58.639 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync
Cisco vulnerabilities
6716 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2014-0664 | MED 6.8 | cisco unity_connection The server in Cisco Unity Connection allows remote authenticated users to cause a denial of service (CPU consumption) via unspecified IMAP commands, aka Bug ID CSCul49976. | 2.8% | — |
| CVE-2013-6982 | MED 4.3 | cisco nx-os The BGP implementation in Cisco NX-OS 6.2(2a) and earlier does not properly handle the interaction of UPDATE messages with IPv6, VPNv4, and VPNv6 labeled unicast-address families, which allows remote attackers to cause a denial of service (peer reset) via a cr | 2.8% | — |
| CVE-2015-6393 | HIGH 7.5 | cisco nx-os Cisco NX-OS 4.1 through 7.3 and 11.0 through 11.2 on Nexus 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device crash) via malformed IPv4 DHCP packets to the DHCPv4 relay agent, aka | 2.8% | — |
| CVE-2015-6392 | HIGH 7.5 | cisco nx-os Cisco NX-OS 4.1 through 7.3 and 11.0 through 11.2 on Nexus 2000, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device crash) via crafted IPv4 DHCP packets to the (1) DHCPv4 relay agent or (2) smart r | 2.8% | — |
| CVE-2007-4285 | HIGH 9.0 | cisco ios Unspecified vulnerability in Cisco IOS and Cisco IOS XR 12.x up to 12.3, including some versions before 12.3(15) and 12.3(14)T, allows remote attackers to obtain sensitive information (partial packet contents) or cause a denial of service (router or component | 2.8% | — |
| CVE-2017-12367 | CRIT 9.6 | cisco webex_meetings_server A "Cisco WebEx Network Recording Player Denial of Service Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a | 2.8% | — |
| CVE-2010-4680 | HIGH 9.0 | cisco 5500_series_adaptive_security_appliance The WebVPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) permits the viewing of CIFS shares even when CIFS file browsing has been disabled, which allows remote authenticated users to bypass intended | 2.8% | — |
| CVE-2010-4675 | HIGH 9.0 | cisco 5500_series_adaptive_security_appliance Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) do not properly determine the interfaces for which TELNET connections should be permitted, which allows remote authenticated users to bypass intended access restrictions v | 2.8% | — |
| CVE-2009-0634 | HIGH 7.1 | cisco cisco_ios Multiple unspecified vulnerabilities in the home agent (HA) implementation in the (1) Mobile IP NAT Traversal feature and (2) Mobile IPv6 subsystem in Cisco IOS 12.3 through 12.4 allow remote attackers to cause a denial of service (input queue wedge and interf | 2.8% | — |
| CVE-2014-3352 | MED 4.3 | cisco cloud_portal Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) 2008.3_SP9 and earlier does not properly consider whether a session is a problematic NULL session, which allows remote attackers to obtain sensitive information via crafted packets, related to an | 2.8% | — |
| CVE-2019-1889 | HIGH 7.2 | cisco application_policy_infrastructure_controller A vulnerability in the REST API for software device management in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an authenticated, remote attacker to escalate privileges to root on an affected device. The vulnerability is due to | 2.8% | — |
| CVE-2018-0419 | HIGH 7.5 | cisco email_security_appliance A vulnerability in certain attachment detection mechanisms of Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of an affected system. The vulnerability is due to the improper detection | 2.8% | — |
| CVE-2015-6259 | HIGH 9.4 | cisco integrated_management_controller_supervisor The JavaServer Pages (JSP) component in Cisco Integrated Management Controller (IMC) Supervisor before 1.0.0.1 and UCS Director (formerly Cloupia Unified Infrastructure Controller) before 5.2.0.1 allows remote attackers to write to arbitrary files via crafted | 2.8% | — |
| CVE-2019-1634 | HIGH 7.2 | cisco integrated_management_controller_supervisor A vulnerability in the Intelligent Platform Management Interface (IPMI) of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on the underlying operatin | 2.8% | — |
| CVE-2017-3812 | MED 6.8 | cisco industrial_ethernet_2000_series_firmware A vulnerability in the implementation of Common Industrial Protocol (CIP) functionality in Cisco Industrial Ethernet 2000 Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to a system memory leak. | 2.8% | — |
| CVE-2017-3820 | MED 6.5 | cisco ios_xe A vulnerability in Simple Network Management Protocol (SNMP) functions of Cisco ASR 1000 Series Aggregation Services Routers running Cisco IOS XE Software Release 3.13.6S, 3.16.2S, or 3.17.1S could allow an authenticated, remote attacker to cause high CPU usag | 2.8% | — |
| CVE-2016-1297 | HIGH 8.8 | cisco application_control_engine_software The Device Manager GUI in Cisco Application Control Engine (ACE) 4710 A5 before A5(3.1) allows remote authenticated users to bypass intended RBAC restrictions and execute arbitrary CLI commands with admin privileges via an unspecified parameter in a POST reque | 2.8% | — |
| CVE-2020-3279 | HIGH 7.2 | cisco rv016_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execu | 2.8% | — |
| CVE-2020-3278 | HIGH 7.2 | cisco rv016_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execu | 2.8% | — |
| CVE-2020-3277 | HIGH 7.2 | cisco rv016_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execu | 2.8% | — |
| CVE-2020-3276 | HIGH 7.2 | cisco rv016_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execu | 2.8% | — |
| CVE-2020-3275 | HIGH 7.2 | cisco rv016_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execu | 2.8% | — |
| CVE-2020-3274 | HIGH 7.2 | cisco rv016_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execu | 2.8% | — |
| CVE-2020-3177 | HIGH 7.5 | cisco unified_communications_manager A vulnerability in the Tool for Auto-Registered Phones Support (TAPS) of Cisco Unified Communications Manager (UCM) and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct directory t | 2.8% | — |
| CVE-2001-0163 | MED 4.6 | cisco aironet_ap340 Cisco AP340 base station produces predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections. | 2.8% | — |