56.571 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Cisco
6655 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2012-4106 | MED 6.8 | cisco unified_computing_system The fabric-interconnect component in Cisco Unified Computing System (UCS) uses the same privilege level for execution of every script, which allows local users to gain privileges and execute arbitrary commands via an unspecified script-execution approach, aka | 0,4% | — |
| CVE-2012-5445 | MED 6.8 | cisco skinny_client_control_protocol_software The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properly validate unspecified system calls, which allows attackers to execute arbitrary code or cause a denial of serv | 0,4% | — |
| CVE-2023-20172 | MED 5.4 | cisco identity_services_engine Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affecte | 0,4% | — |
| CVE-2021-1277 | HIGH 7.5 | cisco data_center_network_manager Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API requests. These vulnerabilities are due to insuff | 0,4% | — |
| CVE-2021-1276 | HIGH 7.5 | cisco data_center_network_manager Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API requests. These vulnerabilities are due to insuff | 0,4% | — |
| CVE-2018-0095 | HIGH 7.8 | cisco asyncos A vulnerability in the administrative shell of Cisco AsyncOS on Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA) could allow an authenticated, local attacker to escalate their privilege level and gain root access. The attack | 0,4% | — |
| CVE-2017-6598 | MED 6.7 | cisco firepower_extensible_operating_system A vulnerability in the debug plug-in functionality of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to exe | 0,4% | — |
| CVE-2005-2681 | HIGH 7.2 | cisco ips_sensor_software Unspecified vulnerability in the command line processing (CLI) logic in Cisco Intrusion Prevention System 5.0(1) and 5.0(2) allows local users with OPERATOR or VIEWER privileges to gain additional privileges via unknown vectors. | 0,4% | — |
| CVE-2019-1601 | HIGH 7.8 | cisco nx-os A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to gain read and write access to a critical configuration file. The vulnerability is due to a failure to impose strict filesystem permissions on | 0,4% | — |
| CVE-2018-15371 | MED 6.7 | cisco ios_xe A vulnerability in the shell access request mechanism of Cisco IOS XE Software could allow an authenticated, local attacker to bypass authentication and gain unrestricted access to the root shell of an affected device. The vulnerability exists because the affe | 0,4% | — |
| CVE-2024-20431 | MED 5.8 | cisco secure_firewall_threat_defense A vulnerability in the geolocation access control feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control policy. This vulnerability is due to improper assignment of geolocation da | 0,4% | — |
| CVE-2024-20350 | HIGH 7.5 | cisco catalyst_center A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to impersonate a Cisco Catalyst Center appliance. This vulnerability is due to the presence of a static SSH host key. An a | 0,4% | — |
| CVE-2024-20361 | MED 5.8 | cisco secure_firewall_management_center A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass configured access controls on managed devices that are running Cisco Fire | 0,4% | — |
| CVE-2024-20293 | MED 5.8 | cisco adaptive_security_appliance_software A vulnerability in the activation of an access control list (ACL) on Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by | 0,4% | — |
| CVE-2021-1237 | HIGH 7.8 | cisco anyconnect_secure_mobility_client A vulnerability in the Network Access Manager and Web Security Agent components of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL injection attack. To exploit this vulnerability, the attacker w | 0,4% | — |
| CVE-2016-6362 | HIGH 7.8 | cisco aironet_access_point_software Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.110.0, 8.2.12x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow local users to gain privileges via crafted CLI parameters, aka Bug ID CSCuz24725. | 0,4% | — |
| CVE-2016-1340 | HIGH 8.4 | cisco unified_computing_system_platform_emulator Heap-based buffer overflow in Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted libclimeta.so filename arguments, aka Bug ID CSCux68837. | 0,4% | — |
| CVE-2014-3391 | MED 6.8 | cisco adaptive_security_appliance_software Untrusted search path vulnerability in Cisco ASA Software 8.x before 8.4(3), 8.5, and 8.7 before 8.7(1.13) allows local users to gain privileges by placing a Trojan horse library file in external memory, leading to library use after device reload because of an | 0,4% | — |
| CVE-2018-0373 | MED 5.5 | cisco anyconnect_secure_mobility_client A vulnerability in vpnva-6.sys for 32-bit Windows and vpnva64-6.sys for 64-bit Windows of Cisco AnyConnect Secure Mobility Client for Windows Desktop could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected syste | 0,4% | — |
| CVE-2002-0881 | LOW 2.1 | cisco skinny_client_control_protocol_software Cisco IP Phone (VoIP) models 7910, 7940, and 7960 use a default administrative password, which allows attackers with physical access to the phone to modify the configuration settings. | 0,4% | — |
| CVE-2025-20210 | HIGH 7.3 | cisco catalyst_center A vulnerability in the management API of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to read and modify the outgoing proxy configuration settings. This vulnerability is due to the lack of authentication | 0,4% | — |
| CVE-2022-20774 | MED 6.8 | cisco ip_phone_6825_firmware A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-base | 0,4% | — |
| CVE-2025-20145 | MED 5.8 | cisco ios_xr A vulnerability in the access control list (ACL) processing in the egress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability exists because certain packets are handled incorrectl | 0,4% | — |
| CVE-2019-1654 | HIGH 7.8 | cisco ap-cos A vulnerability in the development shell (devshell) authentication for Cisco Aironet Series Access Points (APs) running the Cisco AP-COS operating system could allow an authenticated, local attacker to access the development shell without proper authentication | 0,4% | — |
| CVE-2019-1677 | MED 4.6 | cisco webex_meetings A vulnerability in Cisco Webex Meetings for Android could allow an unauthenticated, local attacker to perform a cross-site scripting attack against the application. The vulnerability is due to insufficient validation of the application input parameters. An att | 0,4% | — |