|
249291
|
7.5 |
HIGH
Network
|
cisco
|
telepresence_video_communication_server unified_communications_manager_im_and_presence_service
|
A vulnerability in the XCP Router service of the Cisco Unified Communications Manager IM & Presence Service (CUCM IM&P) and the Cisco TelePresence Video Communication Server (VCS) and Expressway coul…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-0409
|
2024-11-21 12:38 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249292
|
6.1 |
MEDIUM
Network
|
cisco
|
unified_communications_domain_manager hosted_collaboration_solution
|
A vulnerability in Cisco Unified Communications Domain Manager Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on an affected system. The vulne…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0386
|
2024-11-21 12:38 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249293
|
5.4 |
MEDIUM
Network
|
cisco
|
registered_envelope_service
|
A vulnerability in the web-based management interface of the Cisco Registered Envelope Service could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a u…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0367
|
2024-11-21 12:38 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249294
|
9.8 |
CRITICAL
Network
|
qnap
|
helpdesk
|
Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 20180528 and their earlier versions could allow rem…
|
CWE-77
Command Injection
|
CVE-2018-0714
|
2024-11-21 12:38 |
2018-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249295
|
7.8 |
HIGH
Local
|
cisco
|
thor_video_codec
|
Stack-based buffer overflow in the Cisco Thor decoder before commit 18de8f9f0762c3a542b1122589edb8af859d9813 allows local users to cause a denial of service (segmentation fault) and execute arbitrary…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-0429
|
2024-11-21 12:38 |
2018-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249296
|
8.8 |
HIGH
Network
|
cisco
|
identity_services_engine_software
|
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and…
|
CWE-352
Origin Validation Error
|
CVE-2018-0413
|
2024-11-21 12:38 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249297
|
6.1 |
MEDIUM
Network
|
cisco
|
unified_communications_manager
|
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack …
|
CWE-79
Cross-site Scripting
|
CVE-2018-0411
|
2024-11-21 12:38 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249298
|
5.4 |
MEDIUM
Network
|
cisco
|
sf300-08_firmware sf302-08_firmware sf302-08p_firmware sf302-08pp_firmware sf302-08mp_firmware sf302-08mpp_firmware sf300-24_firmware sf300-24p_firmware sf300-24pp_firmware
|
A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could allow an authenticated, remote attacker to conduct a reflected cross-site scrip…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0408
|
2024-11-21 12:38 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249299
|
5.4 |
MEDIUM
Network
|
cisco
|
sf300-08_firmware sf302-08_firmware sf302-08p_firmware sf302-08pp_firmware sf302-08mp_firmware sf302-08mpp_firmware sf300-24_firmware sf300-24p_firmware sf300-24pp_firmware
|
A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could allow an authenticated, remote attacker to conduct a persistent cross-site scri…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0407
|
2024-11-21 12:38 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249300
|
6.1 |
MEDIUM
Network
|
cisco
|
web_security_appliance
|
A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected or Document Object Model based (DOM-…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0406
|
2024-11-21 12:38 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|