|
247931
|
6.1 |
MEDIUM
Network
|
cisco
|
webex_meetings
|
A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0356
|
2024-11-21 12:38 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247932
|
6.1 |
MEDIUM
Network
|
cisco
|
unified_communications_manager
|
A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to conduct a cross-frame scripting (XFS) attack against the user of …
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2018-0355
|
2024-11-21 12:38 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247933
|
6.1 |
MEDIUM
Network
|
cisco
|
unity_connection
|
A vulnerability in the web framework of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of …
|
CWE-79
Cross-site Scripting
|
CVE-2018-0354
|
2024-11-21 12:38 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247934
|
6.7 |
MEDIUM
Local
|
cisco
|
wide_area_application_services
|
A vulnerability in the Disk Check Tool (disk-check.sh) for Cisco Wide Area Application Services (WAAS) Software could allow an authenticated, local attacker to elevate their privilege level to root. …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-0352
|
2024-11-21 12:38 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247935
|
5.4 |
MEDIUM
Network
|
cisco
|
unified_communications_manager
|
A vulnerability in the web framework of the Cisco Unified Communications Manager (Unified CM) software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack aga…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0340
|
2024-11-21 12:38 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247936
|
6.1 |
MEDIUM
Network
|
cisco
|
identity_services_engine_software
|
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a …
|
CWE-79
Cross-site Scripting
|
CVE-2018-0339
|
2024-11-21 12:38 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247937
|
7.8 |
HIGH
Local
|
cisco
|
unified_computing_system
|
A vulnerability in the role-based access-checking mechanisms of Cisco Unified Computing System (UCS) Software could allow an authenticated, local attacker to execute arbitrary commands on an affected…
|
CWE-863
Incorrect Authorization
|
CVE-2018-0338
|
2024-11-21 12:38 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247938
|
8.8 |
HIGH
Network
|
cisco
|
prime_collaboration
|
A vulnerability in the batch provisioning feature of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to escalate privileges to the Administrator level. The vulner…
|
CWE-862
Missing Authorization
|
CVE-2018-0336
|
2024-11-21 12:38 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247939
|
7.8 |
HIGH
Local
|
cisco
|
prime_collaboration
|
A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to view sensitive data. The vulnerability is due to i…
|
CWE-532 CWE-522
Inclusion of Sensitive Information in Log Files Insufficiently Protected Credentials
|
CVE-2018-0335
|
2024-11-21 12:38 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247940
|
4.8 |
MEDIUM
Network
|
cisco
|
anyconnect_secure_mobility_client
|
A vulnerability in the certificate management subsystem of Cisco AnyConnect Network Access Manager and of Cisco AnyConnect Secure Mobility Client for iOS, Mac OS X, Android, Windows, and Linux could …
|
CWE-295
Improper Certificate Validation
|
CVE-2018-0334
|
2024-11-21 12:38 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|