Category: CVE

CVE-2022-20654 | Cisco Webex Meetings up to 40.6.2 Web-based Interface cross site scripting (cisco-sa-webex-xss-FmbPu2pe)

A vulnerability was found in Cisco Webex Meetings. It has been declared as problematic. This vulnerability affects unknown code of the component Web-based Interface. The manipulation leads to basic cross site scripting. This vulnerability was named CVE-2022-20654. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2022-20631 | Cisco Enterprise Chat and Email up to 12.6(1)_ET1 Web-based Management Interface cross site scripting (cisco-sa-ece-multivulns-kbK2yVhR)

A vulnerability was found in Cisco Enterprise Chat and Email. It has been classified as problematic. This affects an unknown part of the component Web-based Management Interface. The manipulation leads to cross site scripting. This vulnerability is uniquely identified as CVE-2022-20631. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2022-20626 | Cisco Prime Access Registrar up to 9.2.0.0 Web-based Management Interface cross site scripting (cisco-sa-prime-reg-xss-zLOz8PfB)

A vulnerability was found in Cisco Prime Access Registrar and classified as problematic. Affected by this issue is some unknown functionality of the component Web-based Management Interface. The manipulation leads to cross site scripting. This vulnerability is handled as CVE-2022-20626. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2022-20634 | Cisco Enterprise Chat and Email up to 12.6(1)_ET1 Web-based Management Interface redirect (cisco-sa-ece-multivulns-kbK2yVhR)

A vulnerability has been found in Cisco Enterprise Chat and Email and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web-based Management Interface. The manipulation leads to open redirect. This vulnerability is known as CVE-2022-20634. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2022-20655 | Cisco IOS XR Software CLI os command injection (cisco-sa-cli-cmdinj-4MttWZPB)

A vulnerability, which was classified as critical, was found in Cisco IOS XR Software, Virtual Topology System (VTS), Network Services Orchestrator, Enterprise NFV Infrastructure Software, Catalyst SD-WAN, Catalyst SD-WAN Manager, IOS XE Catalyst SD-WAN, SD-WAN vEdge Router, Ultra Gateway Platform and Carrier Packet Transport. Affected is an unknown function of the component CLI. The manipulation leads to os command injection. This vulnerability is traded as CVE-2022-20655. Local access is required to approach this attack. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-51497 | LibreNMS up to 24.9.x Custom OID Tab unit cross site scripting

A vulnerability classified as problematic was found in LibreNMS up to 24.9.x. This vulnerability affects unknown code of the component Custom OID Tab. The manipulation of the argument unit leads to cross site scripting. This vulnerability was named CVE-2024-51497. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-51164 | JEPaaS 7.2.8 Query insertBtnLog sql injection

A vulnerability, which was classified as critical, was found in JEPaaS 7.2.8. This affects an unknown part of the file /je/login/btnLog/insertBtnLog of the component Query Handler. The manipulation leads to sql injection. This vulnerability is uniquely identified as CVE-2024-51164. It is possible to initiate the attack remotely. There is no exploit...

Read More
Loading