|
247831
|
8.8 |
HIGH
Network
|
cybozu
|
garoon
|
SQL injection vulnerability in the Notifications application in the Cybozu Garoon 3.5.0 to 4.6.2 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2018-0607
|
2024-11-21 12:38 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247832
|
9.8 |
CRITICAL
Network
|
cisco
|
unified_contact_center_express unified_ip_interactive_voice_response
|
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to retrieve a cleartext password. …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-0403
|
2024-11-21 12:38 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247833
|
8.8 |
HIGH
Network
|
cisco
|
unified_contact_center_express unified_ip_interactive_voice_response
|
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct a cross-site request fo…
|
CWE-352
Origin Validation Error
|
CVE-2018-0402
|
2024-11-21 12:38 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247834
|
6.1 |
MEDIUM
Network
|
cisco
|
unified_contact_center_express unified_ip_interactive_voice_response
|
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (X…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0401
|
2024-11-21 12:38 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247835
|
6.1 |
MEDIUM
Network
|
cisco
|
unified_contact_center_express unified_ip_interactive_voice_response
|
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (X…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0400
|
2024-11-21 12:38 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247836
|
9.8 |
CRITICAL
Network
|
cisco
|
finesse
|
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to retrieve a cleartext password from an affected system. Cisco Bug IDs…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-0399
|
2024-11-21 12:38 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247837
|
9.8 |
CRITICAL
Network
|
cisco
|
finesse
|
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack. Cisco Bug IDs: …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-0398
|
2024-11-21 12:38 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247838
|
6.1 |
MEDIUM
Network
|
cisco
|
unified_communications_manager_im_and_presence_service
|
A vulnerability in the web framework of the Cisco Unified Communications Manager IM and Presence Service software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS)…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0396
|
2024-11-21 12:38 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247839
|
8.8 |
HIGH
Network
|
cisco
|
cloud_services_platform_2100
|
A vulnerability in the web upload function of Cisco Cloud Services Platform 2100 could allow an authenticated, remote attacker to obtain restricted shell access on an affected system. The vulnerabili…
|
CWE-20
Improper Input Validation
|
CVE-2018-0394
|
2024-11-21 12:38 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247840
|
6.5 |
MEDIUM
Network
|
cisco
|
mobility_services_engine_3365_firmware mobility_services_engine_3355_firmware mobility_services_engine_3310_firmware
|
A Read-Only User Effect Change vulnerability in the Policy Builder interface of Cisco Policy Suite could allow an authenticated, remote attacker to make policy changes in the Policy Builder interface…
|
NVD-CWE-noinfo
|
CVE-2018-0393
|
2024-11-21 12:38 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|