Lucene search

K

Cisco Security Vulnerabilities

cve
cve

CVE-2018-15408

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording F...

7.8CVSS

7.7AI Score

0.002EPSS

2018-10-05 02:29 PM
32
cve
cve

CVE-2018-15409

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording F...

7.8CVSS

7.7AI Score

0.002EPSS

2018-10-05 02:29 PM
28
cve
cve

CVE-2018-15410

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording F...

7.8CVSS

7.7AI Score

0.002EPSS

2018-10-05 02:29 PM
33
cve
cve

CVE-2018-15411

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording F...

7.8CVSS

7.7AI Score

0.002EPSS

2018-10-05 02:29 PM
28
cve
cve

CVE-2018-15412

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording F...

7.8CVSS

8.2AI Score

0.002EPSS

2018-10-05 02:29 PM
28
cve
cve

CVE-2018-15413

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording F...

7.8CVSS

7.7AI Score

0.002EPSS

2018-10-05 02:29 PM
29
cve
cve

CVE-2018-15414

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording F...

7.8CVSS

7.7AI Score

0.002EPSS

2018-10-05 02:29 PM
30
cve
cve

CVE-2018-15415

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording F...

7.8CVSS

7.7AI Score

0.002EPSS

2018-10-05 02:29 PM
31
cve
cve

CVE-2018-15416

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording F...

7.8CVSS

7.7AI Score

0.002EPSS

2018-10-05 02:29 PM
27
cve
cve

CVE-2018-15417

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording F...

7.8CVSS

7.7AI Score

0.002EPSS

2018-10-05 02:29 PM
26
cve
cve

CVE-2018-15418

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording F...

7.8CVSS

7.7AI Score

0.002EPSS

2018-10-05 02:29 PM
29
cve
cve

CVE-2018-15419

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording F...

7.8CVSS

7.7AI Score

0.002EPSS

2018-10-05 02:29 PM
24
cve
cve

CVE-2018-15420

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording F...

7.8CVSS

7.7AI Score

0.002EPSS

2018-10-05 02:29 PM
25
cve
cve

CVE-2018-15421

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording F...

7.8CVSS

7.7AI Score

0.002EPSS

2018-10-05 02:29 PM
32
cve
cve

CVE-2018-15422

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording F...

7.8CVSS

7.7AI Score

0.002EPSS

2018-10-05 02:29 PM
34
cve
cve

CVE-2018-15423

A vulnerability in the web UI of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack. The vulnerability is due to insufficient input validation of iFrame data in HTTP requests that are sent to an affected device. An ...

4.7CVSS

4.8AI Score

0.001EPSS

2018-10-05 02:29 PM
36
cve
cve

CVE-2018-15424

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web server.

4.7CVSS

5.5AI Score

0.001EPSS

2018-10-05 02:29 PM
20
cve
cve

CVE-2018-15425

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web server.

4.7CVSS

5.5AI Score

0.001EPSS

2018-10-05 02:29 PM
29
cve
cve

CVE-2018-15426

A vulnerability in the web-based interface of Cisco Unity Connection could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based interface of the affected software. The vulnerability is due to insufficient validation of user-su...

4.8CVSS

4.9AI Score

0.001EPSS

2018-10-05 02:29 PM
39
cve
cve

CVE-2018-15427

A vulnerability in Cisco Video Surveillance Manager (VSM) Software running on certain Cisco Connected Safety and Security Unified Computing System (UCS) platforms could allow an unauthenticated, remote attacker to log in to an affected system by using the root account, which has default, static use...

9.8CVSS

9.8AI Score

0.004EPSS

2018-10-05 02:29 PM
34
cve
cve

CVE-2018-15428

A vulnerability in the implementation of Border Gateway Protocol (BGP) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain BGP update messages. An attacker co...

6.8CVSS

6.7AI Score

0.001EPSS

2018-10-05 02:29 PM
38
cve
cve

CVE-2018-15429

A vulnerability in the web-based UI of Cisco HyperFlex HX Data Platform Software could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability is due to a lack of proper input and authorization of HTTP requests. An attacker could exploit th...

5.3CVSS

5.2AI Score

0.001EPSS

2018-10-05 02:29 PM
29
cve
cve

CVE-2018-15430

A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with user-level privileges on the underlying operating system. The vulnerability is due to insufficien...

7.2CVSS

7.1AI Score

0.006EPSS

2018-10-05 02:29 PM
29
cve
cve

CVE-2018-15431

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording F...

7.3CVSS

7.3AI Score

0.001EPSS

2018-10-05 02:29 PM
32
cve
cve

CVE-2018-15432

A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to the transmission of sensitive information as part of a GET request. An attacker could exploit this vulnerability by se...

4.3CVSS

4.5AI Score

0.001EPSS

2018-10-05 02:29 PM
35
cve
cve

CVE-2018-15433

A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to the transmission of sensitive information as part of a GET request. An attacker could exploit this vulnerability by se...

4.3CVSS

4.5AI Score

0.001EPSS

2018-10-05 02:29 PM
26
cve
cve

CVE-2018-15434

A vulnerability in the web-based management interface of Cisco Unified IP Phone 7900 Series could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insuffic...

6.1CVSS

5.9AI Score

0.001EPSS

2018-10-05 02:29 PM
29
cve
cve

CVE-2018-15435

A vulnerability in the web-based management interface of Cisco SocialMiner could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied...

6.1CVSS

5.9AI Score

0.001EPSS

2018-10-17 10:00 PM
31
cve
cve

CVE-2018-15436

A vulnerability in the web-based management interface of Cisco Webex Events Center, Cisco Webex Meeting Center, Cisco Webex Support Center, and Cisco Webex Training Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based ...

6.1CVSS

5.9AI Score

0.001EPSS

2018-10-05 02:29 PM
36
cve
cve

CVE-2018-15437

A vulnerability in the system scanning component of Cisco Immunet and Cisco Advanced Malware Protection (AMP) for Endpoints running on Microsoft Windows could allow a local attacker to disable the scanning functionality of the product. This could allow executable files to be launched on the system ...

5.5CVSS

5AI Score

0.002EPSS

2018-11-08 05:29 PM
74
cve
cve

CVE-2018-15438

A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF prote...

6.5CVSS

6.8AI Score

0.001EPSS

2018-10-17 10:29 PM
32
cve
cve

CVE-2018-15439

A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mechanism of an affected device. The vulnerability exists because under specific circumstances, the affected software enables a privileged user account wit...

9.8CVSS

9.5AI Score

0.002EPSS

2018-11-08 05:29 PM
53
cve
cve

CVE-2018-15440

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient san...

6.1CVSS

5.8AI Score

0.001EPSS

2019-01-15 08:00 PM
53
cve
cve

CVE-2018-15441

A vulnerability in the web framework code of Cisco Prime License Manager (PLM) could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied input in SQL queries. An attacker could exploit this vulnerabilit...

9.8CVSS

9.8AI Score

0.001EPSS

2018-11-28 06:29 PM
28
cve
cve

CVE-2018-15442

A vulnerability in the update service of Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user. The vulnerability is due to insufficient validation of user-supplied parameters. An attacker could exploit this vuln...

7.8CVSS

7.8AI Score

0.109EPSS

2018-10-24 07:29 PM
122
cve
cve

CVE-2018-15443

A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a configured Intrusion Prevention System (IPS) rule that inspects certain types of TCP traffic. The vulnerability is due to incorrect TCP retransmission handling. An ...

7.5CVSS

7.5AI Score

0.001EPSS

2018-11-08 05:29 PM
24
cve
cve

CVE-2018-15444

A vulnerability in the web-based user interface of Cisco Energy Management Suite Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Entity (XXE) entri...

7.3CVSS

7.1AI Score

0.003EPSS

2018-11-08 06:29 PM
24
cve
cve

CVE-2018-15445

A vulnerability in the web-based management interface of Cisco Energy Management Suite Software could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF prot...

8CVSS

7.8AI Score

0.004EPSS

2018-11-08 06:29 PM
38
cve
cve

CVE-2018-15446

A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper protections on data that is returned from user meeting requests when the Guest access via ID and passcode option is set to Legacy mod...

7.5CVSS

7.7AI Score

0.002EPSS

2018-11-08 06:29 PM
35
cve
cve

CVE-2018-15447

A vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied input in SQL queries. An attacker could exp...

9.8CVSS

9.7AI Score

0.002EPSS

2018-11-08 07:29 PM
21
cve
cve

CVE-2018-15448

A vulnerability in the user management functions of Cisco Registered Envelope Service could allow an unauthenticated, remote attacker to discover sensitive user information. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to an insecure...

7.5CVSS

7.4AI Score

0.001EPSS

2018-11-08 07:29 PM
21
cve
cve

CVE-2018-15449

A vulnerability in the web-based management interface of Cisco Video Surveillance Media Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the web-based management interface of an affected system. The vulnerability is due to insufficient validation of user-...

6.5CVSS

6.5AI Score

0.001EPSS

2018-11-08 07:29 PM
24
cve
cve

CVE-2018-15450

A vulnerability in the web-based UI of Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to overwrite files on the file system. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by using a specific UI input field ...

6.5CVSS

6.3AI Score

0.001EPSS

2018-11-08 08:29 PM
25
cve
cve

CVE-2018-15451

A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplie...

5.4CVSS

5.3AI Score

0.001EPSS

2018-11-08 08:29 PM
27
cve
cve

CVE-2018-15452

A vulnerability in the DLL loading component of Cisco Advanced Malware Protection (AMP) for Endpoints on Windows could allow an authenticated, local attacker to disable system scanning services or take other actions to prevent detection of unauthorized intrusions. To exploit this vulnerability, the...

6.7CVSS

6.3AI Score

0.0004EPSS

2018-11-13 02:29 PM
29
cve
cve

CVE-2018-15453

A vulnerability in the Secure/Multipurpose Internet Mail Extensions (S/MIME) Decryption and Verification or S/MIME Public Key Harvesting features of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause an affected device to corrupt...

8.6CVSS

8.7AI Score

0.002EPSS

2019-01-10 06:29 PM
36
cve
cve

CVE-2018-15454

A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload or trigger high CPU, resulting in a ...

8.6CVSS

8.4AI Score

0.019EPSS

2018-11-01 01:00 PM
68
cve
cve

CVE-2018-15455

A vulnerability in the logging component of Cisco Identity Services Engine could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to the improper validation of requests stored in the system's logging database. An attacker could exploit this...

6.1CVSS

6AI Score

0.002EPSS

2019-01-23 10:29 PM
22
cve
cve

CVE-2018-15456

A vulnerability in the Admin Portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view saved passwords in plain text. The vulnerability is due to the incorrect inclusion of saved passwords when loading configuration pages in the Admin Portal. An attacker w...

4.9CVSS

5AI Score

0.001EPSS

2019-01-10 06:29 PM
31
cve
cve

CVE-2018-15457

A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerability is due to insufficient val...

6.1CVSS

5.9AI Score

0.001EPSS

2019-01-10 07:29 PM
40
Total number of security vulnerabilities6090