57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-0424 | HIGH 8.8 | cisco rv110w_firmware A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an authenticated, remote attacker to execute arbitrary comma | 4.0% | — |
| CVE-2018-0413 | HIGH 8.8 | cisco identity_services_engine_software A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnera | 1.2% | — |
| CVE-2018-0402 | HIGH 8.8 | cisco unified_contact_center_express Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. Cisco Bug IDs: CSCvg70921. | 1.0% | — |
| CVE-2018-0395 | HIGH 8.8 | cisco firepower_extensible_operating_system A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when the device unexpectedly reloads. The | 0.8% | — |
| CVE-2018-0394 | HIGH 8.8 | cisco cloud_services_platform_2100 A vulnerability in the web upload function of Cisco Cloud Services Platform 2100 could allow an authenticated, remote attacker to obtain restricted shell access on an affected system. The vulnerability is due to insufficient input validation of parameters pass | 1.6% | — |
| CVE-2018-0387 | HIGH 8.8 | cisco webex_teams A vulnerability in Cisco Webex Teams (for Windows and macOS) could allow an unauthenticated, remote attacker to execute arbitrary code on the user's device, possibly with elevated privileges. The vulnerability occurs because Cisco Webex Teams does not properly | 3.1% | — |
| CVE-2018-0365 | HIGH 8.8 | cisco amp_7150_firmware A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerabil | 0.9% | — |
| CVE-2018-0364 | HIGH 8.8 | cisco unified_communications_domain_manager A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The | 0.7% | — |
| CVE-2018-0363 | HIGH 8.8 | cisco unified_communications_manager_im_and_presence_service A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (formerly CUPS) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary acti | 0.9% | — |
| CVE-2018-0350 | HIGH 8.8 | cisco vbond_orchestrator A vulnerability in the VPN subsystem configuration in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An att | 3.1% | — |
| CVE-2018-0345 | HIGH 8.8 | cisco vbond_orchestrator A vulnerability in the configuration and management database of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to execute arbitrary commands with the privileges of the vmanage user in the configuration management system of the affected | 3.0% | — |
| CVE-2018-0343 | HIGH 8.8 | cisco vbond_orchestrator A vulnerability in the configuration and management service of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to execute arbitrary code with vmanage user privileges or cause a denial of service (DoS) condition on an affected system. Th | 2.0% | — |
| CVE-2018-0341 | HIGH 8.8 | cisco ip_phone_multiplatform_firmware A vulnerability in the web-based UI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware before 11.2(1) could allow an authenticated, remote attacker to perform a command injection and execute commands with the privileges of the web server | 5.9% | — |
| CVE-2018-0336 | HIGH 8.8 | cisco prime_collaboration A vulnerability in the batch provisioning feature of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to escalate privileges to the Administrator level. The vulnerability is due to insufficient authorization enforcement on b | 2.4% | — |
| CVE-2018-0330 | HIGH 8.8 | cisco nx-os A vulnerability in the NX-API management application programming interface (API) in devices running, or based on, Cisco NX-OS Software could allow an authenticated, remote attacker to execute commands with elevated privileges. The vulnerability is due to a fai | 2.8% | — |
| CVE-2018-0322 | HIGH 8.8 | cisco prime_collaboration A vulnerability in the web management interface of Cisco Prime Collaboration Provisioning (PCP) could allow an authenticated, remote attacker to modify sensitive data that is associated with arbitrary accounts on an affected device. The vulnerability is due to | 2.6% | — |
| CVE-2018-0317 | HIGH 8.8 | cisco prime_collaboration A vulnerability in the web interface of Cisco Prime Collaboration Provisioning (PCP) could allow an authenticated, remote attacker to escalate their privileges. The vulnerability is due to insufficient web portal access control checks. An attacker could exploi | 2.6% | — |
| CVE-2018-0313 | HIGH 8.8 | cisco nx-os A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to send a malicious packet to the management interface on an affected system and execute a command-injection exploit. The vulnerability is due to incorr | 3.9% | — |
| CVE-2018-0303 | HIGH 8.8 | cisco firepower_extensible_operating_system A vulnerability in the Cisco Discovery Protocol component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code as root or cause a denial of service (DoS) condition on the affected device. T | 1.1% | — |
| CVE-2018-0293 | HIGH 8.8 | cisco nx-os A vulnerability in role-based access control (RBAC) for Cisco NX-OS Software could allow an authenticated, remote attacker to execute CLI commands that should be restricted for a nonadministrative user. The attacker would have to possess valid user credentials | 4.8% | — |
| CVE-2018-0292 | HIGH 8.8 | cisco nx-os A vulnerability in the Internet Group Management Protocol (IGMP) Snooping feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code and gain full control of an affected system. The attacker could also cause an | 1.6% | — |
| CVE-2018-0287 | HIGH 8.8 | cisco webex_meetings_online A vulnerability in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. The vulnerability is due to a design flaw in the affected sof | 3.8% | — |
| CVE-2018-0279 | HIGH 8.8 | cisco enterprise_nfv_infrastructure_software A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to access the shell of the underlying Linux operating system on the affected device. The vulnerabilit | 4.5% | — |
| CVE-2018-0274 | HIGH 8.8 | cisco network_services_orchestrator A vulnerability in the CLI parser of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. The vulnerability is due to insufficient input validation. An | 3.9% | — |
| CVE-2018-0270 | HIGH 8.8 | cisco iot_field_network_director A vulnerability in the web-based management interface of Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and alter the data of existing users and groups on an affe | 0.7% | — |