|
248721
|
8.8 |
HIGH
Network
|
cisco
|
identity_services_engine_software
|
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and…
|
CWE-352
Origin Validation Error
|
CVE-2018-0413
|
2024-11-21 12:38 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248722
|
6.1 |
MEDIUM
Network
|
cisco
|
unified_communications_manager
|
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack …
|
CWE-79
Cross-site Scripting
|
CVE-2018-0411
|
2024-11-21 12:38 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248723
|
5.4 |
MEDIUM
Network
|
cisco
|
sf300-08_firmware sf302-08_firmware sf302-08p_firmware sf302-08pp_firmware sf302-08mp_firmware sf302-08mpp_firmware sf300-24_firmware sf300-24p_firmware sf300-24pp_firmware
|
A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could allow an authenticated, remote attacker to conduct a reflected cross-site scrip…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0408
|
2024-11-21 12:38 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248724
|
5.4 |
MEDIUM
Network
|
cisco
|
sf300-08_firmware sf302-08_firmware sf302-08p_firmware sf302-08pp_firmware sf302-08mp_firmware sf302-08mpp_firmware sf300-24_firmware sf300-24p_firmware sf300-24pp_firmware
|
A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could allow an authenticated, remote attacker to conduct a persistent cross-site scri…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0407
|
2024-11-21 12:38 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248725
|
6.1 |
MEDIUM
Network
|
cisco
|
web_security_appliance
|
A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected or Document Object Model based (DOM-…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0406
|
2024-11-21 12:38 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248726
|
5.9 |
MEDIUM
Network
|
cisco
|
advanced_malware_protection_for_endpoints
|
A vulnerability in Cisco AMP for Endpoints Mac Connector Software installed on Apple macOS 10.12 could allow an unauthenticated, remote attacker to cause a kernel panic on an affected system, resulti…
|
NVD-CWE-noinfo
|
CVE-2018-0397
|
2024-11-21 12:38 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248727
|
6.5 |
MEDIUM
Network
|
cisco
|
prime_collaboration prime_collaboration_provisioning
|
A vulnerability in the password change function of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to cause the system to become inoperable. The vulnerability is …
|
NVD-CWE-noinfo
|
CVE-2018-0391
|
2024-11-21 12:38 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248728
|
4.7 |
MEDIUM
Local
|
arm debian
|
mbed_tls debian_linux
|
ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows local users to achieve partial plaintext recovery (for a CBC based ciphersuite) via a cache-based side-channel attack.
|
NVD-CWE-noinfo
|
CVE-2018-0498
|
2024-11-21 12:38 |
2018-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248729
|
5.9 |
MEDIUM
Network
|
arm debian
|
mbed_tls debian_linux
|
ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows remote attackers to achieve partial plaintext recovery (for a CBC based ciphersuite) via a timing-based side-channel attack. This vu…
|
NVD-CWE-noinfo
|
CVE-2018-0497
|
2024-11-21 12:38 |
2018-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248730
|
7.4 |
HIGH
Network
|
dhc
|
dhc_online_shop
|
The DHC Online Shop App for Android version 3.2.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive infor…
|
CWE-295
Improper Certificate Validation
|
CVE-2018-0622
|
2024-11-21 12:38 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|