Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
cisco finesse vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2021-1246
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote malicious user to conduct a cross-site scripting (XSS) attack and obtain potentially confidential information by leveraging a flaw in the authentication mechanis...
Cisco Finesse 12.0\\(1\\)
Cisco Finesse 12.5\\(1\\)
Cisco Finesse
4.3
CVSSv2
CVE-2020-3159
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote malicious user to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software. The vulnerability is due to i...
Cisco Finesse
3.5
CVSSv2
CVE-2015-7851
Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP prior to 4.2.8p4, when used on systems that do not use '\' or '/' characters for directory separation such as OpenVMS, allows remote authenticated users to overwrite ...
Ntp Ntp
Ntp Ntp 4.2.8
4.3
CVSSv2
CVE-2019-15278
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote malicious user to bypass authorization and access sensitive information related to the device. The vulnerability exists because the software fails to sanitize URLs before...
Cisco Finesse 11.6\\(1\\)
Cisco Finesse 12.0\\(1\\)
Cisco Finesse 12.5\\(1\\)
Cisco Unified Contact Center Express 12.0\\(1\\)
5
CVSSv2
CVE-2019-12632
A vulnerability in Cisco Finesse could allow an unauthenticated, remote malicious user to bypass access controls and conduct a server-side request forgery (SSRF) attack on an affected system. The vulnerability exists because the affected system does not properly validate user-sup...
Cisco Finesse 11.6\\(1\\)
Cisco Finesse 12.5\\(1\\)
Cisco Finesse 12.0\\(1\\)
9.3
CVSSv2
CVE-2018-11776
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or...
Apache Struts
3 EDB exploits
45 Github repositories
3 Articles
5
CVSSv2
CVE-2018-0399
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote malicious user to retrieve a cleartext password from an affected system. Cisco Bug IDs: CSCvg71044.
Cisco Finesse 11.5\\(1\\)
7.5
CVSSv2
CVE-2018-0398
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote malicious user to conduct a server-side request forgery (SSRF) attack. Cisco Bug IDs: CSCvg71018.
Cisco Finesse 11.5\\(1\\)
7.8
CVSSv2
CVE-2017-6779
Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote malicious user to cause high disk utilization, resulting in a denial of service (DoS) conditio...
Cisco Emergency Responder
Cisco Emergency Responder 11.0\\(1.10000.10\\)
Cisco Finesse
Cisco Finesse 9.5\\(1\\)
Cisco Hosted Collaboration Mediation Fulfillment
Cisco Hosted Collaboration Mediation Fulfillment 9.5\\(1\\)
Cisco Mediasense 9.5\\(1\\)
Cisco Mediasense
Cisco Prime Collaboration Assurance
Cisco Prime Collaboration Provisioning 12.5
Cisco Prime License Manager
Cisco Socialminer
Cisco Unified Communications Manager
Cisco Unified Communications Manager 12.0
Cisco Unified Communications Manager 10.5\\(2.10000.5\\)
Cisco Unified Communications Manager 11.0\\(1.10000.10\\)
Cisco Unified Communications Manager 11.5\\(1.10000.6\\)
Cisco Unified Contact Center Express 9.0\\(2\\)su1.3
Cisco Unified Contact Center Express
Cisco Unified Intelligence Center
Cisco Unified Intelligence Center 9.5\\(1\\)
Cisco Unity Connection 12.0
10
CVSSv2
CVE-2017-12337
A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could allow an unauthenticated, remote malicious user to gain unauthorized, elevated access to an affected device. The vulnerability occurs when a ...
Cisco Prime License Manager -
Cisco Unity Connection -
Cisco Emergency Responder -
Cisco Unified Communications Manager Im And Presence Service -
Cisco Unified Communications Manager -
Cisco Finesse -
Cisco Mediasense -
Cisco Socialminer -
Cisco Unified Intelligence Center -
Cisco Hosted Collaboration Solution -
Cisco Unified Contact Center Express -
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »