imPC@ndo EN

Vulnerabilità Cisco

6642 CVE

CVE-2025-20128
Media 5.3

A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer underflow i…

cisco secure_endpoint · cisco secure_endpoint_private_cloud · clamav clamav
0.02EPSS
CVE-2015-0698
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in filter search forms in admin web pages on Cisco Web Security Appliance (WSA) devices with software 8.5.0-497 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCu…

cisco web_security_appliance
0.02EPSS
CVE-2015-0696
Media 4.3

Cross-site scripting (XSS) vulnerability in the login page in Cisco TC Software before 7.1.0 on Cisco TelePresence Collaboration Desk and Room Endpoints devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID …

cisco telepresence_tc_software
0.02EPSS
CVE-2014-3410
Media 4.3

The syslog-management subsystem in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to obtain an administrator password by waiting for an administrator to copy a file, and then (1) sniffing the network for a syslog message or (2) readin…

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2015-4278
Media 4.3

Cisco Email Security Appliance (ESA) devices with software 8.5.6-106 and 9.5.0-201 allow remote attackers to cause a denial of service (per-domain e-mail reception outage) by placing malformed DMARC policy data in DNS TXT records for a domain, aka Bug ID CSCuv…

cisco email_security_appliance_firmware
0.02EPSS
CVE-2012-1361
Media 4.3

Cisco IOS 15.1 and 15.2, when the Multicast Music-on-Hold (MMoH) feature of Cisco Unified Communications Manager (CUCM) is enabled, allows remote attackers to obtain sensitive crosstalk information by listening during a PSTN call, aka Bug ID CSCtx77750.

cisco ios
0.02EPSS
CVE-2013-1152
Alta 7.8

Cisco Adaptive Security Appliances (ASA) devices with software 9.0 before 9.0(1.2) allow remote attackers to cause a denial of service (device reload) via a crafted field in a DNS message, aka Bug ID CSCuc80080.

cisco adaptive_security_appliance · cisco adaptive_security_appliance_software
0.02EPSS
CVE-2009-1559
Alta 7.8

Absolute path traversal vulnerability in adm/file.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R24 and possibly 1.00R22 allows remote attackers to read arbitrary files via an absolute pathname in the this_file parameter. NOTE: tra…

cisco wvc54gca
0.02EPSS
CVE-2014-7998
Alta 7.1

Cisco IOS on Aironet access points, when "dot11 aaa authenticator" debugging is enabled, allows remote attackers to cause a denial of service via a malformed EAP packet, aka Bug ID CSCul15509.

cisco ios
0.02EPSS
CVE-2013-5508
Alta 7.1

The SQL*Net inspection engine in Cisco Adaptive Security Appliance (ASA) Software 7.x before 7.2(5.12), 8.x before 8.2(5.44), 8.3.x before 8.3(2.39), 8.4.x before 8.4(6), 8.5.x before 8.5(1.18), 8.6.x before 8.6(1.12), 8.7.x before 8.7(1.6), 9.0.x before 9.0(2…

cisco adaptive_security_appliance_software · cisco firewall_services_module_software
0.02EPSS
CVE-2012-5990
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Health Monitor Login pages in Cisco Prime Network Control System (NCS) and Wireless Control System (WCS) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CS…

cisco prime_network_control_system · cisco wireless_control_system
0.02EPSS
CVE-2012-4643
Alta 7.1

The DHCP server on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 7.0 before 7.2(5.8), 7.1 before 7.2(5.8), 7.2 before 7.2(5.8), 8.0 before 8.0(5.28), 8.1 b…

cisco 5500_series_adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco catalyst_6500 · cisco catalyst_6503-e · e altri 7
0.02EPSS
CVE-2017-6703
Media 5.9

A vulnerability in the web application in the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated, remote attacker to hijack another user's session. More Information: CSCvc90346. Known Affected Releases: 12.1.

cisco prime_collaboration_provisioning
0.02EPSS
CVE-2020-3392
Alta 7.5

A vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive information on an affected system. The vulnerability exists because the affected software does not properly authenticate API …

cisco iot_field_network_director
0.02EPSS
CVE-2019-1965
Alta 7.7

A vulnerability in the Virtual Shell (VSH) session management for Cisco NX-OS Software could allow an authenticated, remote attacker to cause a VSH process to fail to delete upon termination. This can lead to a build-up of VSH processes that overtime can deple…

cisco nx-os
0.02EPSS
CVE-2019-1766
Alta 7.5

A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition.…

cisco ip_phone_8800_firmware
0.02EPSS
CVE-2013-3473
Alta 7.8

The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance before 9.1.1 does not properly determine the existence of an authenticated session, which allows remote attackers to discover usernames and passwords via an HTTP request…

cisco prime_central_for_hosted_collaboration_solution_assurance
0.02EPSS
CVE-2019-12677
Media 6.5

A vulnerability in the Secure Sockets Layer (SSL) VPN feature of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition that prevents the creation of new SSL/Transport Layer S…

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2017-12224
Media 6.5

A vulnerability in the ability for guest users to join meetings via a hyperlink with Cisco Meeting Server could allow an authenticated, remote attacker to enter a meeting with a hyperlink URL, even though access should be denied. The vulnerability is due to th…

cisco meeting_server
0.02EPSS
CVE-2021-1617
Media 6.5

Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to conduct a path traversal or command injection attack on an affected system. These vulnerabilities are due to i…

cisco intersight_virtual_appliance
0.02EPSS
CVE-2017-3870
Media 5.8

A vulnerability in the URL filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured URL filter rule. Affected Products: This vulnerability affects all releases pri…

cisco web_security_appliance
0.02EPSS
CVE-2017-3800
Media 5.8

A vulnerability in the content scanning engine of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured message or content filters on the device. Affected Products: This vulnerabil…

cisco email_security_appliance
0.02EPSS
CVE-2022-20857
Critica 9.8

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilit…

cisco nexus_dashboard
0.02EPSS
CVE-2013-1247
Media 4.3

Cross-site scripting (XSS) vulnerability in the wireless configuration module in Cisco Prime Infrastructure allows remote attackers to inject arbitrary web script or HTML via an SSID that is not properly handled during display of the XML windowing table, aka B…

cisco prime_infrastructure
0.02EPSS
CVE-2026-24700
Alta 7.2

An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The machine_name configuration parameter is not properly sanitized, wh…

cisco rv110w_firmware · cisco rv130_firmware · cisco rv130w_firmware
0.02EPSS