Category: CVE

CVE-2024-50343 | Symfony information disclosure

A vulnerability classified as problematic was found in Symfony. Affected by this vulnerability is an unknown functionality. The manipulation leads to information disclosure. This vulnerability is known as CVE-2024-50343. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-50345 | Symfony redirect

A vulnerability classified as problematic has been found in Symfony. Affected is an unknown function. The manipulation leads to open redirect. This vulnerability is traded as CVE-2024-50345. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-51736 | Symfony on Windows Process Class command injection

A vulnerability was found in Symfony on Windows. It has been rated as critical. This issue affects some unknown processing of the component Process Class Handler. The manipulation leads to command injection. The identification of this vulnerability is CVE-2024-51736. The attack needs to be approached locally. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-20504 | Cisco Secure Email Web-based Management Interface cross site scripting (cisco-sa-esa-wsa-sma-xss-zYm3f49n)

A vulnerability was found in Cisco Secure Email, Secure Email and Web Manager and Secure Web Appliance. It has been declared as problematic. This vulnerability affects unknown code of the component Web-based Management Interface. The manipulation leads to basic cross site scripting. This vulnerability was named CVE-2024-20504. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-20487 | Cisco Identity Services Engine Software 2.7.0 p8 up to 3.3 Patch 3 Web-based Management Interface cross site scripting (cisco-sa-ise-multi-vulns-AF544ED5)

A vulnerability was found in Cisco Identity Services Engine Software. It has been classified as problematic. This affects an unknown part of the component Web-based Management Interface. The manipulation leads to cross site scripting. This vulnerability is uniquely identified as CVE-2024-20487. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-20507 | Cisco Meeting Management up to 3.9.0 Web-based Management Interface information disclosure (cisco-sa-cmm-info-disc-9ZEMAhGA)

A vulnerability was found in Cisco Meeting Management up to 3.9.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Web-based Management Interface. The manipulation leads to information disclosure. This vulnerability is handled as CVE-2024-20507. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-20476 | Cisco Identity Services Engine Software 2.7.0 p8 up to 3.3 Patch 3 Web-based Management Interface client-side enforcement of server-side security (cisco-sa-ise-multi-vulns-AF544ED5)

A vulnerability has been found in Cisco Identity Services Engine Software and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web-based Management Interface. The manipulation leads to client-side enforcement of server-side security. This vulnerability is known as CVE-2024-20476. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-20484 | Cisco Enterprise Chat and Email up to 12.6_ES3_ET2 External Agent Assignment Service denial of service (cisco-sa-ece-dos-Oqb9uFEv)

A vulnerability, which was classified as critical, was found in Cisco Enterprise Chat and Email. Affected is an unknown function of the component External Agent Assignment Service. The manipulation leads to denial of service. This vulnerability is traded as CVE-2024-20484. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-20418 | Cisco IOS XE Controller Web-based Management Interface command injection (cisco-sa-backhaul-ap-cmdinj-R7E28Ecs)

A vulnerability, which was classified as very critical, has been found in Cisco IOS XE Controller. This issue affects some unknown processing of the component Web-based Management Interface. The manipulation leads to command injection. The identification of this vulnerability is CVE-2024-20418. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-20527 | Cisco Identity Services Engine Software up to 3.4.0 API path traversal (cisco-sa-ise-multi-vuln-DBQdWRy)

A vulnerability, which was classified as critical, has been found in Cisco Identity Services Engine Software. This issue affects some unknown processing of the component API. The manipulation leads to path traversal. The identification of this vulnerability is CVE-2024-20527. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-20528 | Cisco Identity Services Engine Software up to 3.3.0 API path traversal (cisco-sa-ise-multi-vuln-DBQdWRy)

A vulnerability classified as critical was found in Cisco Identity Services Engine Software. This vulnerability affects unknown code of the component API. The manipulation leads to path traversal. This vulnerability was named CVE-2024-20528. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More
Loading