← Back

Cisco

cisco

6,580 CVEs • 6,222 products

Products (6,222)

Click to collapse
Toggle
Ios
ios
Ios Xe
ios_xe
Nx Os
nx_os
Ios Xr
ios_xr
Asyncos
asyncos
Asa 5500
asa_5500
Jabber
jabber

CVEs (6,580)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
2Ios
Ios Xe
May 6, 2026
Jul 17, 2016
N/A· v4
5.3 MEDIUM· v3
4.9 MEDIUM· v2
Cisco IOS 12.4 and 15.0 through 15.5 and IOS XE 3.13 through 3.17 allow remote authenticated users to cause a denial of service (device reload) via crafted attributes in a BGP message, aka Bug ID CSCuz21061.
1Cisco
1Webex Meetings Server
May 6, 2026
Jul 17, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.7 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuy92706.
1Cisco
1Ios Xr
May 6, 2026
Jul 15, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The CLI in Cisco IOS XR 6.x through 6.0.1 allows local users to execute arbitrary OS commands in a privileged context by leveraging unspecified container access, aka Bug ID CSCuz62721.
1Cisco
2Asr 5000
Asr 5000 Software
May 6, 2026
Jul 15, 2016
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Cisco ASR 5000 devices with software 18.3 through 20.0.0 allow remote attackers to make configuration changes over SNMP by leveraging knowledge of the read-write community, aka Bug ID CSCuz29526.
1Cisco
1Meeting Server
May 6, 2026
Jul 15, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Meeting Server (formerly Acano Conferencing Server) 1.7 through 1.9 allows remote attackers to inject arbitrary web script or HTML v...Show more
Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Meeting Server (formerly Acano Conferencing Server) 1.7 through 1.9 allows remote attackers to inject arbitrary web script or HTML via crafted parameters, aka Bug ID CSCva19922.Show less
1Cisco
1Webex Meetings Server
May 6, 2026
Jul 15, 2016
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
Cisco WebEx Meetings Server 2.6 allows remote authenticated users to conduct command-injection attacks via vectors related to an upload's file type, aka Bug ID CSCuy92715.
1Cisco
1Webex Meetings Server
May 6, 2026
Jul 15, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Cisco WebEx Meetings Server 2.6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuy92711.
1Cisco
1Webex Meetings Server
May 6, 2026
Jul 15, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the administrator interface in Cisco WebEx Meetings Server 2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuy83194.
1Cisco
1Webex Meetings Server
May 6, 2026
Jul 15, 2016
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in Cisco WebEx Meetings Server 2.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuy83200.
1Cisco
1Ios Xr
May 6, 2026
Jul 15, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Cisco IOS XR 5.x through 5.2.5 on NCS 6000 devices allows remote attackers to cause a denial of service (timer consumption and Route Processor reload) via crafted SSH traffic, aka Bug ID CSCux76819.
1Cisco
1Adaptive Security Appliance Software
May 6, 2026
Jul 12, 2016
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Cisco Adaptive Security Appliance (ASA) Software 8.2 through 9.4.3.3 allows remote attackers to bypass intended ICMP Echo Reply ACLs via vectors related to subtypes.
1Cisco
2Telepresence Video Communication Server
Telepresence Video Communication Server Software
May 6, 2026
Jul 7, 2016
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 and Expressway X8.1 through X8.6 mishandles certificates, which allows remote attackers to bypass auth...Show more
The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 and Expressway X8.1 through X8.6 mishandles certificates, which allows remote attackers to bypass authentication via an arbitrary trusted certificate, aka Bug ID CSCuz64601.Show less
1Cisco
1Amp Threat Grid Appliance
May 6, 2026
Jul 7, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The virtual network stack on Cisco AMP Threat Grid Appliance devices before 2.1.1 allows remote attackers to bypass a sandbox protection mechanism, and consequently obtain sensitive interprocess information or modify int...Show more
The virtual network stack on Cisco AMP Threat Grid Appliance devices before 2.1.1 allows remote attackers to bypass a sandbox protection mechanism, and consequently obtain sensitive interprocess information or modify interprocess data, via a crafted malware sample.Show less
1Cisco
1Prime Infrastructure
May 6, 2026
Jul 7, 2016
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The administrative web interface in Cisco Prime Infrastructure (PI) before 3.1.1 allows remote authenticated users to execute arbitrary commands via crafted field values, aka Bug ID CSCuy96280.
1Cisco
1Ios
May 6, 2026
Jul 3, 2016
N/A· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
Cisco IOS 15.0(2)SG5, 15.1(2)SG3, 15.2(1)E, 15.3(3)S, and 15.4(1.13)S allows remote attackers to cause a denial of service (device crash) via a crafted LLDP packet, aka Bug ID CSCun66735.
1Cisco
3Rv110w Firmware
Rv130w FirmwareRv215w Firmware
May 6, 2026
Jul 3, 2016
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
Buffer overflow in the web-based management interface on Cisco RV110W devices with firmware through 1.2.1.4, RV130W devices with firmware through 1.0.2.7, and RV215W devices with firmware through 1.3.0.7 allows remote au...Show more
Buffer overflow in the web-based management interface on Cisco RV110W devices with firmware through 1.2.1.4, RV130W devices with firmware through 1.0.2.7, and RV215W devices with firmware through 1.3.0.7 allows remote authenticated users to cause a denial of service (device reload) via a crafted HTTP request, aka Bug ID CSCux86669.Show less
1Cisco
1Epc3928 Firmware
May 6, 2026
Jul 3, 2016
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Cisco EPC3928 devices allow remote attackers to obtain sensitive configuration and credential information by making requests during the early part of the boot process, related to a "Boot Information Disclosure" issue, ak...Show more
Cisco EPC3928 devices allow remote attackers to obtain sensitive configuration and credential information by making requests during the early part of the boot process, related to a "Boot Information Disclosure" issue, aka Bug ID CSCux17178.Show less
1Cisco
1Epc3928 Firmware
May 6, 2026
Jul 3, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
goform/Docsis_system on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long LanguageSelect parameter, related to a "Gateway HTTP Corruption Denial of Service" issue, aka B...Show more
goform/Docsis_system on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long LanguageSelect parameter, related to a "Gateway HTTP Corruption Denial of Service" issue, aka Bug ID CSCuy28100.Show less
1Cisco
1Epc3928 Firmware
May 6, 2026
Jul 3, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
goform/WClientMACList on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long h_sortWireless parameter, related to a "Gateway Client List Denial of Service" issue, aka Bug...Show more
goform/WClientMACList on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long h_sortWireless parameter, related to a "Gateway Client List Denial of Service" issue, aka Bug ID CSCux24948.Show less
1Cisco
1Cloud Network Automation Provisioner
May 6, 2026
Jul 3, 2016
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
Cisco Cloud Network Automation Provisioner (CNAP) 1.0(0) in Cisco Configuration Assistant (CCA) allows remote attackers to bypass intended filesystem and administrative-endpoint restrictions via GET API calls, aka Bug ID...Show more
Cisco Cloud Network Automation Provisioner (CNAP) 1.0(0) in Cisco Configuration Assistant (CCA) allows remote attackers to bypass intended filesystem and administrative-endpoint restrictions via GET API calls, aka Bug ID CSCuy77145.Show less