Cisco
cisco
6,580 CVEs • 6,222 products
Products (6,222)
Click to collapseToggle
Products (6,222)
Click to collapse
CVEs (6,580)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted file, aka Bug ID CSCuz80455. |
1Cisco 6Wireless Lan Controller Wireless Lan Controller 6.0Wireless Lan Controller 7.0+3 moreMay 6, 2026 Sep 2, 2016 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 The Adaptive Wireless Intrusion Prevention System (wIPS) feature on Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102.0 allows remote attackers to ca...Show more |
1Cisco 1Small Business 220 Series Smart Plus Switches May 6, 2026 Sep 2, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Cisco Small Business 220 devices with firmware before 1.0.1.1 have a hardcoded SNMP community, which allows remote attackers to read or modify SNMP objects by leveraging knowledge of this community, aka Bug ID CSCuz76216...Show more |
1Cisco 1Small Business 220 Series Smart Plus Switches May 6, 2026 Sep 2, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to cause a denial of service (interface outage) via a crafted HTTP request, aka Bug ID CSCuz7623...Show more |
1Cisco 1Small Business 220 Series Smart Plus Switches May 6, 2026 Sep 2, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted...Show more |
1Cisco 1Small Business 220 Series Smart Plus Switches May 6, 2026 Sep 2, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to hijack the authentication of arbitrary use...Show more |
6Cisco NodejsOpenssl+3 more9Content Security Management Appliance DatabaseEnterprise Linux+6 moreMay 29, 2026 Sep 1, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obt...Show more |
1Cisco 1Anyconnect Secure Mobility Client May 6, 2026 Aug 25, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Cisco AnyConnect Secure Mobility Client before 4.2.05015 and 4.3.x before 4.3.02039 mishandles pathnames, which allows local users to gain privileges via a crafted INF file, aka Bug ID CSCuz92464. |
1Cisco 1Secure Firewall Management Center May 6, 2026 Aug 23, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.0.2, 5.3.1, and 5.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka...Show more |
1Cisco 1Unified Communications Manager May 6, 2026 Aug 23, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The User Data Services (UDS) API implementation in Cisco Unified Communications Manager 11.5 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified API calls, aka...Show more |
Memory leak in Cisco IOS XR 5.1.x through 5.1.3, 5.2.x through 5.2.5, and 5.3.x through 5.3.2 on ASR 9001 devices allows remote attackers to cause a denial of service (control-plane protocol outage) via crafted fragmente...Show more |
Cisco WebEx Meetings Server 2.6 allows remote attackers to bypass intended access restrictions and obtain sensitive application information via unspecified vectors, aka Bug ID CSCuy92724. |
1Cisco 1Connected Streaming Analytics May 6, 2026 Aug 23, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Cisco Connected Streaming Analytics 1.1.1 allows remote authenticated users to discover a notification service password by reading administrative pages, aka Bug ID CSCuz92891. |
1Cisco 1Aironet Access Point Software May 6, 2026 Aug 22, 2016 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 The rate-limit feature in the 802.11 protocol implementation on Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.121.0 and 8.3.x before 8.3.102.0 allows remote attackers to cause a denial of service (d...Show more |
1Cisco 1Aironet Access Point Software May 6, 2026 Aug 22, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.110.0, 8.2.12x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow local users to gain privileges via crafted CLI parameters, aka Bug ID CSCuz24725. |
1Cisco 1Aironet Access Point Software May 6, 2026 Aug 22, 2016 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 The Aggregated MAC Protocol Data Unit (AMPDU) implementation on Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.121.0 and 8.3.x before 8.3.102.0 allows remote attackers to cause a denial of service (d...Show more |
1Cisco 1Transport Gateway Installation Software May 6, 2026 Aug 22, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Cisco Transport Gateway Installation Software 4.1(4.0) on Smart Call Home Transport Gateway devices allows remote attackers to inject arbitrary web script or HTML via a crafted...Show more |
1Cisco 1Identity Services Engine Software May 6, 2026 Aug 22, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Cisco Identity Services Engine 1.3(0.876) allows remote attackers to inject arbitrary web script or HTML via crafted parameters, aka Bug ID CSCva46497. |
1Cisco 1Ip Phone 8800 Series Firmware May 6, 2026 Aug 22, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Cisco IP Phone 8800 devices with software 11.0(1) allow remote attackers to cause a denial of service (memory corruption) via a crafted HTTP request, aka Bug ID CSCuz03038. |
1Cisco 1Ip Phone 8800 Series Firmware May 6, 2026 Aug 22, 2016 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability on Cisco IP Phone 8800 devices with software 11.0 allows remote authenticated users to inject arbitrary web script or HTML via crafted parameters, aka Bug ID CSCuz03024. |