Cisco
cisco
6,669 CVEs • 6,229 products
Products (6,229)
Click to collapseToggle
Products (6,229)
Click to collapse
CVEs (6,669)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 2Telepresence Video Communication Server Telepresence Video Communication Server SoftwareMay 6, 2026 Jul 7, 2016 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 and Expressway X8.1 through X8.6 mishandles certificates, which allows remote attackers to bypass auth...Show more |
1Cisco 1Amp Threat Grid Appliance May 6, 2026 Jul 7, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The virtual network stack on Cisco AMP Threat Grid Appliance devices before 2.1.1 allows remote attackers to bypass a sandbox protection mechanism, and consequently obtain sensitive interprocess information or modify int...Show more |
The administrative web interface in Cisco Prime Infrastructure (PI) before 3.1.1 allows remote authenticated users to execute arbitrary commands via crafted field values, aka Bug ID CSCuy96280. |
Cisco IOS 15.0(2)SG5, 15.1(2)SG3, 15.2(1)E, 15.3(3)S, and 15.4(1.13)S allows remote attackers to cause a denial of service (device crash) via a crafted LLDP packet, aka Bug ID CSCun66735. |
1Cisco 3Rv110w Firmware Rv130w FirmwareRv215w FirmwareMay 6, 2026 Jul 3, 2016 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 Buffer overflow in the web-based management interface on Cisco RV110W devices with firmware through 1.2.1.4, RV130W devices with firmware through 1.0.2.7, and RV215W devices with firmware through 1.3.0.7 allows remote au...Show more |
Cisco EPC3928 devices allow remote attackers to obtain sensitive configuration and credential information by making requests during the early part of the boot process, related to a "Boot Information Disclosure" issue, ak...Show more |
goform/Docsis_system on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long LanguageSelect parameter, related to a "Gateway HTTP Corruption Denial of Service" issue, aka B...Show more |
goform/WClientMACList on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long h_sortWireless parameter, related to a "Gateway Client List Denial of Service" issue, aka Bug...Show more |
1Cisco 1Cloud Network Automation Provisioner May 6, 2026 Jul 3, 2016 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 Cisco Cloud Network Automation Provisioner (CNAP) 1.0(0) in Cisco Configuration Assistant (CCA) allows remote attackers to bypass intended filesystem and administrative-endpoint restrictions via GET API calls, aka Bug ID...Show more |
Cisco Firepower System Software 6.0.0 through 6.1.0 has a hardcoded account, which allows remote attackers to obtain CLI access by leveraging knowledge of the password, aka Bug ID CSCuz56238. |
The proxy process on Cisco Web Security Appliance (WSA) devices through 9.1.0-070 allows remote attackers to cause a denial of service (CPU consumption) by establishing an FTP session and then improperly terminating the...Show more |
1Cisco 1Prime Collaboration Provisioning May 6, 2026 Jul 2, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Cisco Prime Collaboration Provisioning 10.6 SP2 (aka 10.6.0.10602) mishandles LDAP authentication, which allows remote attackers to obtain administrator privileges via a crafted login attempt, aka Bug ID CSCuv37513. |
1Cisco 2Evolved Programmable Network Manager Prime InfrastructureMay 6, 2026 Jul 2, 2016 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Cisco Prime Infrastructure 1.2 through 3.1 and Evolved Programmable Network Manager (EPNM) 1.2 and 2.0 allow remote authenticated users to execute arbitrary commands or upload files via a crafted HTTP request, aka Bug ID...Show more |
1Cisco 2Evolved Programmable Network Manager Prime InfrastructureMay 6, 2026 Jul 2, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The API in Cisco Prime Infrastructure 1.2 through 3.0 and Evolved Programmable Network Manager (EPNM) 1.2 allows remote attackers to execute arbitrary code or obtain sensitive management information via a crafted HTTP re...Show more |
1Cisco 1Unified Contact Center Enterprise May 6, 2026 Jun 23, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Contact Center Enterprise through 10.5(2) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID...Show more |
Cisco AsyncOS 9.7.0-125 on Email Security Appliance (ESA) devices allows remote attackers to bypass intended spam filtering via crafted executable content in a ZIP archive, aka Bug ID CSCuy39210. |
1Cisco 1Prime Collaboration Deployment May 6, 2026 Jun 23, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 SQL injection vulnerability in the SQL database in Cisco Prime Collaboration Deployment before 11.5.1 allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuy92549. |
The General Packet Radio Switching Tunneling Protocol 1 (aka GTPv1) implementation on Cisco ASR 5000 Packet Data Network Gateway devices before 19.4 allows remote attackers to cause a denial of service (Session Manager p...Show more |
1Cisco 1Ip Phone 8800 Series Firmware May 6, 2026 Jun 23, 2016 N/A· v4 7.0 HIGH· v3 6.2 MEDIUM· v2 Cisco 8800 phones with software 11.0(1) do not properly enforce mounted-filesystem permissions, which allows local users to write to arbitrary files by leveraging shell access, aka Bug ID CSCuz03014. |
1Cisco 1Ip Phone 8800 Series Firmware May 6, 2026 Jun 23, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The license-certificate upload functionality on Cisco 8800 phones with software 11.0(1) allows remote authenticated users to delete arbitrary files via an invalid file, aka Bug ID CSCuz03010. |