58.507 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
Cisco vulnerabilities
6716 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-15982 | HIGH 7.2 | cisco data_center_network_manager Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. To exploit | 14.3% | — |
| CVE-2019-15981 | HIGH 7.2 | cisco data_center_network_manager Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. To exploit | 14.3% | — |
| CVE-2019-1599 | HIGH 8.6 | cisco nx-os A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to an issue with allocating and freeing memory buffers in | 14.3% | — |
| CVE-2005-2841 | HIGH 7.5 | cisco ios Buffer overflow in Firewall Authentication Proxy for FTP and/or Telnet Sessions for Cisco IOS 12.2ZH and 12.2ZL, 12.3 and 12.3T, and 12.4 and 12.4T allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted user authen | 14.1% | — |
| CVE-2007-4459 | HIGH 7.1 | cisco voip_phone_cp-7940 Cisco IP Phone 7940 and 7960 with P0S3-08-6-00 firmware, and other SIP firmware before 8.7(0), allows remote attackers to cause a denial of service (device reboot) via (1) a certain sequence of 10 invalid SIP INVITE and OPTIONS messages; or (2) a certain inval | 14.0% | — |
| CVE-2011-0354 | HIGH 10.0 | cisco tandberg_endpoint The default configuration of Cisco Tandberg C Series Endpoints, and Tandberg E and EX Personal Video units, with software before TC4.0.0 has a blank password for the root account, which makes it easier for remote attackers to obtain access via an unspecified l | 14.0% | — |
| CVE-2023-20036 | CRIT 9.9 | cisco industrial_network_director A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands with administrative privileges on the underlying operating system of an affected device. This vulnerability is due to improper input valid | 13.8% | — |
| CVE-2006-3109 | MED 4.3 | cisco call_manager Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 before 3.3(5)SR3, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3), and 4.3 before 4.3(1), allows remote attackers to inject arbitrary web script or HTML via the (1) pattern parameter in ccmadmin/phoneli | 13.7% | — |
| CVE-2018-0476 | MED 5.9 | cisco ios_xe A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due | 13.7% | — |
| CVE-2019-1820 | MED 6.5 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be res | 13.6% | — |
| CVE-2019-1819 | MED 6.5 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be res | 13.6% | — |
| CVE-2019-1818 | MED 6.5 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be res | 13.6% | — |
| CVE-2006-0179 | MED 5.0 | cisco ip_phone_7940 The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN packets (syn flood) to arbitrary ports, as demonstrated to port 80. | 13.6% | — |
| CVE-2013-2683 | MED 5.3 | cisco linksys_e4200_firmware Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers to obtain private IP addresses and other sensitive information. | 13.4% | — |
| CVE-2007-4430 | MED 5.0 | cisco cbos Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command. NOTE: unauthenticated re | 13.3% | — |
| CVE-2020-3387 | HIGH 8.8 | cisco sd-wan_firmware A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to execute code with root privileges on an affected system. The vulnerability is due to insufficient input sanitization during user authentication processing. An att | 13.0% | — |
| CVE-2006-4098 | HIGH 10.0 | cisco secure_access_control_server Stack-based buffer overflow in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary code via a crafted RADIUS Accounting-Request packet. | 12.8% | — |
| CVE-2017-12373 | MED 5.9 | cisco adaptive_security_appliance_5505_firmware A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (R | 12.8% | — |
| CVE-2011-2577 | HIGH 7.8 | cisco telepresence_6000_mxp Unspecified vulnerability in Cisco TelePresence C Series Endpoints, E/EX Personal Video units, and MXP Series Codecs, when using software versions before TC 4.0.0 or F9.1, allows remote attackers to cause a denial of service (crash) via a crafted SIP packet to | 12.7% | — |
| CVE-2020-26073 | HIGH 7.5 | cisco catalyst_sd-wan_manager A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character s | 12.6% | — |
| CVE-2009-1161 | HIGH 10.0 | cisco ciscoworks_common_services Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security Manager, TelePresence Readiness Assessment Manager, Unified Operations Manager, | 12.5% | — |
| CVE-2022-20624 | HIGH 8.6 | cisco nx-os A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validati | 12.4% | — |
| CVE-2001-0041 | HIGH 7.8 | cisco catos Memory leak in Cisco Catalyst 4000, 5000, and 6000 series switches allows remote attackers to cause a denial of service via a series of failed telnet authentication attempts. | 12.1% | — |
| CVE-2006-4313 | MED 5.0 | cisco vpn_3000_concentrator_series_software Multiple unspecified vulnerabilities in Cisco VPN 3000 series concentrators before 4.1, 4.1.x up to 4.1(7)L, and 4.7.x up to 4.7(2)F allow attackers to execute the (1) CWD, (2) MKD, (3) CDUP, (4) RNFR, (5) SIZE, and (6) RMD FTP commands to modify files or crea | 12.0% | — |
| CVE-2006-3733 | HIGH 7.5 | cisco security_monitoring_analysis_and_response_system jmx-console/HtmlAdaptor in the jmx-console in the JBoss web application server, as shipped with Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1, allows remote attackers to gain privileges as the CS-MARS administrator and execute | 12.0% | — |