58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
Cisco vulnerabilities
6716 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2010-0139 | HIGH 9.0 | cisco unified_meetingplace Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.2, and possibly 5 does not properly validate SQL commands, which allows remote attackers to create, modify, or delete data in a database via unspecified vectors, aka Bug ID CSCtc39691. | 2.0% | — |
| CVE-2018-15444 | MED 6.3 | cisco energy_management_suite_software A vulnerability in the web-based user interface of Cisco Energy Management Suite Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper hand | 2.0% | — |
| CVE-2013-5557 | MED 6.3 | cisco adaptive_security_appliance_software The Proxy Bypass Content Rewriter feature in the WebVPN subsystem in Cisco Adaptive Security Appliance (ASA) Software 9.1(.2) and earlier allows remote authenticated users to cause a denial of service (device crash or error-recovery event) via an HTTP request | 2.0% | — |
| CVE-2004-0710 | MED 5.0 | cisco ios IP Security VPN Services Module (VPNSM) in Cisco Catalyst 6500 Series Switch and the Cisco 7600 Series Internet Routers running IOS before 12.2(17b)SXA, before 12.2(17d)SXB, or before 12.2(14)SY03 could allow remote attackers to cause a denial of service (devi | 2.0% | — |
| CVE-2021-1224 | MED 5.8 | cisco ios_xe Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due | 2.0% | — |
| CVE-2020-3283 | HIGH 8.6 | cisco asa_5505_firmware A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Firepower Threat Defense (FTD) Software when running on the Cisco Firepower 1000 Series platform could allow an unauthenticated, remote attacker to trigger a deni | 2.0% | — |
| CVE-2015-6340 | MED 5.0 | cisco asr_5000_software The Proxy Mobile IPv6 (PMIPv6) component in the CDMA implementation on Cisco ASR 5000 devices with software 19.0.M0.60737 allows remote attackers to cause a denial of service (hamgr process restart) via a crafted header in a PMIPv6 packet, aka Bug ID CSCuv6328 | 2.0% | — |
| CVE-2015-6332 | MED 5.0 | cisco prime_infrastructure Cisco Prime Infrastructure 2.2 allows remote attackers to cause a denial of service (daemon hang) by sending many SSL renegotiation requests, aka Bug ID CSCuv56830. | 2.0% | — |
| CVE-2013-3402 | MED 6.5 | cisco unified_communications_manager An unspecified function in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitrary commands via unknown vectors, aka Bug ID CSCuh73440. | 2.0% | — |
| CVE-2018-0282 | MED 6.8 | cisco ios A vulnerability in the TCP socket code of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a state condition between the socket state and the transmission control b | 2.0% | — |
| CVE-1999-1000 | MED 5.0 | cisco cache_engine The web administration interface for Cisco Cache Engine allows remote attackers to view performance statistics. | 2.0% | — |
| CVE-2018-0357 | MED 6.1 | cisco webex_meetings A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerability is due to insufficient input valid | 2.0% | — |
| CVE-2014-2112 | HIGH 7.8 | cisco ios The SSL VPN (aka WebVPN) feature in Cisco IOS 15.1 through 15.4 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP requests, aka Bug ID CSCuf51357. | 2.0% | — |
| CVE-2021-40120 | MED 6.5 | cisco application_extension_platform A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker with administrative privileges to inject arbitrary commands into the underlying operating system and execute t | 2.0% | — |
| CVE-2015-0636 | HIGH 7.8 | cisco ios The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to cause a denial of service (disrupted domain access) via spoofed AN mes | 2.0% | — |
| CVE-2019-1908 | HIGH 7.5 | cisco integrated_management_controller_supervisor A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to view sensitive system information. The vulnerability is due to insufficien | 2.0% | — |
| CVE-2022-20951 | HIGH 7.7 | cisco broadworks_messaging_server A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an authenticated, remote attacker to perform a server-side request forgery (SSRF) attack on an affected device. This vulnerability is due to insuffic | 2.0% | — |
| CVE-2018-0248 | MED 6.8 | cisco wireless_lan_controller_software A vulnerability in the administrative GUI configuration feature of Cisco Wireless LAN Controller (WLC) Software could allow an aUTHENTICated, remote attacker to cause the device to reload unexpectedly during device configuration when the administrator is using | 2.0% | — |
| CVE-2015-6271 | HIGH 7.8 | cisco ios_xe Cisco IOS XE 2.1.0 through 2.4.3 and 2.5.0 on ASR 1000 devices, when NAT Application Layer Gateway is used, allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted SIP packet, aka Bug IDs CSCta74749 and CSCta77008 | 2.0% | — |
| CVE-2015-0739 | MED 4.0 | cisco firesight_system_software The Lights-Out Management (LOM) implementation in Cisco FireSIGHT System Software 5.3.0 on Sourcefire 3D Sensor devices allows remote authenticated users to perform arbitrary Baseboard Management Controller (BMC) file uploads via unspecified vectors, aka Bug I | 2.0% | — |
| CVE-2014-3393 | MED 4.3 | cisco adaptive_security_appliance_software The Clientless SSL VPN portal customization framework in Cisco ASA Software 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before 8.6(1.14), 9.0 before 9.0(4.24), 9.1 before 9.1(5.12), and 9.2 before 9.2(2.4) does not properly implement | 2.0% | — |
| CVE-2010-0142 | HIGH 8.5 | cisco unified_meetingplace MeetingTime in Cisco Unified MeetingPlace 6 before MR5, and possibly 5, allows remote authenticated users to gain privileges via a modified authentication sequence, aka Bug ID CSCsv66530. | 2.0% | — |
| CVE-2002-2140 | MED 5.0 | cisco pix_firewall_software Buffer overflow in Cisco PIX Firewall 5.2.x to 5.2.8, 6.0.x to 6.0.3, 6.1.x to 6.1.3, and 6.2.x to 6.2.1 allows remote attackers to cause a denial of service via HTTP traffic authentication using (1) TACACS+ or (2) RADIUS. | 2.0% | — |
| CVE-2016-1402 | HIGH 7.5 | cisco identity_services_engine_software The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorization is enabled, allows remote attackers to cause a denial of service (authentication outage) via a crafted Passw | 2.0% | — |
| CVE-2015-4233 | MED 6.5 | cisco unified_meetingplace SQL injection vulnerability in Cisco Unified MeetingPlace 8.6(1.2) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuu54037. | 2.0% | — |