imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2023-44487
Sfruttata Alta 7.5

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

akka http_server · amazon opensearch_data_prepper · apache apisix · apache solr · e altri 161
1.00EPSS
CVE-2021-44228
Ransomware Critica 10.0

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who c…

apache log4j · apple xcode · bentley synchro · bentley synchro_4d · e altri 139
1.00EPSS
CVE-2021-1498
Sfruttata Critica 9.8

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Deta…

cisco hyperflex_hx_data_platform
1.00EPSS
CVE-2020-3452
Sfruttata Alta 7.5

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files …

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
1.00EPSS
CVE-2021-1497
Sfruttata Critica 9.8

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Deta…

cisco hyperflex_hx_data_platform
1.00EPSS
CVE-2018-0296
Sfruttata Alta 7.5

A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on cer…

cisco adaptive_security_appliance_software · cisco firepower_threat_defense · cisco secure_firewall_threat_defense
1.00EPSS
CVE-2019-1653
Sfruttata Alta 7.5

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to improper access controls f…

cisco rv320_firmware · cisco rv325_firmware
1.00EPSS
CVE-2022-22965
Sfruttata Critica 9.8

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot …

cisco cx_cloud_agent · oracle commerce_platform · oracle communications_cloud_native_core_automated_test_suite · oracle communications_cloud_native_core_binding_support_function · e altri 34
1.00EPSS
CVE-2023-20198
Sfruttata Critica 10.0

Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors e…

cisco ios_xe · rockwellautomation allen-bradley_stratix_5200_firmware · rockwellautomation allen-bradley_stratix_5800_firmware
1.00EPSS
CVE-2018-0171
Sfruttata Critica 9.8

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary co…

cisco ios
0.99EPSS
CVE-2017-9805
Sfruttata Alta 8.1

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payload…

apache struts · cisco digital_media_manager · cisco hosted_collaboration_solution · cisco media_experience_engine · e altri 3
0.99EPSS
CVE-2017-3881
Sfruttata Critica 9.8

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. The…

cisco ios · cisco ios_xe
0.99EPSS
CVE-2025-32433
Sfruttata Critica 10.0

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protoco…

cisco cloud_native_broadband_network_gateway · cisco confd_basic · cisco enterprise_nfv_infrastructure_software · cisco inode_manager · e altri 19
0.99EPSS
CVE-2025-20281
Sfruttata Critica 10.0

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerabi…

cisco identity_services_engine · cisco identity_services_engine_passive_identity_connector
0.97EPSS
CVE-2019-1652
Sfruttata Alta 7.2

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands. The vul…

cisco rv320_firmware · cisco rv325_firmware
0.96EPSS
CVE-2024-20439
Sfruttata Critica 9.8

A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an ad…

cisco smart_license_utility
0.92EPSS
CVE-2026-20182
Sfruttata Critica 10.0

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The sect…

cisco catalyst_sd-wan_manager · cisco sd-wan_vbond_orchestrator · cisco sd-wan_vsmart_controller
0.92EPSS
CVE-2023-20273
Sfruttata Alta 7.2

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerabilit…

cisco ios_xe
0.90EPSS
CVE-2026-20127
Sfruttata Critica 10.0

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remot…

cisco catalyst_sd-wan_manager · cisco sd-wan_vbond_orchestrator · cisco sd-wan_vsmart_controller
0.88EPSS
CVE-2016-6366
Sfruttata Alta 8.8

Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary …

cisco adaptive_security_appliance_software · cisco asa_1000v_cloud_firewall_software · cisco pix_firewall_software
0.88EPSS
CVE-2016-6415
Sfruttata Alta 7.5

The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Assoc…

cisco ios · cisco ios_xe · cisco ios_xr
0.87EPSS
CVE-2025-20362
Sfruttata Media 6.5

Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to u…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.87EPSS
CVE-2020-3580
Ransomware Media 6.1

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.86EPSS
CVE-2020-3161
Sfruttata Critica 9.8

A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to …

cisco 8831_firmware · cisco ip_phone_7811_firmware · cisco ip_phone_7821_firmware · cisco ip_phone_7841_firmware · e altri 9
0.84EPSS
CVE-2026-20230
Sfruttata Alta 8.6

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks thro…

cisco unified_communications_manager
0.83EPSS