Cisco
cisco
6,669 CVEs • 6,229 products
Products (6,229)
Click to collapseToggle
Products (6,229)
Click to collapse
CVEs (6,669)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 1Firesight System Software May 6, 2026 Sep 12, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1, when certain malware blocking options are enabled, allow remote attackers to bypass malware detection via crafted fields in HTTP head...Show more |
1Cisco 1Firesight System Software May 6, 2026 Sep 12, 2016 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1 allows remote authenticated users to inject arbitrar...Show more |
1Cisco 1Firesight System Software May 6, 2026 Sep 12, 2016 N/A· v4 9.1 CRITICAL· v3 5.8 MEDIUM· v2 Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hijack web sessions via a session identifier, aka Bug ID CSCuz80503. |
1Cisco 1Hosted Collaboration Mediation Fulfillment May 6, 2026 Sep 12, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10.6(3) and earlier allows remote attackers to write to arbitrary files via a crafted URL, aka Bug ID CSC...Show more |
1Cisco 1Hosted Collaboration Mediation Fulfillment May 6, 2026 Sep 12, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10.6(3) and earlier allows remote authenticated users to read arbitrary files via a crafted pathname in a...Show more |
1Cisco 6Wireless Lan Controller Software Wireless Lan Controller Software 6.0Wireless Lan Controller Software 7.0+3 moreMay 6, 2026 Sep 12, 2016 N/A· v4 5.3 MEDIUM· v3 5.7 MEDIUM· v2 Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow remote attackers to cause a denial of service (device reload) by sending crafted Inter-Acce...Show more |
1Cisco 2Spa300 Firmware Spa500 FirmwareMay 6, 2026 Sep 12, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The HTTP framework on Cisco SPA300, SPA500, and SPA51x devices allows remote attackers to cause a denial of service (device outage) via a series of malformed HTTP requests, aka Bug ID CSCut67385. |
1Cisco 1Media Origination System Suite May 6, 2026 Sep 3, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Media Origination System Suite Software 2.6 and earlier in Cisco Virtual Media Packager (VMP) allows remote attackers to bypass authentication and make arbitrary Platform and Applications Manager (PAM) API calls via unsp...Show more |
Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to execute arbitrary code via a crafted file, aka Bug ID CSCva09375. |
Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted file, aka Bug ID CSCuz80455. |
1Cisco 6Wireless Lan Controller Wireless Lan Controller 6.0Wireless Lan Controller 7.0+3 moreMay 6, 2026 Sep 2, 2016 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 The Adaptive Wireless Intrusion Prevention System (wIPS) feature on Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102.0 allows remote attackers to ca...Show more |
1Cisco 1Small Business 220 Series Smart Plus Switches May 6, 2026 Sep 2, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Cisco Small Business 220 devices with firmware before 1.0.1.1 have a hardcoded SNMP community, which allows remote attackers to read or modify SNMP objects by leveraging knowledge of this community, aka Bug ID CSCuz76216...Show more |
1Cisco 1Small Business 220 Series Smart Plus Switches May 6, 2026 Sep 2, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to cause a denial of service (interface outage) via a crafted HTTP request, aka Bug ID CSCuz7623...Show more |
1Cisco 1Small Business 220 Series Smart Plus Switches May 6, 2026 Sep 2, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted...Show more |
1Cisco 1Small Business 220 Series Smart Plus Switches May 6, 2026 Sep 2, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to hijack the authentication of arbitrary use...Show more |
6Cisco NodejsOpenssl+3 more9Content Security Management Appliance DatabaseEnterprise Linux+6 moreMay 29, 2026 Sep 1, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obt...Show more |
1Cisco 1Anyconnect Secure Mobility Client May 6, 2026 Aug 25, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Cisco AnyConnect Secure Mobility Client before 4.2.05015 and 4.3.x before 4.3.02039 mishandles pathnames, which allows local users to gain privileges via a crafted INF file, aka Bug ID CSCuz92464. |
1Cisco 1Secure Firewall Management Center May 6, 2026 Aug 23, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.0.2, 5.3.1, and 5.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka...Show more |
1Cisco 1Unified Communications Manager May 6, 2026 Aug 23, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The User Data Services (UDS) API implementation in Cisco Unified Communications Manager 11.5 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified API calls, aka...Show more |
Memory leak in Cisco IOS XR 5.1.x through 5.1.3, 5.2.x through 5.2.5, and 5.3.x through 5.3.2 on ASR 9001 devices allows remote attackers to cause a denial of service (control-plane protocol outage) via crafted fragmente...Show more |