cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2023-20249,https://securityvulnerability.io/vulnerability/CVE-2023-20249,Cisco TelePresence Management Suite Software Vulnerability Could Lead to Cross-Site Scripting Attacks,"A vulnerability exists in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software that can be exploited by an authenticated remote attacker to perform a cross-site scripting (XSS) attack. The root cause of this vulnerability lies in the insufficient input validation implemented within the management interface. By manipulating specific data fields within the interface, an attacker could insert malicious scripts, allowing execution of arbitrary code in the context of the affected interface. This could also lead to unauthorized access to sensitive information stored in the user's browser.",Cisco,Cisco Telepresence Management Suite (tms),5.4,MEDIUM,0.0004299999854993075,false,,false,false,false,,,false,false,,2024-04-24T20:47:22.184Z,0 CVE-2023-20248,https://securityvulnerability.io/vulnerability/CVE-2023-20248,Cisco TelePresence Management Suite Software Vulnerability Could Lead to Cross-Site Scripting Attacks,"A vulnerability exists in the web-based management interface of the Cisco TelePresence Management Suite (TMS) Software, enabling authenticated, remote attackers to potentially carry out a cross-site scripting (XSS) attack. This issue arises from inadequate input validation within the management interface, which allows malicious data to be inserted into specific fields. If exploited, the attacker could execute arbitrary script code within the context of the affected interface or gain unauthorized access to sensitive information stored in the user's browser.",Cisco,Cisco Telepresence Management Suite (tms),,,0.0004299999854993075,false,,false,false,true,2024-08-29T18:15:04.000Z,,false,false,,2024-04-24T20:46:55.722Z,0 CVE-2021-34760,https://securityvulnerability.io/vulnerability/CVE-2021-34760,Cisco TelePresence Management Suite Stored Cross-Site Scripting Vulnerability,"A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by inserting malicious data in a specific data field in the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.",Cisco,Cisco Telepresence Management Suite (tms),4.8,MEDIUM,0.0006600000197067857,false,,false,false,true,2024-08-04T02:15:23.000Z,,false,false,,2021-10-21T03:15:00.000Z,0 CVE-2020-3185,https://securityvulnerability.io/vulnerability/CVE-2020-3185,Cisco TelePresence Management Suite Stored Cross-Site Scripting Vulnerability,"A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by inserting malicious data in a specific data field in the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected web-based management interface or access sensitive, browser-based information.",Cisco,Cisco Telepresence Management Suite (tms),4.8,MEDIUM,0.0006600000197067857,false,,false,false,true,2024-08-04T08:16:28.000Z,,false,false,,2020-03-04T00:00:00.000Z,0 CVE-2019-1661,https://securityvulnerability.io/vulnerability/CVE-2019-1661,Cisco TelePresence Management Suite Cross-Site Scripting Vulnerability,"A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information.",Cisco,Cisco Telepresence Management Suite (tms),6.1,MEDIUM,0.0007099999929778278,false,,false,false,true,2024-08-04T19:16:03.000Z,,false,false,,2019-02-07T22:29:00.000Z,0 CVE-2019-1660,https://securityvulnerability.io/vulnerability/CVE-2019-1660,Cisco TelePresence Management Suite Simple Object Access Protocol Vulnerability,"A vulnerability in the Simple Object Access Protocol (SOAP) of Cisco TelePresence Management Suite (TMS) software could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to a lack of proper access and authentication controls on the affected TMS software. An attacker could exploit this vulnerability by gaining access to internal, trusted networks to send crafted SOAP calls to the affected device. If successful, an exploit could allow the attacker to access system management tools. Under normal circumstances, this access should be prohibited.",Cisco,Cisco Telepresence Management Suite (tms),5.3,MEDIUM,0.0010300000431016088,false,,false,false,true,2024-08-04T19:16:03.000Z,,false,false,,2019-02-07T21:29:00.000Z,0 CVE-2018-15467,https://securityvulnerability.io/vulnerability/CVE-2018-15467,Cisco TelePresence Management Suite Cross-Site Scripting Vulnerability,"A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information.",Cisco,Cisco Telepresence Management Suite (tms),6.1,MEDIUM,0.0007099999929778278,false,,false,false,true,2024-08-05T10:17:54.000Z,,false,false,,2019-01-11T15:29:00.000Z,0 CVE-2015-0620,https://securityvulnerability.io/vulnerability/CVE-2015-0620,,"The XML parser in Cisco TelePresence Management Suite (TMS) 14.3(.2) and earlier does not properly handle external entities, which allows remote authenticated users to cause a denial of service via POST requests, aka Bug ID CSCus51494.",Cisco,Telepresence Management Suite,,,0.004470000043511391,false,,false,false,false,,,false,false,,2015-02-18T02:00:00.000Z,0 CVE-2013-1229,https://securityvulnerability.io/vulnerability/CVE-2013-1229,,"TMSSNMPService.exe in TelePresence Manager in Cisco TelePresence Management Suite (TMS) on 64-bit platforms allows remote attackers to cause a denial of service (process crash) via SNMP traps, aka Bug ID CSCue00028.",Cisco,Telepresence Management Suite,,,0.001610000035725534,false,,false,false,false,,,false,false,,2013-05-01T12:00:00.000Z,0