Cisco
cisco
6,669 CVEs • 6,229 products
Products (6,229)
Click to collapseToggle
Products (6,229)
Click to collapse
CVEs (6,669)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 1Adaptive Security Appliance Software May 6, 2026 Jan 15, 2016 N/A· v4 4.3 MEDIUM· v3 3.5 LOW· v2 The DCERPC Inspection implementation in Cisco Adaptive Security Appliance (ASA) Software 9.4.1 through 9.5.1 allows remote authenticated users to bypass an intended DCERPC-only ACL by sending arbitrary network traffic, a...Show more |
1Cisco 1Aironet Access Point Software May 6, 2026 Jan 15, 2016 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 Cisco Aironet 1800 devices with software 7.2, 7.3, 7.4, 8.1(112.3), 8.1(112.4), and 8.1(15.14) have a default account, which makes it easier for remote attackers to obtain access via unspecified vectors, aka Bug ID CSCuw...Show more |
1Cisco 1Identity Services Engine Software May 6, 2026 Jan 15, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Admin portal in Cisco Identity Services Engine (ISE) 1.1.x, 1.2.0 before patch 17, 1.2.1 before patch 8, 1.3 before patch 5, and 1.4 before patch 4 allows remote attackers to obtain administrative access via unspecif...Show more |
1Cisco 1Aironet Access Point Software May 6, 2026 Jan 15, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The IP ingress packet handler on Cisco Aironet 1800 devices with software 8.1(112.3) and 8.1(112.4) allows remote attackers to cause a denial of service via a crafted header in an IP packet, aka Bug ID CSCuv63138. |
1Cisco 1Wireless Lan Controller Software May 6, 2026 Jan 15, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 before 8.1.131.0 allow remote attackers to change configuration settings via unspecified vectors, aka Bug ID CSCuw06153. |
Cisco Prime Infrastructure does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a...Show more |
1Cisco 1Unified Communications Manager May 6, 2026 Jan 8, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 SQL injection vulnerability in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCut66767. |
Cisco IOS XR 4.2.0, 4.3.0, 5.0.0, 5.1.0, 5.2.0, 5.2.2, 5.2.4, 5.3.0, and 5.3.2 does not properly restrict the number of Path Computation Elements (PCEs) for OSPF LSA opaque area updates, which allows remote attackers to...Show more |
Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks and trigger cleartext XMPP sessions via unspecified vectors, aka Bug ID CSCuw87419. |
Cisco IOS XE 16.1.1 allows remote attackers to cause a denial of service (device reload) via a packet with the 00-00-00-00-00-00 source MAC address, aka Bug ID CSCux48405. |
The IKEv1 state machine in Cisco IOS 15.4 through 15.6 and IOS XE 3.15 through 3.17 allows remote attackers to cause a denial of service (IPsec connection termination) via a crafted IKEv1 packet to a tunnel endpoint, aka...Show more |
1Cisco 1Dpq3925 8x4 Docsis 3.0 Wireless Residential Gateway With Embedded Digital Voice Adapter May 6, 2026 Dec 18, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Cisco DPQ3925 devices with EDVA r1 Base allow remote attackers to obtain sensitive information via a crafted HTTP request, aka Bug ID CSCuv03958. |
Cisco FireSIGHT Management Center allows remote attackers to bypass the HTTP attack detection feature and avoid triggering Snort IDS rules via an SSL session that is mishandled after decryption, aka Bug ID CSCux53437. |
1Cisco 1Prime Network Services Controller May 6, 2026 Dec 18, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 Cisco Prime Network Services Controller 3.0 allows local users to bypass intended access restrictions and execute arbitrary commands via additional parameters to an unspecified command, aka Bug ID CSCus99427. |
1Cisco 1Application Policy Infrastructure Controller May 6, 2026 Dec 18, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) allows local users to bypass intended access restrictions and obtain single-user-mode root access via unspecified vectors, aka Bug...Show more |
1Cisco 1Unified Communications Manager May 6, 2026 Dec 16, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The WebApplications Identity Management subsystem in Cisco Unified Communications Manager 10.5(0.98000.88) allows remote attackers to cause a denial of service (subsystem outage) via invalid session tokens, aka Bug ID CS...Show more |
1Cisco 1Secure Firewall Management Center May 6, 2026 Dec 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Cisco FirePOWER Management Center 5.4.1.3, 6.0.0, and 6.0.1 provides verbose responses to requests for help files, which allows remote attackers to obtain potentially sensitive version information by reading an unspecifi...Show more |
1Cisco 1Hosted Collaboration Solution May 6, 2026 Dec 15, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Cisco Hosted Collaboration Mediation Fulfillment 10.6(3) does not use RBAC, which allows remote authenticated users to obtain sensitive credential information by leveraging admin access and making SOAP API requests, aka...Show more |
The TFTP implementation on Cisco Small Business SPA30x, SPA50x, SPA51x phones 7.5.7 improperly validates firmware-image file integrity, which allows local users to load a Trojan horse image by leveraging shell access, ak...Show more |
1Cisco 1Integrated Management Controller Supervisor May 6, 2026 Dec 15, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The Supervisor 1.0.0.0 and 1.0.0.1 in Cisco Integrated Management Controller (IMC) before 2.0(9) allows remote authenticated users to cause a denial of service (IP interface outage) via crafted parameters in an HTTP requ...Show more |