1.8

CVSS3.1

CVE-2024-52525 - Nextcloud Server User password is available in memory of the PHP process

Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unencrypted in the session data. The session data is encrypted before being saved in the session storage (Redis or disk), but it would allow a malicious process that gains access to tโ€ฆ

๐Ÿ“… Published: Nov. 15, 2024, 4:30 p.m. ๐Ÿ”„ Last Modified: Jan. 23, 2025, 2:33 p.m.

6.4

CVSS3.1

CVE-2021-1483 - Cisco SD-WAN vManage Software XML External Entity Vulnerability

A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. This vulnerability is due to improper handling of XML External Entity (XXE) entries when the affectedโ€ฆ

๐Ÿ“… Published: Nov. 15, 2024, 4:27 p.m. ๐Ÿ”„ Last Modified: Aug. 4, 2025, 2:41 p.m.

6.5

CVSS3.1

CVE-2021-1484 - Cisco SD-WAN vManage Command Injection Vulnerability

A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to inject arbitrary commands on an affected system and cause a denial of service (DoS) condition. This vulnerability is due to improper input validation of user-supplied input to the dโ€ฆ

๐Ÿ“… Published: Nov. 15, 2024, 4:26 p.m. ๐Ÿ”„ Last Modified: Aug. 4, 2025, 2:41 p.m.

6.5

CVSS3.0

CVE-2021-1491 - Cisco SD-WAN vManage Software Information Disclosure Vulnerability

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying file system of the device. This vulnerability is due to insufficient file scope limiting. An attacker could exploit thโ€ฆ

๐Ÿ“… Published: Nov. 15, 2024, 4:25 p.m. ๐Ÿ”„ Last Modified: Aug. 4, 2025, 2:42 p.m.

9.3

CVSS4.0

CVE-2024-52528 - Auth Token can be passed dummy or wrong the middleware response is 200 OK

Budget Control Gateway acts as an entry point for incoming requests and routes them to the appropriate microservices for Budget Control. Budget Control Gateway does not properly validate auth tokens, which allows attackers to bypass intended restrictions. This vulnerability is fixed in 1.5.2.

๐Ÿ“… Published: Nov. 15, 2024, 4:21 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.8

CVSS3.1

CVE-2021-1494 -

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of specific HTTP header parameters. An attacker could exploit thisโ€ฆ

๐Ÿ“… Published: Nov. 15, 2024, 4:21 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2022-20633 - Cisco Enterprise Chat and Email Username Enumeration Vulnerability

A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to perform a username enumeration attack against an affected device. This vulnerability is due to differences in authentication responses that are sent back from the applicatioโ€ฆ

๐Ÿ“… Published: Nov. 15, 2024, 4:15 p.m. ๐Ÿ”„ Last Modified: July 31, 2025, 3:07 p.m.

6.1

CVSS3.1

CVE-2022-20632 - Cisco Enterprise Chat and Email Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface of an affected device. The vulnerability exists because the web-based management interface does not properly validate useโ€ฆ

๐Ÿ“… Published: Nov. 15, 2024, 4:14 p.m. ๐Ÿ”„ Last Modified: July 31, 2025, 3:08 p.m.

5.8

CVSS3.1

CVE-2021-34753 - Cisco Firepower Threat Defense Ethernet Industrial Protocol Policy Bypass Vulnerabilities

A vulnerability in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic. This vulnerability is due to incomplete processing during deep โ€ฆ

๐Ÿ“… Published: Nov. 15, 2024, 4:14 p.m. ๐Ÿ”„ Last Modified: Aug. 7, 2025, 6:04 p.m.

6.7

CVSS3.1

CVE-2021-34752 - Cisco Firepower Threat Defense Command Injection Vulnerabilities

A vulnerability in the CLI of Cisco FTD Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands with root privileges on the underlying operating system of an affected device.  This vulnerability is due to insufficient validatioโ€ฆ

๐Ÿ“… Published: Nov. 15, 2024, 4:14 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 7855 of 34,919
ยซ previous page ยป next page
Filters