58.483 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
Cisco vulnerabilities
6716 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-3251 | HIGH 8.8 | cisco ucs_director Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulne | 61.5% | — |
| CVE-2020-3250 | CRIT 9.8 | cisco ucs_director Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulne | 60.9% | — |
| CVE-2020-27128 | MED 6.5 | cisco sd-wan A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to write arbitrary files to an affected system. The vulnerability is due to improper validation of requests to APIs. An attacker co | 60.8% | — |
| CVE-2020-3495 | CRIT 9.9 | cisco jabber A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of message contents. An attacker could exploit this vulnerability by sending specially crafted | 59.9% | — |
| CVE-2008-0532 | HIGH 10.0 | cisco acs_for_windows Multiple buffer overflows in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to execute arbitrary code via a long argument located i | 57.1% | — |
| CVE-2008-0027 | HIGH 10.0 | cisco unified_callmanager Heap-based buffer overflow in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM) 4.2 before 4.2(3)SR3 and 4.3 before 4.3(1)SR1, and CallManager 4.0 and 4.1 before 4.1(3)SR5c, allows remote attacke | 57.1% | — |
| CVE-2019-16012 | HIGH 8.1 | cisco sd-wan_firmware A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web UI improperly validates SQL values. An attack | 54.2% | — |
| CVE-2024-20440 | HIGH 7.5 | cisco smart_license_utility A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulnerability by sending a | 51.9% | — |
| CVE-2019-15980 | HIGH 7.2 | cisco data_center_network_manager Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. To exploit | 50.0% | — |
| CVE-2018-15439 | CRIT 9.8 | cisco sf200-24_firmware A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mechanism of an affected device. The vulnerability exists because under specific circumstances, the affected softwar | 49.7% | — |
| CVE-2022-20828 | MED 6.5 | cisco asa_firepower A vulnerability in the CLI parser of Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected ASA FirePOWER mod | 49.3% | — |
| CVE-2018-0258 | CRIT 9.8 | cisco prime_data_center_network_manager A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to any directory of a vulnerable device (aka Path Traversal) and execute those files. This vulnerability affects th | 48.2% | — |
| CVE-2019-15984 | HIGH 7.2 | cisco data_center_network_manager Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. To exploit these vulnerabilities, an attacker would n | 46.9% | — |
| CVE-2019-1636 | HIGH 7.8 | cisco webex_teams A vulnerability in the Cisco Webex Teams client, formerly Cisco Spark, could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI that is defined in Windows operating | 46.9% | — |
| CVE-2019-15276 | MED 6.5 | cisco wireless_lan_controller_software A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists due to a failure of the HTT | 46.3% | — |
| CVE-2018-0114 | HIGH 7.5 | cisco node-jose A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens using a key that is embedded within the token. The vulnerability is due to node-jose following the JSON Web Signature (JW | 42.7% | — |
| CVE-2020-3331 | CRIT 9.8 | cisco rv110w_wireless-n_vpn_firewall_firmware A vulnerability in the web-based management interface of Cisco RV110W Wireless-N VPN Firewall and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to im | 41.7% | — |
| CVE-2019-1898 | MED 5.3 | cisco rv110w_firmware A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to access the syslog file on an affected device. The vulnerability is due to improper authorization of an HTTP req | 41.7% | — |
| CVE-2011-0966 | MED 6.8 | cisco ciscoworks_common_services Directory traversal vulnerability in cwhp/auditLog.do in the Homepage Auditing component in Cisco CiscoWorks Common Services 3.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, aka Bug ID CSCto35577. | 41.3% | — |
| CVE-2023-20209 | MED 6.5 | cisco telepresence_video_communication_server A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read-write privileges on the application to perform a command injection | 40.8% | — |
| CVE-2019-1936 | HIGH 7.2 | cisco integrated_management_controller_supervisor A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an authenticated, remote attacker to execute arbitrary commands on the | 39.5% | — |
| CVE-2025-20282 | CRIT 10.0 | cisco identity_services_engine A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root. This vulnerability is | 38.7% | — |
| CVE-2020-3240 | HIGH 7.3 | cisco ucs_director Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulne | 38.7% | — |
| CVE-2019-15977 | HIGH 7.5 | cisco data_center_network_manager Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. F | 38.1% | — |
| CVE-2019-15978 | HIGH 7.2 | cisco data_center_network_manager Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative privileges on the DCNM application to inject arbitrary commands on the underlying operatin | 37.5% | — |