← Back

Cisco

cisco

6,580 CVEs • 6,222 products

Products (6,222)

Click to collapse
Toggle
Ios
ios
Ios Xe
ios_xe
Nx Os
nx_os
Ios Xr
ios_xr
Asyncos
asyncos
Asa 5500
asa_5500
Jabber
jabber

CVEs (6,580)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
14Adaptive Security Appliance Software
Dx Series Ip Phones FirmwareIos Xe+11 more
May 6, 2026
Apr 21, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686.
1Cisco
2Ios
Ios Xe
May 6, 2026
Apr 20, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The NTP implementation in Cisco IOS 15.1 and 15.5 and IOS XE 3.2 through 3.17 allows remote attackers to modify the system time via crafted packets, aka Bug ID CSCux46898.
1Cisco
1Unified Computing System Platform Emulator
May 6, 2026
Apr 16, 2016
N/A· v4
8.4 HIGH· v3
7.2 HIGH· v2
Heap-based buffer overflow in Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted libclimeta.so filename arguments, aka Bug ID CSCu...Show more
Heap-based buffer overflow in Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted libclimeta.so filename arguments, aka Bug ID CSCux68837.Show less
1Cisco
1Unified Computing System Platform Emulator
May 6, 2026
Apr 16, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted arguments on a ucspe-copy command line, aka Bug ID CSCux68832.
1Cisco
1Ios
May 6, 2026
Apr 14, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Cisco IOS before 15.2(2)E1 on Catalyst switches allows remote attackers to obtain potentially sensitive software-version information via a request to the Network Mobility Services Protocol (NMSP) port, aka Bug ID CSCum62...Show more
Cisco IOS before 15.2(2)E1 on Catalyst switches allows remote attackers to obtain potentially sensitive software-version information via a request to the Network Mobility Services Protocol (NMSP) port, aka Bug ID CSCum62591.Show less
1Cisco
1Unified Computing System Central Software
May 6, 2026
Apr 14, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Cisco Unified Computing System (UCS) Central Software 1.3(1b) and earlier allows remote attackers to execute arbitrary OS commands via a crafted HTTP request, aka Bug ID CSCuv33856.
1Cisco
1Unity Connection
May 6, 2026
Apr 12, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Cisco Unity Connection through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCus21776.
1Cisco
1Ios Xr
May 6, 2026
Apr 12, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Cisco IOS XR 4.2.3, 4.3.0, 4.3.4, and 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (CRC and symbol errors, and interface flap) via crafted bit patterns in packets, aka Bug ID CSCuv78548.
1Cisco
1Ip Interoperability And Collaboration System
May 6, 2026
Apr 8, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Cisco IP Interoperability and Collaboration System 4.10(1) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuy12339.
1Cisco
1Ucs Invicta C3124sa Appliance
May 6, 2026
Apr 6, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Cisco UCS Invicta C3124SA Appliance 4.3.1 through 5.0.1, UCS Invicta Scaling System and Appliance, and Whiptail Racerunner improperly store a default SSH private key, which allows remote attackers to obtain root access v...Show more
Cisco UCS Invicta C3124SA Appliance 4.3.1 through 5.0.1, UCS Invicta Scaling System and Appliance, and Whiptail Racerunner improperly store a default SSH private key, which allows remote attackers to obtain root access via unspecified vectors, aka Bug ID CSCun71294.Show less
2Cisco
Sun
3Evolved Programmable Network Manager
OpensolarisPrime Infrastructure
May 6, 2026
Apr 6, 2016
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID...Show more
Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID CSCuw03192.Show less
2Cisco
Sun
3Evolved Programmable Network Manager
OpensolarisPrime Infrastructure
May 6, 2026
Apr 6, 2016
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gain privileges via an H...Show more
The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gain privileges via an HTTP request that is inconsistent with a pattern filter, aka Bug ID CSCuy10227.Show less
1Cisco
2Asa With Firepower Services
Firesight System Software
May 6, 2026
Apr 1, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cisco FireSIGHT System Software 5.4.0 through 6.0.1 and ASA with FirePOWER Services 5.4.0 through 6.0.0.1 allow remote attackers to bypass malware protection via crafted fields in HTTP headers, aka Bug ID CSCux22726.
1Cisco
2Ios
Nx Os
May 6, 2026
Mar 26, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.1 and 15.2 and NX-OS 4.1 through 6.2 allows remote attackers to cause a denial of service (device reload) via a crafted header in a packet, aka Bug...Show more
The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.1 and 15.2 and NX-OS 4.1 through 6.2 allows remote attackers to cause a denial of service (device reload) via a crafted header in a packet, aka Bug ID CSCuu64279.Show less
6Cisco
LenovoSamsung+3 more
6Gs1900 10hp Firmware
Ios XeKeymouse Firmware+3 more
May 6, 2026
Mar 26, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager allow remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCuj23293.
7Cisco
IntelNetgear+4 more
7Core I5 9400f Firmware
Gs1900 10hp FirmwareIos Xe+4 more
May 6, 2026
Mar 26, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in a Smart Insta...Show more
The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in a Smart Install packet, aka Bug ID CSCuv45410.Show less
6Cisco
NetgearSamsung+3 more
6Gs1900 10hp Firmware
Ios XeJr6150 Firmware+3 more
May 6, 2026
Mar 26, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Cisco IOS 15.0 through 15.5 and IOS XE 3.3 through 3.16 allow remote attackers to cause a denial of service (device reload) via a crafted DHCPv6 Relay message, aka Bug ID CSCus55821.
7Cisco
LenovoNetgear+4 more
7Gs1900 10hp Firmware
Ios XeJr6150 Firmware+4 more
May 6, 2026
Mar 26, 2016
N/A· v4
5.9 MEDIUM· v3
7.1 HIGH· v2
The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of service (device reload) via fragmented packets, aka Bug ID CSCux38417.
1Cisco
1Ios Xr
May 6, 2026
Mar 24, 2016
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which allows remote authenticated users to cause a denial of service (overwri...Show more
The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which allows remote authenticated users to cause a denial of service (overwrite) via unspecified vectors, aka Bug ID CSCuw75848.Show less
1Cisco
1Ios
May 6, 2026
Mar 24, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The Wide Area Application Services (WAAS) Express implementation in Cisco IOS 15.1 through 15.5 allows remote attackers to cause a denial of service (device reload) via a crafted TCP segment, aka Bug ID CSCuq59708.