imPC@ndo EN

Vulnerabilità Cisco

6642 CVE

CVE-2015-4272
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the ccmivr page in Cisco Unified Communications Manager (formerly CallManager) 10.5(2.10000.5) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCut19580.

cisco unified_communications_manager
0.02EPSS
CVE-2015-4260
Media 4.3

Cross-site scripting (XSS) vulnerability in Cisco Hosted Collaboration Solution 10.6(1) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCuu14862.

cisco hosted_collaboration_solution
0.02EPSS
CVE-2015-0774
Media 4.3

Cross-site scripting (XSS) vulnerability in Cisco Application and Content Networking System (ACNS) 5.5(9) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuu70650.

cisco application_and_content_networking_system_software
0.02EPSS
CVE-2015-0737
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSIGHT System Software 5.3.1.1 allow remote attackers to inject arbitrary web script or HTML via a crafted (1) GET or (2) POST parameter, aka Bug ID CSCuu11099.

cisco firesight_system_software
0.02EPSS
CVE-2015-0766
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface in the Management Center component in Cisco FireSIGHT System Software 6.0.0 allow remote attackers to inject arbitrary web script or HTML via unspecified fields, aka Bug ID…

cisco firesight_system_software
0.02EPSS
CVE-2015-0738
Media 4.3

Cross-site scripting (XSS) vulnerability in the Web Tracking Report page on Cisco Web Security Appliance (WSA) devices 8.5.0-497 allows remote attackers to inject arbitrary web script or HTML via an unspecified field, aka Bug ID CSCuu16008.

cisco web_security_appliance
0.02EPSS
CVE-2015-0734
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Email Security Appliance (ESA) 8.5.6-106 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in a (1) GET or (2) POST request, aka Bug ID CSCut87743.

cisco email_security_appliance_firmware
0.02EPSS
CVE-2015-0728
Media 4.3

Cross-site scripting (XSS) vulnerability in Cisco Access Control Server (ACS) 5.5(0.1) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuu11002.

cisco secure_access_control_system
0.02EPSS
CVE-2015-0727
Media 4.3

Cross-site scripting (XSS) vulnerability in the HTTP module in Cisco Security Manager (CSM) 4.7(0)SP1(1) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut27789.

cisco security_manager
0.02EPSS
CVE-2015-0724
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in dncs 7.0.0.12 in Cisco Headend Digital Broadband Delivery System allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in a (1) GET or (2) POST request, aka Bug ID CSCur2…

cisco headend_digital_broadband_delivery_system
0.02EPSS
CVE-2017-6759
Media 6.5

A vulnerability in the UpgradeManager of the Cisco Prime Collaboration Provisioning Tool 12.1 could allow an authenticated, remote attacker to write arbitrary files as root on the system. The vulnerability is due to insufficient input validation. An attacker c…

cisco prime_collaboration_provisioning
0.02EPSS
CVE-2017-3845
Media 6.1

A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected devi…

cisco prime_collaboration_assurance
0.02EPSS
CVE-2017-3838
Media 6.1

A vulnerability in Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to conduct a DOM-based cross-site scripting (XSS) attack against the user of the web interface of the affected system. More Information: CSCvc04838. Kno…

cisco secure_access_control_system
0.02EPSS
CVE-2017-3829
Media 6.1

A vulnerability in the web-based management interface of Cisco Unified Communications Manager Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an aff…

cisco unified_communications_manager
0.02EPSS
CVE-2017-3828
Media 6.1

A vulnerability in the web-based management interface of Cisco Unified Communications Manager Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an aff…

cisco unified_communications_manager
0.02EPSS
CVE-2017-3821
Media 6.1

A vulnerability in the serviceability page of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct reflected cross-site scripting (XSS) attacks. More Information: CSCvc49348. Known Affected Releases: 10.5(2.14076.1). …

cisco unified_communications_manager
0.02EPSS
CVE-2016-6472
Media 6.1

A vulnerability in several parameters of the ccmivr page of Cisco Unified Communication Manager (CallManager) could allow an unauthenticated, remote attacker to launch a cross-site scripting (XSS) attack against a user of the web interface on the affected syst…

cisco unified_communications_manager
0.02EPSS
CVE-2016-1423
Media 6.1

A vulnerability in the display of email messages in the Messages in Quarantine (MIQ) view in Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a user to click a malicious link in the MIQ view. The m…

cisco email_security_appliance
0.02EPSS
CVE-2014-3363
Bassa 3.5

Cross-site scripting (XSS) vulnerability in the web framework in Cisco Unified Communications Manager (UCM) 9.1(2.10000.28) allows remote authenticated users to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuq68443.

cisco unified_communications_manager
0.02EPSS
CVE-2022-20693
Media 4.7

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this v…

cisco ios_xe
0.02EPSS
CVE-2014-3292
Media 5.5

The Real Time Monitoring Tool (RTMT) implementation in Cisco Unified Communications Manager (Unified CM) allows remote authenticated users to (1) read or (2) delete arbitrary files via a crafted URL, aka Bug IDs CSCuo17302 and CSCuo17199.

cisco unified_communications_manager
0.02EPSS
CVE-2014-3339
Media 6.5

Multiple SQL injection vulnerabilities in the administrative web interface in Cisco Unified Communications Manager (CM) and Cisco Unified Presence Server (CUPS) allow remote authenticated users to execute arbitrary SQL commands via crafted input to unspecified…

cisco unified_communications_domain_manager · cisco unified_presence_server
0.02EPSS
CVE-2013-3441
Media 5.4

Cisco Aironet 3600 access points allow remote attackers to cause a denial of service (memory corruption and device crash) by disrupting Cisco Wireless LAN Controller communication and consequently forcing many transitions from FlexConnect mode to Standalone mo…

cisco aironet_3600 · cisco aironet_3600e · cisco aironet_3600i · cisco aironet_3600p
0.02EPSS
CVE-2006-2322
Media 6.4

The transparent proxy feature of the Cisco Application Velocity System (AVS) 3110 5.0 and 4.0 and earlier, and 3120 5.0.0 and earlier, has a default configuration that allows remote attackers to proxy arbitrary TCP connections, aka Bug ID CSCsd32143.

cisco application_velocity_system_3110 · cisco application_velocity_system_3120
0.02EPSS
CVE-2012-4097
Media 4.3

The BGP implementation in Cisco NX-OS does not properly filter segment types in AS paths, which allows remote attackers to cause a denial of service (BGP service reset) via a malformed UPDATE message, aka Bug ID CSCtn13043.

cisco nx-os
0.02EPSS