56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Cisco vulnerabilities
6655 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2011-2569 | MED 6.8 | cisco nx-os Cisco Nexus OS (aka NX-OS) 4.2 and 5.0 and Cisco Unified Computing System with software 1.4 and 2.0 do not properly restrict command-line options, which allows local users to gain privileges via unspecified vectors, aka Bug IDs CSCtf40008, CSCtg18363, CSCtr446 | 0.3% | — |
| CVE-2006-5394 | LOW 2.1 | cisco secure_desktop The default configuration of Cisco Secure Desktop (CSD) has an unchecked "Disable printing" box in Secure Desktop Settings, which might allow local users to read data that was sent to a printer during another user's SSL VPN session. | 0.3% | — |
| CVE-2021-1536 | MED 4.8 | cisco webex_meetings_desktop A vulnerability in Cisco Webex Meetings Desktop App for Windows, Cisco Webex Meetings Server, Cisco Webex Network Recording Player for Windows, and Cisco Webex Teams for Windows could allow an authenticated, local attacker to perform a DLL injection attack on | 0.3% | — |
| CVE-2020-3541 | MED 4.4 | cisco webex_meetings A vulnerability in the media engine component of Cisco Webex Meetings Client for Windows, Cisco Webex Meetings Desktop App for Windows, and Cisco Webex Teams for Windows could allow an authenticated, local attacker to gain access to sensitive information. The | 0.3% | — |
| CVE-2017-12315 | MED 6.0 | cisco hyperflex_hx_data_platform A vulnerability in system logging when replication is being configured with the Cisco HyperFlex System could allow an authenticated, local attacker to view sensitive information that should be restricted in the system log files. The attacker would have to be a | 0.3% | — |
| CVE-2016-6470 | HIGH 7.8 | cisco hybrid_media_service A vulnerability in the installation procedure of the Cisco Hybrid Media Service could allow an authenticated, local attacker to elevate privileges to the root level. More Information: CSCvb81344. Known Affected Releases: 1.0. | 0.3% | — |
| CVE-2013-1172 | MED 6.6 | cisco anyconnect_secure_mobility_client The Cisco Security Service in Cisco AnyConnect Secure Mobility Client (aka AnyConnect VPN Client) does not properly verify files, which allows local users to gain privileges via unspecified vectors, aka Bug ID CSCud14153. | 0.3% | — |
| CVE-2002-0225 | MED 4.6 | cisco tacacs\+ tac_plus Tacacs+ daemon F4.0.4.alpha, originally maintained by Cisco, creates files from the accounting directive with world-readable and writable permissions, which allows local users to access and modify sensitive files. | 0.3% | — |
| CVE-2023-20221 | MED 6.5 | cisco ip_conference_phone_7832_with_multiplatform_firmware A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-base | 0.3% | — |
| CVE-2021-1558 | MED 6.0 | cisco dna_spaces\ Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. These vulnerabilities are due to insufficient restrictions duri | 0.3% | — |
| CVE-2021-1557 | MED 6.0 | cisco dna_spaces\ Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. These vulnerabilities are due to insufficient restrictions duri | 0.3% | — |
| CVE-2021-1514 | HIGH 7.8 | cisco catalyst_sd-wan_manager A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with Administrator privileges on the underlying operating system. This vulnerability is due to insufficient input valid | 0.3% | — |
| CVE-2020-27129 | MED 6.7 | cisco sd-wan_vmanage A vulnerability in the remote management feature of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to inject arbitrary commands and potentially gain elevated privileges. The vulnerability is due to improper validation of commands to | 0.3% | — |
| CVE-2017-12332 | MED 4.4 | cisco nx-os A vulnerability in Cisco NX-OS System Software patch installation could allow an authenticated, local attacker to write a file to arbitrary locations. The vulnerability is due to insufficient restrictions in the patch installation process. An attacker could ex | 0.3% | — |
| CVE-2015-0755 | MED 6.8 | cisco anyconnect_secure_mobility_client The Posture module for Cisco Identity Services Engine (ISE), as distributed in Cisco AnyConnect Secure Mobility Client 4.0(64), allows local users to gain privileges via unspecified commands, aka Bug ID CSCut05797. | 0.3% | — |
| CVE-2020-3477 | MED 5.5 | cisco ios A vulnerability in the CLI parser of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to access files from the flash: filesystem. The vulnerability is due to insufficient application of restrictions during the execution | 0.3% | — |
| CVE-2020-3396 | MED 6.8 | cisco ios_xe A vulnerability in the file system on the pluggable USB 3.0 Solid State Drive (SSD) for Cisco IOS XE Software could allow an authenticated, physical attacker to remove the USB 3.0 SSD and modify sensitive areas of the file system, including the namespace conta | 0.3% | — |
| CVE-2020-3394 | HIGH 7.8 | cisco nx-os A vulnerability in the Enable Secret feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, local attacker to issue the enable command and get full administrative privileges. To e | 0.3% | — |
| CVE-2025-20288 | MED 5.8 | cisco unified_contact_center_express A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improp | 0.3% | — |
| CVE-2025-20214 | MED 4.3 | cisco ios_xe A vulnerability in the Network Configuration Access Control Module (NACM) of Cisco IOS XE Software could allow an authenticated, remote attacker to obtain unauthorized read access to configuration or operational data. This vulnerability exists because a sub | 0.3% | — |
| CVE-2017-6666 | MED 6.0 | cisco ios_xr A vulnerability in the forwarding component of Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series Routers could allow an authenticated, local attacker to cause the router to stop forwarding data traffic across Traffic Engineering (TE) | 0.3% | — |
| CVE-2015-0584 | HIGH 7.2 | cisco desktop_collaboration_experience_dx650 The image-upgrade implementation on Cisco Desktop Collaboration Experience (aka Collaboration Desk Experience or DX) DX650 endpoints allows local users to execute arbitrary OS commands via an unspecified parameter, aka Bug ID CSCus38947. | 0.3% | — |
| CVE-2007-1072 | HIGH 7.2 | cisco unified_ip_phone_firmware_7906g The command line interface (CLI) in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier allows local users to obtain privileges or cause a denial of service via unspecified vectors. NOTE: this issue can be | 0.3% | — |
| CVE-2024-20497 | MED 4.3 | cisco expressway-e A vulnerability in Cisco Expressway Edge (Expressway-E) could allow an authenticated, remote attacker to masquerade as another user on an affected system. This vulnerability is due to inadequate authorization checks for Mobile and Remote Access (MRA) users. | 0.3% | — |
| CVE-2024-20303 | HIGH 7.4 | cisco ios_xe A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper ma | 0.3% | — |