Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
cisco finesse - vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2021-1245
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote malicious user to conduct a cross-site scripting (XSS) attack and obtain potentially confidential information by leveraging a flaw in the authentication mechanis...
Cisco Finesse 12.0\\(1\\)
Cisco Finesse 12.5\\(1\\)
Cisco Finesse
4.3
CVSSv2
CVE-2020-3159
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote malicious user to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software. The vulnerability is due to i...
Cisco Finesse
4.3
CVSSv2
CVE-2019-15278
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote malicious user to bypass authorization and access sensitive information related to the device. The vulnerability exists because the software fails to sanitize URLs before...
Cisco Finesse 11.6\\(1\\)
Cisco Finesse 12.0\\(1\\)
Cisco Finesse 12.5\\(1\\)
Cisco Unified Contact Center Express 12.0\\(1\\)
4.3
CVSSv2
CVE-2017-12288
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express could allow an unauthenticated, remote malicious user to conduct a cross-site scripting (XSS) attack against a user of an affected device. The vulnerability is due to insufficient valida...
Cisco Finesse 11.5\\(1\\)
4.3
CVSSv2
CVE-2017-6761
A vulnerability in the web-based management interface of Cisco Finesse 10.6(1) and 11.5(1) could allow an unauthenticated, remote malicious user to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerab...
Cisco Finesse 11.5\\(1\\)
Cisco Finesse 10.6\\(1\\)
4.3
CVSSv2
CVE-2015-4310
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Finesse 10.5(1) allow remote malicious users to inject arbitrary web script or HTML via unspecified parameters in a (1) GET or (2) POST request, aka Bug IDs CSCuq82322, CSCut95853, and CSCuq73975.
Cisco Finesse 10.5\\(1\\) Base
4.3
CVSSv2
CVE-2015-1788
The BN_GF2m_mod_inv function in crypto/bn/bn_gf2m.c in OpenSSL prior to 0.9.8s, 1.0.0 prior to 1.0.0e, 1.0.1 prior to 1.0.1n, and 1.0.2 prior to 1.0.2b does not properly handle ECParameters structures in which the curve is over a malformed binary polynomial field, which allows re...
Openssl Openssl
Openssl Openssl 1.0.1m
Openssl Openssl 1.0.2a
Openssl Openssl 1.0.1j
Openssl Openssl 1.0.0n
Openssl Openssl 1.0.1
Openssl Openssl 1.0.0c
Openssl Openssl 1.0.0i
Openssl Openssl 1.0.0
Openssl Openssl 1.0.1h
Openssl Openssl 1.0.0m
Openssl Openssl 1.0.1c
Openssl Openssl 1.0.1g
Openssl Openssl 1.0.0h
Openssl Openssl 1.0.0e
Openssl Openssl 1.0.0f
Openssl Openssl 1.0.0d
Openssl Openssl 1.0.0j
Openssl Openssl 1.0.0p
Openssl Openssl 1.0.1a
Openssl Openssl 1.0.0o
Openssl Openssl 1.0.1d
1 Article
4.3
CVSSv2
CVE-2015-0714
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Finesse Server 10.0(1), 10.5(1), 10.6(1), and 11.0(1) allow remote malicious users to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCut53595.
Cisco Finesse 10.0\\(1\\) Base
Cisco Finesse 10.5\\(1\\) Base
Cisco Finesse 10.6\\(1\\) Base
Cisco Finesse 11.0\\(1\\) Base
4.3
CVSSv2
CVE-2015-0285
The ssl3_client_hello function in s3_clnt.c in OpenSSL 1.0.2 prior to 1.0.2a does not ensure that the PRNG is seeded before proceeding with a handshake, which makes it easier for remote malicious users to defeat cryptographic protection mechanisms by sniffing the network and then...
Openssl Openssl 1.0.2
4.3
CVSSv2
CVE-2015-0208
The ASN.1 signature-verification implementation in the rsa_item_verify function in crypto/rsa/rsa_ameth.c in OpenSSL 1.0.2 prior to 1.0.2a allows remote malicious users to cause a denial of service (NULL pointer dereference and application crash) via crafted RSA PSS parameters to...
Openssl Openssl 1.0.2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »