IT

Cisco vulnerabilities

6647 CVE

CVE-2018-0206
Medium 6.1

A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an af…

cisco unified_communications_manager
0.01EPSS
CVE-2018-0205
Medium 6.1

A vulnerability in the User Provisioning tab in the Cisco Prime Collaboration Provisioning Tool could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. The vulnerability is due to improper input validation. An attacker c…

cisco prime_collaboration_provisioning
0.01EPSS
CVE-2018-0200
Medium 6.1

A vulnerability in the web-based interface of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based interface of an affected product. The vulnerabili…

cisco prime_service_catalog
0.01EPSS
CVE-2018-0093
Medium 6.1

A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affe…

cisco web_security_appliance
0.01EPSS
CVE-2018-0091
Medium 6.1

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a Document Object Model (DOM) cross-site scripting (XSS) attack against a user of the web-based management …

cisco identity_services_engine
0.01EPSS
CVE-2017-12366
Medium 6.1

A vulnerability in Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected system. The vulnerability is due to insufficient input validation of some parameters that…

cisco webex_meeting_center
0.01EPSS
CVE-2017-12356
Medium 6.1

A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an a…

cisco jabber
0.01EPSS
CVE-2017-12304
Medium 6.1

A vulnerability in the IOS daemon (IOSd) web-based management interface of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface on an a…

cisco ios
0.01EPSS
CVE-2017-12298
Medium 6.1

A vulnerability in Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected system. The vulnerability is due to insufficient input validation of some parameters that…

cisco webex_meeting_center
0.01EPSS
CVE-2017-12296
Medium 6.1

A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected system. The vulnerability is due to insufficient input validation of some parameters th…

cisco webex_meetings_server
0.01EPSS
CVE-2017-12288
Medium 6.1

A vulnerability in the web-based management interface of Cisco Unified Contact Center Express could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected device. The vulnerability is due to insuf…

cisco finesse
0.01EPSS
CVE-2017-12272
Medium 6.1

A vulnerability in the web framework code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected software. The vulnerability is due to insuffic…

cisco ios_xe
0.01EPSS
CVE-2017-12265
Medium 6.1

A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an …

cisco adaptive_security_appliance
0.01EPSS
CVE-2017-6788
Medium 6.1

The WebLaunch functionality of Cisco AnyConnect Secure Mobility Client Software contains a vulnerability that could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected software. The vulnerabil…

cisco anyconnect_secure_mobility_client
0.01EPSS
CVE-2016-1438
High 7.5

Cisco AsyncOS 9.7.0-125 on Email Security Appliance (ESA) devices allows remote attackers to bypass intended spam filtering via crafted executable content in a ZIP archive, aka Bug ID CSCuy39210.

cisco asyncos
0.01EPSS
CVE-2021-1535
Medium 5.3

A vulnerability in the cluster management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. To be affected by this vulnerability, the Cisco SD-WAN vManage Software mu…

cisco sd-wan_vmanage
0.01EPSS
CVE-2020-3461
Medium 5.3

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. The vulnerability is due to missing authentication on …

cisco data_center_network_manager
0.01EPSS
CVE-2018-0109
Low 2.7

A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to access sensitive data about the application. An attacker could exploit this vulnerability to obtain information to conduct additional reconnaissance attacks. The vu…

cisco webex_meetings_server
0.01EPSS
CVE-2015-0712
Medium 5.0

The session-manager service in Cisco StarOS 12.0, 12.2(300), 14.0, and 14.0(600) on ASR 5000 devices allows remote attackers to cause a denial of service (service reload and packet loss) via malformed HTTP packets, aka Bug ID CSCud14217.

cisco staros
0.01EPSS
CVE-2015-0657
Medium 5.0

Cisco IOS XR allows remote attackers to cause a denial of service (RSVP process reload) via a malformed RSVP packet, aka Bug ID CSCur69192.

cisco ios_xr
0.01EPSS
CVE-2015-0605
Medium 4.3

The uuencode inspection engine in Cisco AsyncOS on Cisco Email Security Appliance (ESA) devices 8.5 and earlier allows remote attackers to bypass intended content restrictions via a crafted e-mail attachment with uuencode encoding, aka Bug ID CSCzv54343.

cisco asyncos
0.01EPSS
CVE-2014-8014
Medium 5.0

Cisco IOS XR allows remote attackers to cause a denial of service (RSVP process reload) via a malformed RSVP packet, aka Bug ID CSCub63710.

cisco ios_xr
0.01EPSS
CVE-2014-3268
Medium 5.0

Cisco IOS 15.2(4)M4 on Cisco Unified Border Element (CUBE) devices allows remote attackers to cause a denial of service (input-queue consumption and traffic-processing outage) via crafted RTCP packets, aka Bug ID CSCuj72215.

cisco ios · cisco unified_border_element
0.01EPSS
CVE-2012-4079
Medium 5.0

The XML API service in the Fabric Interconnect component in Cisco Unified Computing System (UCS) allows remote attackers to cause a denial of service (API service outage) via a malformed XML document in a packet, aka Bug ID CSCtg48206.

cisco unified_computing_system
0.01EPSS
CVE-2012-3919
Medium 5.0

The Cisco Application Control Engine (ACE) module 3.0 for Cisco Catalyst switches and Cisco routers does not properly monitor Load Balancer (LB) queues, which allows remote attackers to cause a denial of service (incorrect memory access and module reboot) via …

cisco application_control_engine_module
0.01EPSS