← Back

Cisco

cisco

6,669 CVEs • 6,229 products

Products (6,229)

Click to collapse
Toggle
Ios
ios
Ios Xe
ios_xe
Nx Os
nx_os
Ios Xr
ios_xr
Asyncos
asyncos
Asa 5500
asa_5500
Jabber
jabber
Roomos
roomos

CVEs (6,669)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
3Rv110w Wireless N Vpn Firewall Firmware
Rv130w Wireless N Multifunction Vpn Router FirmwareRv215w Wireless N Vpn Router Firmware
May 6, 2026
Aug 8, 2016
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Cisco RV110W, RV130W, and RV215W devices have an incorrect RBAC configuration for the default account, which allows remote authenticated users to obtain root access via a login session with that account, aka Bug IDs CSCu...Show more
Cisco RV110W, RV130W, and RV215W devices have an incorrect RBAC configuration for the default account, which allows remote authenticated users to obtain root access via a login session with that account, aka Bug IDs CSCuv90139, CSCux58175, and CSCux73557.Show less
1Cisco
3Rv110w Wireless N Vpn Firewall Firmware
Rv130w Wireless N Multifunction Vpn Router FirmwareRv215w Wireless N Vpn Router Firmware
May 6, 2026
Aug 8, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The CLI command parser on Cisco RV110W, RV130W, and RV215W devices allows local users to execute arbitrary shell commands as an administrator via crafted parameters, aka Bug IDs CSCuv90134, CSCux58161, and CSCux73567.
1Cisco
1Asyncos
May 6, 2026
Aug 1, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cisco AsyncOS on Email Security Appliance (ESA) devices through 9.7.0-125 allows remote attackers to bypass malware detection via a crafted attachment in an e-mail message, aka Bug ID CSCuz14932.
1Cisco
1Videoscape Session Resource Manager
May 6, 2026
Jul 28, 2016
N/A· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
Cisco Videoscape Session Resource Manager (VSRM) allows remote attackers to cause a denial of service (device restart) by sending a traffic flood to upstream devices, aka Bug ID CSCva01813.
1Cisco
1Nx Os
May 6, 2026
Jul 28, 2016
N/A· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
Cisco Nexus 1000v Application Virtual Switch (AVS) devices before 5.2(1)SV3(1.5i) allow remote attackers to cause a denial of service (ESXi hypervisor crash and purple screen) via a crafted Cisco Discovery Protocol packe...Show more
Cisco Nexus 1000v Application Virtual Switch (AVS) devices before 5.2(1)SV3(1.5i) allow remote attackers to cause a denial of service (ESXi hypervisor crash and purple screen) via a crafted Cisco Discovery Protocol packet that triggers an out-of-bounds memory access, aka Bug ID CSCuw57985.Show less
1Cisco
1Firesight System Software
May 6, 2026
Jul 28, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cisco FireSIGHT System Software 5.3.0, 5.3.1, 5.4.0, 6.0, and 6.0.1 allows remote attackers to bypass Snort rules via crafted parameters in the header of an HTTP packet, aka Bug ID CSCuz20737.
1Cisco
1Prime Service Catalog
May 6, 2026
Jul 28, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Prime Service Catalog (PSC) 11.0 allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCu...Show more
Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Prime Service Catalog (PSC) 11.0 allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuz63795.Show less
1Cisco
1Wireless Lan Controller Software
May 6, 2026
Jul 28, 2016
N/A· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
Cisco Wireless LAN Controller (WLC) devices 7.4(121.0) and 8.0(0.30220.385) allow remote attackers to cause a denial of service via crafted wireless management frames, aka Bug ID CSCun92979.
1Cisco
1Unified Computing System Performance Manager
May 6, 2026
Jul 28, 2016
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The web framework in Cisco Unified Computing System (UCS) Performance Manager 2.0.0 and earlier allows remote authenticated users to execute arbitrary commands via crafted parameters in a GET request, aka Bug ID CSCuy078...Show more
The web framework in Cisco Unified Computing System (UCS) Performance Manager 2.0.0 and earlier allows remote authenticated users to execute arbitrary commands via crafted parameters in a GET request, aka Bug ID CSCuy07827.Show less
1Cisco
2Ios
Ios Xe
May 6, 2026
Jul 17, 2016
N/A· v4
5.3 MEDIUM· v3
4.9 MEDIUM· v2
Cisco IOS 12.4 and 15.0 through 15.5 and IOS XE 3.13 through 3.17 allow remote authenticated users to cause a denial of service (device reload) via crafted attributes in a BGP message, aka Bug ID CSCuz21061.
1Cisco
1Webex Meetings Server
May 6, 2026
Jul 17, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.7 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuy92706.
1Cisco
1Ios Xr
May 6, 2026
Jul 15, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The CLI in Cisco IOS XR 6.x through 6.0.1 allows local users to execute arbitrary OS commands in a privileged context by leveraging unspecified container access, aka Bug ID CSCuz62721.
1Cisco
2Asr 5000
Asr 5000 Software
May 6, 2026
Jul 15, 2016
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Cisco ASR 5000 devices with software 18.3 through 20.0.0 allow remote attackers to make configuration changes over SNMP by leveraging knowledge of the read-write community, aka Bug ID CSCuz29526.
1Cisco
1Meeting Server
May 6, 2026
Jul 15, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Meeting Server (formerly Acano Conferencing Server) 1.7 through 1.9 allows remote attackers to inject arbitrary web script or HTML v...Show more
Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Meeting Server (formerly Acano Conferencing Server) 1.7 through 1.9 allows remote attackers to inject arbitrary web script or HTML via crafted parameters, aka Bug ID CSCva19922.Show less
1Cisco
1Webex Meetings Server
May 6, 2026
Jul 15, 2016
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
Cisco WebEx Meetings Server 2.6 allows remote authenticated users to conduct command-injection attacks via vectors related to an upload's file type, aka Bug ID CSCuy92715.
1Cisco
1Webex Meetings Server
May 6, 2026
Jul 15, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Cisco WebEx Meetings Server 2.6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuy92711.
1Cisco
1Webex Meetings Server
May 6, 2026
Jul 15, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the administrator interface in Cisco WebEx Meetings Server 2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuy83194.
1Cisco
1Webex Meetings Server
May 6, 2026
Jul 15, 2016
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in Cisco WebEx Meetings Server 2.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuy83200.
1Cisco
1Ios Xr
May 6, 2026
Jul 15, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Cisco IOS XR 5.x through 5.2.5 on NCS 6000 devices allows remote attackers to cause a denial of service (timer consumption and Route Processor reload) via crafted SSH traffic, aka Bug ID CSCux76819.
1Cisco
1Adaptive Security Appliance Software
May 6, 2026
Jul 12, 2016
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Cisco Adaptive Security Appliance (ASA) Software 8.2 through 9.4.3.3 allows remote attackers to bypass intended ICMP Echo Reply ACLs via vectors related to subtypes.