← Back

Cisco

cisco

6,580 CVEs • 6,222 products

Products (6,222)

Click to collapse
Toggle
Ios
ios
Ios Xe
ios_xe
Nx Os
nx_os
Ios Xr
ios_xr
Asyncos
asyncos
Asa 5500
asa_5500
Jabber
jabber

CVEs (6,580)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Secure Firewall Management Center
May 6, 2026
Aug 18, 2016
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.3.1.2, and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Se...Show more
The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.3.1.2, and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.3.1.2, and 5.4.x before 5.4.0.1 allows remote authenticated users to increase user-account privileges via crafted HTTP requests, aka Bug ID CSCur25483.Show less
1Cisco
1Secure Firewall Management Center
May 6, 2026
Aug 18, 2016
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x before...Show more
The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 allows remote authenticated users to execute arbitrary commands as root via crafted HTTP requests, aka Bug ID CSCur25513.Show less
1Cisco
1Application Policy Infrastructure Controller Enterprise Module
May 6, 2026
Aug 18, 2016
N/A· v4
8.8 HIGH· v3
8.5 HIGH· v2
The Grapevine update process in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0 allows remote authenticated users to execute arbitrary commands as root via a crafted upgrade parameter,...Show more
The Grapevine update process in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0 allows remote authenticated users to execute arbitrary commands as root via a crafted upgrade parameter, aka Bug ID CSCux15507.Show less
1Cisco
1Adaptive Security Appliance Software
Apr 22, 2026
Aug 18, 2016
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA.
1Cisco
3Adaptive Security Appliance Software
Asa 1000v Cloud Firewall SoftwarePix Firewall Software
Apr 22, 2026
Aug 18, 2016
N/A· v4
8.8 HIGH· v3
8.5 HIGH· v2
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote a...Show more
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON.Show less
1Cisco
1Ios
May 6, 2026
Aug 8, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Cisco IOS 15.5(3)S3, 15.6(1)S2, 15.6(2)S1, and 15.6(2)T1 does not properly dequeue invalid NTP packets, which allows remote attackers to cause a denial of service (interface wedge) by sending many crafted NTP packets, ak...Show more
Cisco IOS 15.5(3)S3, 15.6(1)S2, 15.6(2)S1, and 15.6(2)T1 does not properly dequeue invalid NTP packets, which allows remote attackers to cause a denial of service (interface wedge) by sending many crafted NTP packets, aka Bug ID CSCva35619.Show less
1Cisco
1Prime Infrastructure
May 6, 2026
Aug 8, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Cisco Prime Infrastructure 2.2(2) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, relate...Show more
Cisco Prime Infrastructure 2.2(2) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCuw65846, a different vulnerability than CVE-2015-6434.Show less
1Cisco
1Telepresence Video Communication Server
May 6, 2026
Aug 8, 2016
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The administrative web interface in Cisco TelePresence Video Communication Server Expressway X8.5.2 allows remote authenticated users to execute arbitrary commands via crafted fields, aka Bug ID CSCuv12531.
1Cisco
1Unified Communications Manager Im And Presence Service
May 6, 2026
Aug 8, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Cisco Unified Communications Manager IM and Presence Service 9.1(1) SU6, 9.1(1) SU6a, 9.1(1) SU7, 10.5(2) SU2, 10.5(2) SU2a, 11.0(1) SU1, and 11.5(1) allows remote attackers to cause a denial of service (sipd process res...Show more
Cisco Unified Communications Manager IM and Presence Service 9.1(1) SU6, 9.1(1) SU6a, 9.1(1) SU7, 10.5(2) SU2, 10.5(2) SU2a, 11.0(1) SU1, and 11.5(1) allows remote attackers to cause a denial of service (sipd process restart) via crafted headers in a SIP packet, aka Bug ID CSCva39072.Show less
1Cisco
2Rv180 Vpn Router Firmware
Rv180w Vpn Router Firmware
May 6, 2026
Aug 8, 2016
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Cisco RV180 and RV180W devices allow remote authenticated users to execute arbitrary commands as root via a crafted HTTP request, aka Bug ID CSCuz48592.
1Cisco
2Rv180 Vpn Router Firmware
Rv180w Wireless N Multifunction Vpn Router Firmware
May 6, 2026
Aug 8, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Directory traversal vulnerability in the web interface on Cisco RV180 and RV180W devices allows remote attackers to read arbitrary files via a crafted HTTP request, aka Bug ID CSCuz43023.
1Cisco
3Rv110w Wireless N Vpn Firewall Firmware
Rv130w Wireless N Multifunction Vpn Router FirmwareRv215w Wireless N Vpn Router Firmware
May 6, 2026
Aug 8, 2016
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Cisco RV110W, RV130W, and RV215W devices have an incorrect RBAC configuration for the default account, which allows remote authenticated users to obtain root access via a login session with that account, aka Bug IDs CSCu...Show more
Cisco RV110W, RV130W, and RV215W devices have an incorrect RBAC configuration for the default account, which allows remote authenticated users to obtain root access via a login session with that account, aka Bug IDs CSCuv90139, CSCux58175, and CSCux73557.Show less
1Cisco
3Rv110w Wireless N Vpn Firewall Firmware
Rv130w Wireless N Multifunction Vpn Router FirmwareRv215w Wireless N Vpn Router Firmware
May 6, 2026
Aug 8, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The CLI command parser on Cisco RV110W, RV130W, and RV215W devices allows local users to execute arbitrary shell commands as an administrator via crafted parameters, aka Bug IDs CSCuv90134, CSCux58161, and CSCux73567.
1Cisco
1Asyncos
May 6, 2026
Aug 1, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cisco AsyncOS on Email Security Appliance (ESA) devices through 9.7.0-125 allows remote attackers to bypass malware detection via a crafted attachment in an e-mail message, aka Bug ID CSCuz14932.
1Cisco
1Videoscape Session Resource Manager
May 6, 2026
Jul 28, 2016
N/A· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
Cisco Videoscape Session Resource Manager (VSRM) allows remote attackers to cause a denial of service (device restart) by sending a traffic flood to upstream devices, aka Bug ID CSCva01813.
1Cisco
1Nx Os
May 6, 2026
Jul 28, 2016
N/A· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
Cisco Nexus 1000v Application Virtual Switch (AVS) devices before 5.2(1)SV3(1.5i) allow remote attackers to cause a denial of service (ESXi hypervisor crash and purple screen) via a crafted Cisco Discovery Protocol packe...Show more
Cisco Nexus 1000v Application Virtual Switch (AVS) devices before 5.2(1)SV3(1.5i) allow remote attackers to cause a denial of service (ESXi hypervisor crash and purple screen) via a crafted Cisco Discovery Protocol packet that triggers an out-of-bounds memory access, aka Bug ID CSCuw57985.Show less
1Cisco
1Firesight System Software
May 6, 2026
Jul 28, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cisco FireSIGHT System Software 5.3.0, 5.3.1, 5.4.0, 6.0, and 6.0.1 allows remote attackers to bypass Snort rules via crafted parameters in the header of an HTTP packet, aka Bug ID CSCuz20737.
1Cisco
1Prime Service Catalog
May 6, 2026
Jul 28, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Prime Service Catalog (PSC) 11.0 allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCu...Show more
Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Prime Service Catalog (PSC) 11.0 allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuz63795.Show less
1Cisco
1Wireless Lan Controller Software
May 6, 2026
Jul 28, 2016
N/A· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
Cisco Wireless LAN Controller (WLC) devices 7.4(121.0) and 8.0(0.30220.385) allow remote attackers to cause a denial of service via crafted wireless management frames, aka Bug ID CSCun92979.
1Cisco
1Unified Computing System Performance Manager
May 6, 2026
Jul 28, 2016
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The web framework in Cisco Unified Computing System (UCS) Performance Manager 2.0.0 and earlier allows remote authenticated users to execute arbitrary commands via crafted parameters in a GET request, aka Bug ID CSCuy078...Show more
The web framework in Cisco Unified Computing System (UCS) Performance Manager 2.0.0 and earlier allows remote authenticated users to execute arbitrary commands via crafted parameters in a GET request, aka Bug ID CSCuy07827.Show less