58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
Cisco vulnerabilities
6716 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-6646 | MED 5.3 | cisco remote_expert_manager A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive Order information on an affected system. The vulnerability exists because the affected software does not suf | 2.7% | — |
| CVE-2017-6645 | MED 5.3 | cisco remote_expert_manager A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive Virtual Temporary Directory information on an affected system. The vulnerability exists because the affected | 2.7% | — |
| CVE-2017-6644 | MED 5.3 | cisco remote_expert_manager A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability exists because the affected software does not sufficien | 2.7% | — |
| CVE-2017-6643 | MED 5.3 | cisco remote_expert_manager A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive Virtual Directory information on an affected system. The vulnerability exists because the affected software | 2.7% | — |
| CVE-2017-6642 | MED 5.3 | cisco remote_expert_manager A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability exists because the affected software does not sufficien | 2.7% | — |
| CVE-2014-0658 | MED 5.4 | cisco unified_ip_phone_9951 Cisco 9900 Unified IP phones allow remote attackers to cause a denial of service (unregistration) via a crafted SIP header, aka Bug ID CSCul24898. | 2.7% | — |
| CVE-2017-12219 | HIGH 7.5 | cisco spa_301_firmware A vulnerability in the handling of IP fragments for the Cisco Small Business SPA300, SPA500, and SPA51x Series IP Phones could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) conditio | 2.7% | — |
| CVE-2016-9225 | HIGH 8.6 | cisco asa_cx_context-aware_security_software A vulnerability in the data plane IP fragment handler of the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security module could allow an unauthenticated, remote attacker to cause the CX module to be unable to process further traffic, resulting in a | 2.7% | — |
| CVE-2009-1157 | HIGH 7.8 | cisco adaptive_security_appliance_5500 Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)6, 7.1 before 7.1(2)82, 7.2 before 7.2(4)30, 8.0 before 8.0(4)28, and 8.1 before 8.1(2)19 allows remote attackers to cause a denial of service (mem | 2.7% | — |
| CVE-2016-1365 | HIGH 8.8 | cisco application_policy_infrastructure_controller_enterprise_module The Grapevine update process in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0 allows remote authenticated users to execute arbitrary commands as root via a crafted upgrade parameter, aka Bug ID CSCux15507. | 2.7% | — |
| CVE-2017-6750 | HIGH 7.5 | cisco web_security_appliance A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated, local attacker to log in to the device with the privileges of a limited user or an unauthenticated, remote attacker to authenticate to certain areas of the we | 2.7% | — |
| CVE-2008-3803 | MED 5.1 | cisco ios A "logic error" in Cisco IOS 12.0 through 12.4, when a Multiprotocol Label Switching (MPLS) VPN with extended communities is configured, sometimes causes a corrupted route target (RT) to be used, which allows remote attackers to read traffic from other VPNs in | 2.6% | — |
| CVE-2005-3788 | MED 5.4 | cisco adaptive_security_appliance_software Race condition in Cisco Adaptive Security Appliance (ASA) 7.0(0), 7.0(2), and 7.0(4), when running with an Active/Standby configuration and when the failover LAN interface fails, allows remote attackers to cause a denial of service (standby firewall failure) b | 2.6% | — |
| CVE-2020-3401 | MED 6.5 | cisco sd-wan_firmware A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. The vulnerability is due to | 2.6% | — |
| CVE-2018-0090 | HIGH 7.5 | cisco nx-os A vulnerability in management interface access control list (ACL) configuration of Cisco NX-OS System Software could allow an unauthenticated, remote attacker to bypass configured ACLs on the management interface. This could allow traffic to be forwarded to th | 2.6% | — |
| CVE-2014-0649 | HIGH 9.0 | cisco secure_access_control_system The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authorization requirements, which allows remote authenticated users to obtain superadmin access via a request to this interface, aka Bug ID CSCud75180. | 2.6% | — |
| CVE-2020-3381 | HIGH 8.8 | cisco sd-wan_firmware A vulnerability in the web management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct directory traversal attacks and obtain read and write access to sensitive files on a targeted system. The vulnerability is | 2.6% | — |
| CVE-2015-4307 | HIGH 9.0 | cisco prime_collaboration_provisioning The web framework in Cisco Prime Collaboration Provisioning before 11.0 allows remote authenticated users to bypass intended access restrictions and create administrative accounts via a crafted URL, aka Bug ID CSCut64111. | 2.6% | — |
| CVE-2015-4304 | HIGH 9.0 | cisco prime_collaboration_assurance The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended access restrictions, and create administrative accounts or read data from arbitrary tenant domains, via a crafted URL, aka Bug I | 2.6% | — |
| CVE-2007-0960 | HIGH 9.0 | cisco asa_5500 Unspecified vulnerability in Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to use the LOCAL authentication method, allows remote authenticated users to gain privileges via unspecified vectors. | 2.6% | — |
| CVE-2012-0367 | HIGH 7.8 | cisco unity_connection Cisco Unity Connection before 7.1.5b(Su5), 8.0 and 8.5 before 8.5.1(Su3), and 8.6 before 8.6.2 allows remote attackers to cause a denial of service (services crash) via a series of crafted TCP segments, aka Bug ID CSCtq67899. | 2.6% | — |
| CVE-2019-1869 | HIGH 8.6 | cisco staros A vulnerability in the internal packet-processing functionality of the Cisco StarOS operating system running on virtual platforms could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of s | 2.6% | — |
| CVE-2019-1712 | MED 5.8 | cisco ios_xr A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the PIM process to restart, resulting in a denial of service condition on an affected device. The vulnerabilit | 2.6% | — |
| CVE-2017-6619 | HIGH 8.8 | cisco integrated_management_controller_supervisor A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute arbitrary commands on an affected system. The vulnerability exists because the affected software does not suff | 2.6% | — |
| CVE-2005-0186 | MED 5.0 | cisco ios Cisco IOS 12.1YD, 12.2T, 12.3 and 12.3T, when configured for the IOS Telephony Service (ITS), CallManager Express (CME) or Survivable Remote Site Telephony (SRST), allows remote attackers to cause a denial of service (device reboot) via a malformed packet to t | 2.6% | — |