56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Cisco vulnerabilities
6655 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-20518 | MED 6.5 | cisco rv042_firmware A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to execute arbitrary code as the root user. To exploit this vulnerability, | 0.6% | — |
| CVE-2021-1250 | MED 6.5 | cisco data_center_network_manager Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack a | 0.6% | — |
| CVE-2021-1249 | MED 6.5 | cisco data_center_network_manager Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack a | 0.6% | — |
| CVE-2021-1253 | MED 6.5 | cisco data_center_network_manager Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack a | 0.6% | — |
| CVE-2021-1127 | MED 5.4 | cisco enterprise_nfv_infrastructure_software A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The | 0.6% | — |
| CVE-2023-20018 | HIGH 8.6 | cisco ip_phone_7800_firmware A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker to bypass authentication on an affected device. This vulnerability is due to insufficient validation of user- | 0.6% | — |
| CVE-2013-6705 | MED 6.1 | cisco ios The IP Device Tracking (IPDT) feature in Cisco IOS and IOS XE allows remote attackers to cause a denial of service (IPDT AVL corruption and device reload) via a crafted sequence of ARP packets, aka Bug ID CSCuh38133. | 0.6% | — |
| CVE-2023-20259 | HIGH 8.6 | cisco emergency_responder A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attacker to cause high CPU utilization, which could impact access to the web-based management interface and cause delays with call proce | 0.6% | — |
| CVE-2020-3207 | MED 6.7 | cisco ios_xe A vulnerability in the processing of boot options of specific Cisco IOS XE Software switches could allow an authenticated, local attacker with root shell access to the underlying operating system (OS) to conduct a command injection attack during device boot. T | 0.6% | — |
| CVE-2013-3068 | MED 6.8 | cisco linksys_wrt310n_router_firmware Cross-site request forgery (CSRF) vulnerability in apply.cgi in Linksys WRT310Nv2 2.0.0.1 allows remote attackers to hijack the authentication of administrators for requests that change passwords and modify remote management ports. | 0.6% | — |
| CVE-2021-34764 | MED 4.8 | cisco firepower_management_center_virtual_appliance Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabiliti | 0.6% | — |
| CVE-2019-1649 | MED 6.7 | cisco 15454-m-wse-k9_firmware A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability af | 0.6% | — |
| CVE-2023-20254 | HIGH 7.2 | cisco sd-wan_manager A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow an authenticated, remote attacker to access another tenant that is being managed by the same Cisco Catalyst SD-WAN Manager instance. This vul | 0.6% | — |
| CVE-2024-20528 | LOW 3.8 | cisco identity_services_engine A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to upload files to arbitrary locations on the underlying operating system of an affected device. To exploit this vulnerability, an attacker would need valid Super Admin | 0.6% | — |
| CVE-2012-4072 | MED 4.3 | cisco unified_computing_system The KVM subsystem in Cisco Unified Computing System (UCS) relies on a hardcoded X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers, and read keyboard and mouse events, by leveraging knowledge of this certificate's private key, aka | 0.6% | — |
| CVE-2021-1482 | MED 6.4 | cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization checking and gain access to sensitive information on an affected system. This vulnerability is du | 0.6% | — |
| CVE-2017-12279 | MED 4.3 | cisco aironet_ap_firmware A vulnerability in the packet processing code of Cisco IOS Software for Cisco Aironet Access Points could allow an unauthenticated, adjacent attacker to retrieve content from memory on an affected device, which could lead to the disclosure of confidential info | 0.6% | — |
| CVE-2022-20965 | MED 4.3 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to take privileges actions within the web-based management interface. This vulnerability is due to improper access control | 0.6% | — |
| CVE-2017-9489 | HIGH 8.8 | cisco dpc3939b_firmware The Comcast firmware on Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST) devices allows configuration changes via CSRF. | 0.6% | — |
| CVE-2019-1846 | HIGH 7.4 | cisco ios_xr A vulnerability in the Multiprotocol Label Switching (MPLS) Operations, Administration, and Maintenance (OAM) implementation of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to tr | 0.6% | — |
| CVE-2019-1749 | HIGH 7.4 | cisco ios_xe A vulnerability in the ingress traffic validation of Cisco IOS XE Software for Cisco Aggregation Services Router (ASR) 900 Route Switch Processor 3 (RSP3) could allow an unauthenticated, adjacent attacker to trigger a reload of an affected device, resulting in | 0.6% | — |
| CVE-2023-20116 | MED 6.8 | cisco unified_communications_manager A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a d | 0.6% | — |
| CVE-2005-4825 | MED 5.7 | cisco network_admission_control_manager_and_server_system_software Cisco Clean Access 3.5.5 and earlier on the Secure Smart Manager allows remote attackers to bypass authentication and cause a denial of service (disk consumption), or make unauthorized files accessible, by uploading files through requests to certain JSP script | 0.6% | — |
| CVE-2024-20255 | HIGH 8.2 | cisco expressway A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is d | 0.6% | — |
| CVE-2018-0249 | MED 4.3 | cisco aironet_access_point_software A vulnerability when handling incoming 802.11 Association Requests for Cisco Aironet 1800 Series Access Point (APs) on Qualcomm Atheros (QCA) based hardware platforms could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) conditio | 0.6% | — |