58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
Cisco vulnerabilities
6716 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-12216 | HIGH 8.8 | cisco socialminer A vulnerability in the web-based user interface of Cisco SocialMiner could allow an unauthenticated, remote attacker to have read and write access to information stored in the affected system. The vulnerability is due to improper handling of XML External Entit | 2.9% | — |
| CVE-2012-4086 | MED 5.1 | cisco unified_computing_system A setup script for fabric interconnect devices in Cisco Unified Computing System (UCS) allows remote attackers to execute arbitrary commands via invalid parameters, aka Bug ID CSCtg20790. | 2.9% | — |
| CVE-2014-0721 | HIGH 10.0 | cisco unified_sip_phone_3905 The Cisco Unified SIP Phone 3905 with firmware before 9.4(1) allows remote attackers to obtain root access via a session on the test interface on TCP port 7870, aka Bug ID CSCuh75574. | 2.9% | — |
| CVE-2010-4682 | HIGH 7.8 | cisco 5500_series_adaptive_security_appliance Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) allows remote attackers to cause a denial of service (memory consumption) by making multiple incorrect LDAP authentication attempts, aka Bug ID CSCtf29867. | 2.9% | — |
| CVE-2019-1687 | HIGH 7.5 | cisco adaptive_security_appliance_software A vulnerability in the TCP proxy functionality for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to restart unexpectedly, resulting in a de | 2.9% | — |
| CVE-2007-0397 | MED 6.4 | cisco adaptive_security_appliance_device_manager The Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.3 and Adaptive Security Device Manager (ASDM) before 5.2(2.54) do not validate the SSL/TLS certificates or SSH public keys when connecting to devices, which allows remote attacker | 2.9% | — |
| CVE-2008-2057 | MED 5.4 | cisco adaptive_security_appliance_software The Instant Messenger (IM) inspection engine in Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 7.2.x before 7.2(4), 8.0.x before 8.0(3)10, and 8.1.x before 8.1(1)2 allows remote attackers to cause a denial of service via a crafted pac | 2.9% | — |
| CVE-2016-1468 | HIGH 8.8 | cisco telepresence_video_communication_server The administrative web interface in Cisco TelePresence Video Communication Server Expressway X8.5.2 allows remote authenticated users to execute arbitrary commands via crafted fields, aka Bug ID CSCuv12531. | 2.9% | — |
| CVE-2008-0531 | HIGH 9.3 | cisco session_initiation_protocol_\(sip\)_firmware Heap-based buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote SIP servers to execute arbitrary code via a crafted challenge/response message. | 2.9% | — |
| CVE-2019-1703 | HIGH 8.6 | cisco secure_firewall_threat_defense A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for the Cisco Firepower 2100 Series could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulti | 2.9% | — |
| CVE-2007-5552 | HIGH 9.3 | cisco ios Integer overflow in Cisco IOS allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is | 2.9% | — |
| CVE-2020-3284 | CRIT 9.8 | cisco a99-rp2-se_firmware A vulnerability in the enhanced Preboot eXecution Environment (PXE) boot loader for Cisco IOS XR 64-bit Software could allow an unauthenticated, remote attacker to execute unsigned code during the PXE boot process on an affected device. The PXE boot loader is | 2.9% | — |
| CVE-2016-1472 | HIGH 7.5 | cisco small_business_220_series_smart_plus_switches The web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to cause a denial of service (interface outage) via a crafted HTTP request, aka Bug ID CSCuz76238. | 2.9% | — |
| CVE-2018-0405 | HIGH 7.5 | cisco rv180w_firmware A vulnerability in the web framework code for Cisco RV180W Wireless-N Multifunction VPN Router and Small Business RV Series RV220W Wireless Network Security Firewall could allow an unauthenticated, remote attacker to conduct a directory path traversal attack o | 2.9% | — |
| CVE-2010-3037 | HIGH 8.5 | cisco unified_videoconferencing_system_3515_multipoint_control_unit goform/websXMLAdminRequestCgi.cgi in Cisco Unified Videoconferencing (UVC) System 5110 and 5115, and possibly Unified Videoconferencing System 3545 and 5230, Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway, Unified Videoconferencing 3522 Ba | 2.9% | — |
| CVE-2020-3437 | MED 6.5 | cisco sd-wan_firmware A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying filesystem of the device. The vulnerability is due to insufficient file scope limitin | 2.9% | — |
| CVE-2007-2463 | HIGH 7.8 | cisco adaptive_security_appliance_software Unspecified vulnerability in Cisco Adaptive Security Appliance (ASA) and PIX 7.1 before 7.1(2)49 and 7.2 before 7.2(2)17 allows remote attackers to cause a denial of service (device reload) via unknown vectors related to VPN connection termination and password | 2.9% | — |
| CVE-2014-2197 | HIGH 9.0 | cisco unified_cdm_application_software The Administration GUI in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 8.1.4 does not properly implement access control, which allows remote authenticated users to modify administrative crede | 2.9% | — |
| CVE-2018-15430 | HIGH 7.2 | cisco telepresence_video_communication_server A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with user-level privileges on the underlying operating system. | 2.9% | — |
| CVE-2021-1337 | HIGH 7.2 | cisco rv016_multi-wan_vpn_router_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpect | 2.9% | — |
| CVE-2015-0713 | HIGH 9.0 | cisco telepresence_advanced_media_gateway The web framework in Cisco TelePresence Advanced Media Gateway Series Software before 1.1(1.40), Cisco TelePresence IP Gateway Series Software, Cisco TelePresence IP VCR Series Software before 3.0(1.27), Cisco TelePresence ISDN Gateway Software before 2.2(1.94 | 2.9% | — |
| CVE-2016-6379 | HIGH 7.5 | cisco ios Cisco IOS 12.2 and IOS XE 3.14 through 3.16 and 16.1 allow remote attackers to cause a denial of service (device reload) via crafted IP Detail Record (IPDR) packets, aka Bug ID CSCuu35089. | 2.9% | — |
| CVE-2016-6386 | HIGH 7.5 | cisco ios_xe Cisco IOS XE 3.1 through 3.17 and 16.1 on 64-bit platforms allows remote attackers to cause a denial of service (data-structure corruption and device reload) via fragmented IPv4 packets, aka Bug ID CSCux66005. | 2.9% | — |
| CVE-2016-6355 | HIGH 7.5 | cisco ios_xr Memory leak in Cisco IOS XR 5.1.x through 5.1.3, 5.2.x through 5.2.5, and 5.3.x through 5.3.2 on ASR 9001 devices allows remote attackers to cause a denial of service (control-plane protocol outage) via crafted fragmented packets, aka Bug ID CSCux26791. | 2.9% | — |
| CVE-2016-1466 | HIGH 7.5 | cisco unified_communications_manager_im_and_presence_service Cisco Unified Communications Manager IM and Presence Service 9.1(1) SU6, 9.1(1) SU6a, 9.1(1) SU7, 10.5(2) SU2, 10.5(2) SU2a, 11.0(1) SU1, and 11.5(1) allows remote attackers to cause a denial of service (sipd process restart) via crafted headers in a SIP packe | 2.9% | — |