imPC@ndo IT

Cisco vulnerabilities

6639 CVE

CVE-2022-20699
Exploited Critical 10.0

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization prot…

cisco rv340_firmware · cisco rv340w_firmware · cisco rv345_firmware · cisco rv345p_firmware
0.72EPSS
CVE-2024-20353
Exploited High 8.6

A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting i…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.71EPSS
CVE-2017-6736
Exploited High 8.8

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. …

cisco ios · cisco ios_xe
0.71EPSS
CVE-2020-3259
Ransomware High 7.5

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could l…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.69EPSS
CVE-2025-20337
Exploited Critical 10.0

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerabi…

cisco identity_services_engine · cisco identity_services_engine_passive_identity_connector
0.66EPSS
CVE-2018-0125
Exploited Critical 9.8

A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system, including issuing com…

cisco rv132w_firmware · cisco rv134w_firmware
0.55EPSS
CVE-2023-20118
Exploited Medium 6.5

A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability…

cisco rv016_firmware · cisco rv042_firmware · cisco rv042g_firmware · cisco rv082_firmware · and 2 more
0.54EPSS
CVE-2017-6737
Exploited High 8.8

A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected devi…

cisco ios · cisco ios_xe
0.43EPSS
CVE-2025-20333
Exploited Critical 9.9

A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code on an affected device. …

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.40EPSS
CVE-2015-0666
Exploited High 7.5

Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to read arbitrary files via a crafted pathname, aka Bug ID CSCus00241.

cisco prime_data_center_network_manager
0.40EPSS
CVE-2025-20352
Exploited High 7.7

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on …

cisco ios · cisco ios_xe · cisco ios_xe_sd-wan
0.39EPSS
CVE-2008-4128
Exploited Medium 4.3

Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /leve…

cisco ios
0.33EPSS
CVE-2026-20133
Exploited Medium 6.5

A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmi…

cisco catalyst_sd-wan_manager
0.31EPSS
CVE-2026-20131
Ransomware Critical 10.0

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to i…

cisco secure_firewall_management_center
0.31EPSS
CVE-2025-20393
Exploited Critical 10.0

A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root …

cisco asyncos
0.30EPSS
CVE-2026-20262
Exploited Medium 6.5

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affe…

cisco catalyst_sd-wan_manager
0.28EPSS
CVE-2020-3153
Ransomware Medium 6.5

A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the …

cisco anyconnect_secure_mobility_client
0.27EPSS
CVE-2026-20245
Exploited High 7.8

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute …

cisco catalyst_sd-wan_manager · cisco sd-wan_vsmart_controller
0.25EPSS
CVE-2026-20122
Exploited Medium 5.4

A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access o…

cisco catalyst_sd-wan_manager
0.25EPSS
CVE-2016-6367
Exploited High 7.8

Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA.

cisco adaptive_security_appliance_software
0.23EPSS
CVE-2023-20269
Ransomware Medium 5.0

A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify val…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.22EPSS
CVE-2017-6742
Exploited High 8.8

A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected devi…

cisco ios · cisco ios_xe
0.21EPSS
CVE-2024-20359
Exploited Medium 6.0

A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, l…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.19EPSS
CVE-2014-2120
Exploited Medium 6.1

Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun19025.

cisco adaptive_security_appliance_software
0.19EPSS
CVE-2018-0147
Exploited Critical 9.8

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure dese…

cisco secure_access_control_system
0.18EPSS