an affected device tha…
|
NVD-CWE-noinfo
|
CVE-2018-0119
|
2024-11-21 12:37 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246909
|
8.6 |
HIGH
Network
|
cisco
|
asr_5000_firmware asr_5500_firmware
|
A vulnerability in the ingress packet processing functionality of the Cisco Virtualized Packet Core-Distributed Instance (VPC-DI) Software could allow an unauthenticated, remote attacker to cause bot…
|
CWE-20
Improper Input Validation
|
CVE-2018-0117
|
2024-11-21 12:37 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246910
|
7.2 |
HIGH
Network
|
cisco
|
mobility_services_engine
|
A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to be authorized as a subscriber without providing a valid password; however,…
|
CWE-287
Improper Authentication
|
CVE-2018-0116
|
2024-11-21 12:37 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|