56.560 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
Cisco vulnerabilities
6647 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-20135 | MED 5.7 | cisco ios_xr A vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. This vulnerability is due to a time-of-check, time-of-use (TOCTOU) race condition w | 0.1% | — |
| CVE-2023-20236 | MED 6.7 | cisco ios_xr A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to install an unverified software image on an affected device. This vulnerability is due to insufficient image verification. An attacker could ex | 0.1% | — |
| CVE-2025-20119 | MED 6.0 | cisco application_policy_infrastructure_controller A vulnerability in the system file permission handling of Cisco APIC could allow an authenticated, local attacker to overwrite critical system files, which could cause a DoS condition. To exploit this vulnerability, the attacker must have valid administrative | 0.1% | — |
| CVE-2026-20064 | MED 6.5 | cisco secure_firewall_threat_defense A vulnerability in of Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to cause the device to unexpectedly reload, causing a denial of service (DoS) condition. This vulnerability is due to improper validation | 0.1% | — |
| CVE-2026-20157 | HIGH 7.5 | cisco roomos As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally d | 0.1% | — |
| CVE-2024-20309 | MED 5.6 | cisco ios_xe A vulnerability in auxiliary asynchronous port (AUX) functions of Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload or stop responding. This vulnerability is due to the incorrect handling of specific in | 0.1% | — |
| CVE-2026-20246 | MED 6.0 | cisco umbrella_virtual_appliance A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied commands. An attacker with | 0.1% | — |
| CVE-2024-20503 | MED 5.5 | cisco duo_authentication_for_epic A vulnerability in Cisco Duo Epic for Hyperdrive could allow an authenticated, local attacker to view sensitive information in cleartext on an affected system. This vulnerability is due to improper storage of an unencrypted registry key. A low-privileged at | 0.1% | — |
| CVE-2025-20143 | MED 6.7 | cisco ios_xr A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Secure Boot functionality and load unverified software on an affected device. To exploit this vulnerability, the attack | 0.1% | — |
| CVE-2024-20292 | MED 4.4 | cisco duo_authentication_for_windows_logon_and_rdp A vulnerability in the logging component of Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, local attacker to view sensitive information in clear text on an affected system. This vulnerability is due to improper storage of | 0.1% | — |
| CVE-2023-20016 | MED 6.3 | cisco fxos A vulnerability in the backup configuration feature of Cisco UCS Manager Software and in the configuration export feature of Cisco FXOS Software could allow an unauthenticated attacker with access to a backup file to decrypt sensitive information stored in the | 0.1% | — |
| CVE-2024-20280 | MED 6.3 | cisco ucs_central_software A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files. This vulnerability is due to a weakness | 0.1% | — |
| CVE-2024-20448 | MED 6.3 | cisco nexus_dashboard_fabric_controller A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco Data Center Network Manager (DCNM), could allow an attacker with access to a backup file to view sensitive information. This vulnerability is due to the improper | 0.1% | — |
| CVE-2026-20008 | MED 6.0 | cisco adaptive_security_appliance_software A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to craft Lua code that coul | 0.1% | — |
| CVE-2026-20046 | HIGH 8.8 | cisco ios_xr A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges and gain full administrative control of an affected device. This vulnerability is due to incorrec | 0.1% | — |
| CVE-2024-20343 | MED 5.5 | cisco ios_xr A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to read any file in the file system of the underlying Linux operating system. The attacker must have valid credentials on the affected device. This vulnerabilit | 0.1% | — |
| CVE-2025-20259 | MED 5.3 | cisco thousandeyes_endpoint_agent Multiple vulnerabilities in the update process of Cisco ThousandEyes Endpoint Agent for Windows could allow an authenticated, local attacker to delete arbitrary files on an affected device. These vulnerabilities are due to improper access controls on files | 0.1% | — |
| CVE-2024-20325 | MED 5.1 | cisco unified_intelligence_center A vulnerability in the Live Data server of Cisco Unified Intelligence Center could allow an unauthenticated, local attacker to read and modify data in a repository that belongs to an internal service on an affected device. This vulnerability is due to insuf | 0.1% | — |
| CVE-2023-20044 | MED 6.7 | cisco cx_cloud_agent A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. This vulnerability is due to insecure file permissions. An attacker could exploit this vulnerability by persuading support to update setting | 0.1% | — |
| CVE-2024-20489 | HIGH 8.4 | cisco ios_xr A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB credentials. This vulnerability is due to improper storage of the unencrypted database cred | 0.1% | — |
| CVE-2024-20394 | MED 5.5 | cisco appdynamics A vulnerability in Cisco AppDynamics Network Visibility Agent could allow an unauthenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the inability to handle unexpected input. An attack | 0.1% | — |
| CVE-2025-20277 | LOW 3.4 | cisco unified_contact_center_express A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, local attacker to execute arbitrary code on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. | 0.1% | — |
| CVE-2024-20324 | MED 5.5 | cisco ios_xe A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, low-privileged, local attacker to access WLAN configuration details including passwords. This vulnerability is due to improper privilege checks. An attacker could exploit this | 0.1% | — |
| CVE-2020-3483 | HIGH 7.1 | cisco duo_network_gateway Duo has identified and fixed an issue with the Duo Network Gateway (DNG) product in which some customer-provided SSL certificates and private keys were not excluded from logging. This issue resulted in certificate and private key information being written out | 0.1% | — |
| CVE-2019-1589 | MED 4.6 | cisco nx-os A vulnerability in the Trusted Platform Module (TPM) functionality of software for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, local attacker with physical access to view sensitive in | 0.1% | — |