56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Cisco vulnerabilities
6655 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1972 | MED 6.7 | cisco enterprise_network_function_virtualization_infrastructure A vulnerability the Cisco Enterprise NFV Infrastructure Software (NFVIS) restricted CLI could allow an authenticated, local attacker with valid administrator-level credentials to elevate privileges and execute arbitrary commands on the underlying operating sys | 0.5% | — |
| CVE-2024-20417 | MED 6.5 | cisco identity_services_engine Multiple vulnerabilities in the REST API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct blind SQL injection attacks. These vulnerabilities are due to insufficient validation of user-supplied input in REST AP | 0.5% | — |
| CVE-2024-20310 | MED 6.1 | cisco unified_communications_manager_im_and_presence_service A vulnerability in the web-based interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against an authenticated user of the inter | 0.5% | — |
| CVE-2021-1131 | MED 6.5 | cisco video_surveillance_8000p_ip_camera_firmware A vulnerability in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause an affected IP camera to reload. The vulnerability is due to missing checks when Cisco | 0.5% | — |
| CVE-2018-0429 | HIGH 7.8 | cisco thor_video_codec Stack-based buffer overflow in the Cisco Thor decoder before commit 18de8f9f0762c3a542b1122589edb8af859d9813 allows local users to cause a denial of service (segmentation fault) and execute arbitrary code via a crafted non-conformant Thor bitstream. | 0.5% | — |
| CVE-2021-1256 | MED 6.0 | cisco secure_firewall_threat_defense A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite files on the file system of an affected device by using directory traversal techniques. A successful exploit could cause syste | 0.5% | — |
| CVE-2007-4786 | MED 5.3 | cisco adaptive_security_appliance_software Cisco Adaptive Security Appliance (ASA) running PIX 7.0 before 7.0.7.1, 7.1 before 7.1.2.61, 7.2 before 7.2.2.34, and 8.0 before 8.0.2.11, when AAA is enabled, composes %ASA-5-111008 messages from the "test aaa" command with cleartext passwords and sends them | 0.5% | — |
| CVE-2022-20657 | MED 6.1 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco PI and Cisco EPNM could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface of an affected device. This vulnerability exists because the we | 0.5% | — |
| CVE-2022-20631 | MED 6.1 | cisco enterprise_chat_and_email A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface of an affected device. The vulnerability exists because the web-based management i | 0.5% | — |
| CVE-2023-20175 | HIGH 8.8 | cisco identity_services_engine A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an attacker must have valid | 0.5% | — |
| CVE-2016-6454 | MED 6.5 | cisco hosted_collaboration_mediation_fulfillment A cross-site request forgery (CSRF) vulnerability in the web interface of the Cisco Hosted Collaboration Mediation Fulfillment application could allow an unauthenticated, remote attacker to execute unwanted actions. More Information: CSCva54241. Known Affected | 0.5% | — |
| CVE-2024-20357 | MED 5.9 | cisco ip_phone_6821_with_multiplatform_firmware A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiate phone calls on an affected device. This vulnerability exists because bounds-checking does not occur while parsing XML requests. An at | 0.5% | — |
| CVE-2023-20167 | MED 6.0 | cisco identity_services_engine Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the underlying operating system to either elevate privileges to root or read arbitrary files. To exploit these vulnerabi | 0.5% | — |
| CVE-2023-20183 | MED 5.4 | cisco catalyst_center Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user | 0.5% | — |
| CVE-2023-20058 | MED 6.1 | cisco packaged_contact_center_enterprise A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists be | 0.5% | — |
| CVE-2022-20852 | MED 5.4 | cisco webex_meetings Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow a remote attacker to conduct a cross-site scripting (XSS) attack or a frame hijacking attack against a user of the web interface. For more information about these vulnerabilities | 0.5% | — |
| CVE-2018-0176 | HIGH 7.8 | cisco ios_xe Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device. The vulnerabi | 0.5% | — |
| CVE-2018-0169 | HIGH 7.8 | cisco ios Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device. The vulnerabi | 0.5% | — |
| CVE-2024-20482 | MED 6.5 | cisco secure_firewall_management_center A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to elevate privileges on an affected device. To exploi | 0.5% | — |
| CVE-2024-20362 | MED 6.1 | cisco rv016_firmware A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. | 0.5% | — |
| CVE-2018-0481 | MED 6.7 | cisco ios_xe A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exist because the affected software improper | 0.5% | — |
| CVE-2018-0477 | MED 6.7 | cisco ios_xe A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exist because the affected software improper | 0.5% | — |
| CVE-2022-20769 | HIGH 7.4 | cisco wireless_lan_controller_software A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insuff | 0.5% | — |
| CVE-2018-15431 | HIGH 7.3 | cisco webex_business_suite_32 A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im | 0.5% | — |
| CVE-2026-20174 | MED 4.9 | cisco nexus_dashboard A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to insufficient validation of the metadata update file. | 0.5% | — |