56.560 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
Cisco vulnerabilities
6647 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-20432 | CRIT 9.9 | cisco nexus_dashboard_fabric_controller A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device. This vulnerability is due to i | 1.1% | — |
| CVE-2022-20750 | MED 5.3 | cisco redundancy_configuration_manager A vulnerability in the checkpoint manager implementation of Cisco Redundancy Configuration Manager (RCM) for Cisco StarOS Software could allow an unauthenticated, remote attacker to cause the checkpoint manager process to restart upon receipt of malformed TCP | 1.1% | — |
| CVE-2021-1129 | MED 5.3 | cisco content_security_management_appliance A vulnerability in the authentication for the general purpose APIs implementation of Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker | 1.1% | — |
| CVE-2021-1266 | MED 4.3 | cisco managed_services_accelerator A vulnerability in the REST API of Cisco Managed Services Accelerator (MSX) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the way that the affected software logs ce | 1.1% | — |
| CVE-2015-6380 | MED 6.5 | cisco firepower_extensible_operating_system An unspecified script in the web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to execute arbitrary OS commands via crafted parameters, aka Bug ID CSCux10622. | 1.1% | — |
| CVE-2010-4679 | HIGH 7.8 | cisco 5500_series_adaptive_security_appliance Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) do not properly handle Online Certificate Status Protocol (OCSP) connection failures, which allows remote OCSP responders to cause a denial of service (TCP socket exhausti | 1.1% | — |
| CVE-2010-2082 | MED 5.0 | cisco scientific_atlanta_webstar_dpc2100r2 The web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 has a default administrative password (aka SAPassword) of W2402, which makes it easier for remote attackers to obtain privileged access. | 1.1% | — |
| CVE-2009-2046 | MED 6.8 | cisco video_surveillance_2500_series_ip_camera The embedded web server on the Cisco Video Surveillance 2500 Series IP Camera with firmware before 2.1 allows remote attackers to read arbitrary files via a (1) http or (2) https request, related to the (a) SD Camera Web Server and the (b) Wireless Camera HTTP | 1.1% | — |
| CVE-2009-1160 | MED 4.3 | cisco adaptive_security_appliance_5500 Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)1, 7.1 before 7.1(2)74, 7.2 before 7.2(4)9, and 8.0 before 8.0(4)5 do not properly implement the implicit deny statement, which might allow remote attackers to su | 1.1% | — |
| CVE-2021-1581 | MED 6.5 | cisco application_policy_infrastructure_controller Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload attack on an affected system. For more informa | 1.1% | — |
| CVE-2019-12666 | MED 6.7 | cisco ios_xe A vulnerability in the Guest Shell of Cisco IOS XE Software could allow an authenticated, local attacker to perform directory traversal on the base Linux operating system of Cisco IOS XE Software. The vulnerability is due to incomplete validation of certain co | 1.1% | — |
| CVE-2020-3410 | HIGH 8.1 | cisco secure_firewall_management_center A vulnerability in the Common Access Card (CAC) authentication feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and access the FMC system. The attacker must have a valid CAC to | 1.1% | — |
| CVE-2016-1404 | HIGH 7.5 | cisco ucs_invicta_c3124sa_appliance Cisco UCS Invicta 4.3, 4.5, and 5.0.1 on Invicta appliances and Invicta Scaling System uses the same hardcoded GnuPG encryption key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by sniffi | 1.1% | — |
| CVE-2013-5548 | MED 4.3 | cisco ios The IKEv2 implementation in Cisco IOS, when AES-GCM or AES-GMAC is used, allows remote attackers to bypass certain IPsec anti-replay features via IPsec tunnel traffic, aka Bug ID CSCuj47795. | 1.1% | — |
| CVE-2022-20737 | HIGH 8.5 | cisco adaptive_security_appliance_software A vulnerability in the handler for HTTP authentication for resources accessed through the Clientless SSL VPN portal of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition o | 1.1% | — |
| CVE-2020-3472 | MED 5.0 | cisco webex_meetings_online A vulnerability in the contacts feature of Cisco Webex Meetings could allow an authenticated, remote attacker with a legitimate user account to access sensitive information. The vulnerability is due to improper access restrictions on users who are added within | 1.1% | — |
| CVE-2018-15380 | HIGH 8.8 | cisco hyperflex_hx_data_platform A vulnerability in the cluster service manager of Cisco HyperFlex Software could allow an unauthenticated, adjacent attacker to execute commands as the root user. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnera | 1.1% | — |
| CVE-2002-1097 | HIGH 7.5 | cisco vpn_3000_concentrator_series_software Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages. | 1.1% | — |
| CVE-2021-1465 | MED 4.3 | cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a directory traversal attack and obtain read access to sensitive files on an affected system. The vulnerability is | 1.1% | — |
| CVE-2017-3798 | MED 6.1 | cisco unified_communications_manager A cross-site scripting (XSS) filter bypass vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to mount XSS attacks against a user of an affected device. More Information: | 1.1% | — |
| CVE-2022-20847 | HIGH 8.6 | cisco ios_xe A vulnerability in the DHCP processing functionality of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the improp | 1.1% | — |
| CVE-2010-3050 | MED 6.5 | cisco ios Cisco IOS before 12.2(33)SXI allows remote authenticated users to cause a denial of service (device reboot). | 1.1% | — |
| CVE-2012-5030 | MED 6.5 | cisco ios Cisco IOS before 15.2(4)S6 does not initialize an unspecified variable, which might allow remote authenticated users to cause a denial of service (CPU consumption, watchdog timeout, crash) by walking specific SNMP objects. | 1.1% | — |
| CVE-2017-3810 | MED 5.4 | cisco prime_service_catalog A vulnerability in the web framework of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a web URL redirect attack against a user who is logged in to an affected system. More Information: CSCvb21745. Known Affected Releases: | 1.1% | — |
| CVE-2017-12302 | MED 4.3 | cisco unified_communications_domain_manager A vulnerability in the Cisco Unified Communications Manager SQL database interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection. The vulnerability is due to a la | 1.1% | — |