10

CVSS3.1

CVE-2024-20418 - Cisco Ultra-Reliable Wireless Backhaul Software Command Injection Vulnerability

A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Points could allow an unauthenticated, remote attacker to perform command injection attacks with root privileges on the underlying operating s…

📅 Published: Nov. 6, 2024, 4:59 p.m. 🔄 Last Modified: Nov. 8, 2024, 4:55 a.m.

5.1

CVSS4.0

CVE-2024-10318 - NGINX OpenID Connect Vulnerability

A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled account. As a result, although the attacker cannot log in as the victim, they c…

📅 Published: Nov. 6, 2024, 4:48 p.m. 🔄 Last Modified: Nov. 8, 2024, 7:51 p.m.

5.4

CVSS3.1

CVE-2024-20540 - Cisco Unified Contact Center Management Portal Stored Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) could allow an authenticated, remote attacker with low privileges to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability exist…

📅 Published: Nov. 6, 2024, 4:32 p.m. 🔄 Last Modified: Aug. 7, 2025, 7:04 p.m.

4.8

CVSS3.1

CVE-2024-20539 - Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct a stored XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not sufficiently validate user-supplied input…

📅 Published: Nov. 6, 2024, 4:32 p.m. 🔄 Last Modified: Nov. 22, 2024, 7:42 p.m.

6.1

CVSS3.1

CVE-2024-20538 - Cisco Identity Services Engine Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not sufficiently validate user-supplied input. An…

📅 Published: Nov. 6, 2024, 4:31 p.m. 🔄 Last Modified: Nov. 20, 2024, 2:36 p.m.

6.5

CVSS3.1

CVE-2024-20537 - Cisco Identity Services Engine Authorization Bypass Vulnerability

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions. This vulnerability is due to a lack of server-side validation of Administrator permissions. An attacker c…

📅 Published: Nov. 6, 2024, 4:31 p.m. 🔄 Last Modified: Nov. 22, 2024, 7:53 p.m.

8.8

CVSS3.1

CVE-2024-20536 - Cisco Nexus Dashboard Fabric Controller SQL Injection Vulnerability

A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with read-only privileges to execute arbitrary SQL commands on an affected device. This vulnerability is due to insufficient v…

📅 Published: Nov. 6, 2024, 4:31 p.m. 🔄 Last Modified: Aug. 7, 2025, 12:23 a.m.

4.8

CVSS3.1

CVE-2024-20534 - Cisco IP Phone 6800, 7800, 8800, and 9800 Series with Multiplatform Firmware Stored Cross-Site Scri…

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks against users. This vulnerabi…

📅 Published: Nov. 6, 2024, 4:31 p.m. 🔄 Last Modified: Jan. 5, 2026, 2:51 p.m.

4.8

CVSS3.1

CVE-2024-20533 - Cisco IP Phone 6800, 7800, 8800, and 9800 Series with Multiplatform Firmware Stored Cross-Site Scri…

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks against users. This vulnerabi…

📅 Published: Nov. 6, 2024, 4:31 p.m. 🔄 Last Modified: Jan. 5, 2026, 2:50 p.m.

5.5

CVSS3.1

CVE-2024-20532 - Cisco Identity Services Engine Arbitrary File Read and Delete Vulnerability

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To exploit this vulnerability, the attacker would need valid Super Admin credentials. This vulnerability is due to insufficient validation of user-suppl…

📅 Published: Nov. 6, 2024, 4:31 p.m. 🔄 Last Modified: April 28, 2025, 4:54 p.m.
Total resulsts: 344676
Page 7552 of 34,468
« previous page » next page
Filters