imPC@ndo IT

Cisco vulnerabilities

6639 CVE

CVE-2021-1435
High 7.2

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to inject arbitrary commands that can be executed as the root user. This vulnerability is due to insufficient input validation. An attacker could exploit this …

cisco ios_xe
0.08EPSS
CVE-2017-6637
Medium 6.5

A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticated, remote attacker to delete any file from an affected system. The vulnerability exists because the affected software doe…

cisco prime_collaboration_provisioning
0.08EPSS
CVE-2006-4776
High 7.5

Heap-based buffer overflow in the VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(19) allows remote attackers to execute arbitrary code via a long VLAN name in a VTP type 2 summary advertisement.

cisco ios
0.08EPSS
CVE-2018-0315
Critical 9.8

A vulnerability in the authentication, authorization, and accounting (AAA) security services of Cisco IOS XE Software could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device or cause an affected device to reload, resulti…

cisco ios_xe
0.08EPSS
CVE-2015-6401
High 7.5

Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allow remote attackers to bypass an intended authentication requirement and execute unspecified administrative functions via a crafted HTTP request, aka Bug ID CSCux24941.

cisco epc3928_docsis_3.0_8x4_wireless_residential_gateway_with_embedded_digital_voice_adapter
0.08EPSS
CVE-2010-0642
Medium 5.0

Cisco Collaboration Server (CCS) 5 allows remote attackers to read the source code of JHTML files via URL encoded characters in the filename extension, as demonstrated by (1) changing .jhtml to %2Ejhtml, (2) changing .jhtml to .jhtm%6C, (3) appending %00 after…

cisco collaboration_server
0.08EPSS
CVE-2025-20363
Critical 9.0

A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, r…

cisco adaptive_security_appliance_software · cisco ios · cisco ios_xe · cisco ios_xr · and 1 more
0.08EPSS
CVE-2009-1557
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allow remote attackers to inject arbitrary web script or HTML via the next_file parameter to (1) main.cgi, (2) img/main.cg…

cisco wvc54gca
0.07EPSS
CVE-2016-1429
High 7.5

Directory traversal vulnerability in the web interface on Cisco RV180 and RV180W devices allows remote attackers to read arbitrary files via a crafted HTTP request, aka Bug ID CSCuz43023.

cisco rv180_vpn_router_firmware · cisco rv180w_wireless-n_multifunction_vpn_router_firmware
0.07EPSS
CVE-2018-0300
High 7.2

A vulnerability in the process of uploading new application images to Cisco FXOS on the Cisco Firepower 4100 Series Next-Generation Firewall (NGFW) and Firepower 9300 Security Appliance could allow an authenticated, remote attacker using path traversal techniq…

cisco fxos
0.07EPSS
CVE-2004-0081
Medium 5.0

OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.

4d webstar · apple mac_os_x · apple mac_os_x_server · avaya converged_communications_server · and 62 more
0.07EPSS
CVE-2024-20450
Critical 9.8

Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying oper…

cisco spa_301_firmware · cisco spa_303_firmware · cisco spa_501g_firmware · cisco spa_502g_firmware · and 7 more
0.07EPSS
CVE-2015-6402
Medium 4.3

Cross-site scripting (XSS) vulnerability in the management interface on Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCux24935.

cisco epc3928_docsis_3.0_8x4_wireless_residential_gateway_with_embedded_digital_voice_adapter
0.07EPSS
CVE-2005-3481
High 9.3

Cisco IOS 12.0 to 12.4 might allow remote attackers to execute arbitrary code via a heap-based buffer overflow in system timers. NOTE: this issue does not correspond to a specific vulnerability, rather a general weakness that only increases the feasibility of …

cisco ios
0.07EPSS
CVE-2017-11502
Critical 9.8

Technicolor DPC3928AD DOCSIS devices allow remote attackers to read arbitrary files via a request starting with "GET /../" on TCP port 4321.

cisco dpc3928ad_docsis_wireless_router_firmware
0.07EPSS
CVE-2000-1022
High 7.5

The mailguard feature in Cisco Secure PIX Firewall 5.2(2) and earlier does not properly restrict access to SMTP commands, which allows remote attackers to execute restricted commands by sending a DATA command before sending the restricted commands.

cisco pix_firewall_software
0.07EPSS
CVE-2020-3383
High 8.8

A vulnerability in the archive utility of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability is due to a lack of proper input validation of path…

cisco data_center_network_manager
0.07EPSS
CVE-2022-20785
High 7.5

On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in HTML file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.…

cisco secure_endpoint · clamav clamav · debian debian_linux · fedoraproject fedora
0.07EPSS
CVE-2023-20052
Medium 5.3

On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote att…

cisco secure_endpoint · cisco secure_endpoint_private_cloud · clamav clamav · stormshield stormshield_network_security
0.07EPSS
CVE-2018-0253
Critical 9.8

A vulnerability in the ACS Report component of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected system. Commands executed by the attacker are processed at the targeted user's …

cisco secure_access_control_system
0.07EPSS
CVE-2022-20770
High 8.6

On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in CHM file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.1…

cisco secure_endpoint · clamav clamav · debian debian_linux · fedoraproject fedora
0.07EPSS
CVE-2014-3306
High 10.0

The web server on Cisco DPC3010, DPC3212, DPC3825, DPC3925, DPQ3925, EPC3010, EPC3212, EPC3825, and EPC3925 Wireless Residential Gateway products allows remote attackers to execute arbitrary code via a crafted HTTP request, aka Bug ID CSCup40808.

cisco dpc3010 · cisco dpc3212 · cisco dpc3825 · cisco dpc3925 · and 5 more
0.07EPSS
CVE-2020-3280
Critical 9.8

A vulnerability in the Java Remote Management Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to insecure deserialization …

cisco unified_contact_center_express
0.07EPSS
CVE-2026-20148
Medium 4.9

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system and read arbitrary files. To exploit this vulnerability, the attacker must have valid administrati…

cisco identity_services_engine · cisco identity_services_engine_passive_identity_connector
0.07EPSS
CVE-2008-6280
Medium 4.3

Cross-site scripting (XSS) vulnerability in apply.cgi on the Linksys WRT160N allows remote attackers to inject arbitrary web script or HTML via the action parameter in a DHCP_Static operation.

cisco wrt160n
0.07EPSS