Vulnerabilities (CVE)

Filtered by vendor Cisco Subscribe
Filtered by product Cloud Web Security
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-3154 1 Cisco 1 Cloud Web Security 2020-02-24 4.0 MEDIUM 4.9 MEDIUM
A vulnerability in the web UI of Cisco Cloud Web Security (CWS) could allow an authenticated, remote attacker to execute arbitrary SQL queries. The vulnerability exists because the web-based management interface improperly validates SQL values. An authenticated attacker could exploit this vulnerability sending malicious requests to the affected device. An exploit could allow the attacker to modify values on or return values from the underlying database.
CVE-2015-0674 1 Cisco 1 Cloud Web Security 2017-07-31 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the Alert Service of Cisco Cloud Web Security base revision allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.