imPC@ndo IT

Cisco vulnerabilities

6639 CVE

CVE-2013-3568
High 8.8

Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.

cisco linksys_wrt110_firmware
0.25EPSS
CVE-2019-1914
High 7.2

A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability is due to insufficient validation of user-supplied input. A…

cisco sf-220-24_firmware · cisco sf220-24p_firmware · cisco sf220-48_firmware · cisco sf220-48p_firmware · and 7 more
0.25EPSS
CVE-2011-1610
Medium 6.4

Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5)su4, 8.0 before 8.0(3a)su2, and 8.5 befo…

cisco unified_communications_manager
0.25EPSS
CVE-2006-3101
Medium 4.3

Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco Secure ACS for UNIX 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error, (2) SSL, and (3) Ok parameters.

cisco secure_access_control_server
0.24EPSS
CVE-2012-1337
High 9.3

Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP10, and T27 LD before SP32 CP1 allows remote attackers to execute arbitrary code via a crafted WRF file, a different vulner…

cisco webex_recording_format_player
0.24EPSS
CVE-2013-5528
Medium 4.0

Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to read arbitrary files via directory traversal sequences in an unspecified input string, aka Bug ID CSCui788…

cisco unified_communications_manager
0.23EPSS
CVE-2009-1287
Medium 4.3

Cross-site scripting (XSS) vulnerability in Cisco Subscriber Edge Services Manager (SESM) allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: some of these details are obtained from third party information.

cisco subscriber_edge_services_manager
0.23EPSS
CVE-2020-3249
High 7.5

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulne…

cisco ucs_director · cisco ucs_director_express_for_big_data
0.23EPSS
CVE-2024-20404
High 7.2

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an affected system. This vulnerability is due to insufficient validation of user-supplied input for specific …

cisco finesse
0.23EPSS
CVE-2014-3300
High 7.5

The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 10 does not properly implement access control, which allows remote attackers to modify user information via a crafted URL, a…

cisco unified_cdm_application_software · cisco unified_communications_domain_manager
0.22EPSS
CVE-2011-3305
High 7.8

Directory traversal vulnerability in Cisco Network Admission Control (NAC) Manager 4.8.x allows remote attackers to read arbitrary files via crafted traffic to TCP port 443, aka Bug ID CSCtq10755.

cisco nac_manager
0.22EPSS
CVE-2011-0959
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to inject arbitrary web script or HTML via (1) the extn parameter to iptm/advancedfind.do, (2) the deviceInstanceName parameter to …

cisco unified_operations_manager
0.21EPSS
CVE-2020-16138
High 7.5

A denial-of-service issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to remotely disable the device until it is power cycled. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, this CVE i…

cisco unified_ip_conference_station_7937g_firmware
0.21EPSS
CVE-2008-1157
High 10.0

Cisco CiscoWorks Internetwork Performance Monitor (IPM) 2.6 creates a process that executes a command shell and listens on a randomly chosen TCP port, which allows remote attackers to execute arbitrary commands.

cisco ciscoworks_internetwork_performance_monitor
0.21EPSS
CVE-2021-1585
High 7.5

A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a user's operating system. This vulnerability is due to a lack of proper signature verification for speci…

cisco adaptive_security_device_manager
0.20EPSS
CVE-2022-20695
Critical 10.0

A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication controls and log in to the device through the management interface This vulnerability i…

cisco wireless_lan_controller_8.10.151.0 · cisco wireless_lan_controller_8.10.162.0
0.20EPSS
CVE-2011-1609
High 8.5

SQL injection vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5)su1, 8.0 before 8.0(3), and 8.5 before 8.5(1) allows remote authenticated users to execute arbitrary SQL commands via un…

cisco unified_communications_manager
0.20EPSS
CVE-2011-0364
High 10.0

The Management Console (webagent.exe) in Cisco Security Agent 5.1, 5.2, and 6.0 before 6.0.2.145 allows remote attackers to create arbitrary files and execute arbitrary code via unspecified parameters in a crafted st_upload request.

cisco security_agent
0.20EPSS
CVE-2007-4286
High 9.3

Buffer overflow in the Next Hop Resolution Protocol (NHRP) functionality in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (restart) and execute arbitrary code via a crafted NHRP packet.

cisco ios
0.19EPSS
CVE-2020-16137
Critical 9.8

A privilege escalation issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to reset the credentials for the SSH administrative console to arbitrary values. Note: We cannot prove this vulnerability exists. Out of an abund…

cisco unified_ip_conference_station_7937g_firmware
0.19EPSS
CVE-2025-20124
Critical 9.9

A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands as the root user on an affected device. This vulnerability is due to insecure deserialization of user-supplied Java byte streams by the affect…

cisco identity_services_engine
0.18EPSS
CVE-2005-3774
Medium 5.0

Cisco PIX 6.3 and 7.0 allows remote attackers to cause a denial of service (blocked new connections) via spoofed TCP packets that cause the PIX to create embryonic connections that that would not produce a valid connection with the end system, including (1) SY…

cisco pix
0.18EPSS
CVE-2019-12624
High 8.8

A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected d…

cisco ios_xe
0.18EPSS
CVE-2018-0301
Critical 9.8

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to craft a packet to the management interface on an affected system, causing a buffer overflow. The vulnerability is due to incorrect input validation…

cisco nx-os
0.18EPSS
CVE-2021-34746
Critical 9.8

A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and log in to an affected device as an ad…

cisco enterprise_nfv_infrastructure_software
0.18EPSS