58.483 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
Vulnerabilità Cisco
6716 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-1499 | MED 5.3 | cisco hyperflex_hx_data_platform A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to upload files to an affected device. This vulnerability is due to missing authentication for the upload function. An att | 80,4% | — |
| CVE-2002-1359 | HIGH 10.0 | cisco ios Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol | 80,2% | — |
| CVE-2022-20705 | CRIT 10.0 | cisco rv160_firmware Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization prot | 80,0% | — |
| CVE-2020-16139 | HIGH 7.5 | cisco unified_ip_conference_station_7937g_firmware A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the device remotely through sending specially crafted packets. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, th | 79,8% | — |
| CVE-2019-1622 | MED 5.3 | cisco data_center_network_manager A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device. The vulnerability is due to improper access controls fo | 78,9% | — |
| CVE-2018-0127 | CRIT 9.8 | cisco rv132w_firmware A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to view configuration parameters for an affected device, which could lead to the d | 77,5% | — |
| CVE-2017-12243 | HIGH 7.8 | cisco firepower_4100_next-generation_firewall_firmware A vulnerability in the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to obtain root shell privileges on the de | 77,1% | — |
| CVE-2013-5486 | HIGH 10.0 | cisco prime_data_center_network_manager Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to write arbitrary files via the chartid parameter, aka Bug IDs CSCue77035 and CSCue77036. NOT | 76,0% | — |
| CVE-2019-1937 | CRIT 9.8 | cisco integrated_management_controller_supervisor A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to acquire a valid session token w | 75,9% | — |
| CVE-2020-3247 | CRIT 9.8 | cisco ucs_director Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulne | 75,6% | — |
| CVE-2022-20707 | CRIT 10.0 | cisco rv340_firmware Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization prot | 75,3% | — |
| CVE-2020-3248 | CRIT 9.8 | cisco ucs_director Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulne | 74,4% | — |
| CVE-2016-1287 | CRIT 9.8 | cisco adaptive_security_appliance_software Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0 before 9.0(4.38), 9.1 before 9.1(7), 9.2 before 9.2(4.5), 9.3 before 9.3(3.7), 9.4 before 9.4(2.4), and 9.5 before 9.5(2.2) on ASA 5500 dev | 74,2% | — |
| CVE-2014-0659 | HIGH 10.0 | cisco rvs4000 The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1, and RVS4000 router with firmware through 2.0.3.2 allow remote attackers to read credential and configuration data, and exe | 73,8% | — |
| CVE-2018-5390 | HIGH 7.5 | a10networks advanced_core_operating_system Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service. | 73,7% | — |
| CVE-2020-3239 | HIGH 8.8 | cisco ucs_director Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulne | 73,6% | — |
| CVE-2000-0945 | HIGH 10.0 | cisco catalyst_3500_xl The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory. | 72,6% | — |
| CVE-2021-1472 | MED 5.3 | cisco rv160_firmware Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these | 72,0% | — |
| CVE-2011-2039 | HIGH 7.6 | cisco anyconnect_secure_mobility_client The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.185 on Windows, and on Windows Mobile, downloads a client executable file (vpndownloader.exe) without verifying its authenticity, which allows remote | 70,0% | — |
| CVE-2001-0537 | HIGH 9.3 | cisco ios HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL. | 68,5% | — |
| CVE-2020-27130 | CRIT 9.1 | cisco security_manager A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character sequences within requests to an affected device. | 65,9% | — |
| CVE-2019-12630 | CRIT 9.8 | cisco security_manager A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied conte | 65,8% | — |
| CVE-2008-3558 | HIGH 9.3 | cisco webex_meeting_manager Stack-based buffer overflow in the WebexUCFObject ActiveX control in atucfobj.dll in Cisco WebEx Meeting Manager before 20.2008.2606.4919 allows remote attackers to execute arbitrary code via a long argument to the NewObject method. | 65,4% | — |
| CVE-2021-1473 | MED 5.3 | cisco rv340_firmware Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these | 64,4% | — |
| CVE-2017-6622 | CRIT 9.8 | cisco prime_collaboration_provisioning A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privileges. The vulnerability is due to missing security constraint | 62,2% | — |