Show filters
570 Total Results
Displaying 301-310 of 570
Sort by:
Attacker Value
Unknown

CVE-2012-2148

Disclosure Date: December 06, 2019 (last updated November 27, 2024)
An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies
Attacker Value
Unknown

CVE-2019-15986

Disclosure Date: November 21, 2019 (last updated November 27, 2024)
A vulnerability in the CLI of Cisco Unity Express could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. To exploit this vulnerability, an attacker would need valid administrator credentials. The vulnerability is due to improper input validation for certain CLI commands that are executed on a vulnerable system. An attacker could exploit this vulnerability by logging in to the system and sending crafted CLI commands. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root.
Attacker Value
Unknown

CVE-2019-1915

Disclosure Date: October 02, 2019 (last updated November 27, 2024)
A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (SME), Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections by the affected software. An attacker could exploit this vulnerability by persuading a targeted user to click a malicious link. A successful exploit could allow the attacker to send arbitrary requests that could change the password of a targeted user. An attacker could then take unauthorized actions on behalf of the targeted user.
Attacker Value
Unknown

CVE-2019-12707

Disclosure Date: October 02, 2019 (last updated November 27, 2024)
A vulnerability in the web-based interface of multiple Cisco Unified Communications products could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input by the web-based interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.
Attacker Value
Unknown

CVE-2015-9447

Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.
Attacker Value
Unknown

CVE-2015-9446

Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php.
Attacker Value
Unknown

CVE-2015-9445

Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation.
Attacker Value
Unknown

CVE-2019-16104

Disclosure Date: September 08, 2019 (last updated November 27, 2024)
Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO.
Attacker Value
Unknown

CVE-2019-16105

Disclosure Date: September 08, 2019 (last updated November 27, 2024)
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows ..%2f directory traversal via a rest/json/configdb/download/ URI.
0
Attacker Value
Unknown

CVE-2019-16103

Disclosure Date: September 08, 2019 (last updated November 27, 2024)
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows privilege escalation (by administrators) from the menu to a root Bash OS shell via the spsshell feature.
0