Cisco
cisco
6,580 CVEs • 6,222 products
Products (6,222)
Click to collapseToggle
Products (6,222)
Click to collapse
CVEs (6,580)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The web framework in Cisco WebEx Meetings Server produces different returned messages for URL requests depending on whether a username exists, which allows remote attackers to enumerate user accounts via a series of requ...Show more |
1Cisco 1Unified Communications Domain Manager May 6, 2026 Jan 10, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Cisco Unified Communication Domain Manager Platform Software allows remote attackers to cause a denial of service (CPU consumption, and performance degradation or service outage) via a flood of malformed TCP packets and...Show more |
The play/modules component in Cisco WebEx Meetings Server allows remote attackers to obtain administrator access via crafted API requests, aka Bug ID CSCuj40421. |
The OutlookAction LI in Cisco WebEx Meetings Server allows remote authenticated users to obtain sensitive encrypted-password information via unspecified vectors, aka Bug IDs CSCuj40453 and CSCuj40449. |
Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj40456. |
Cross-site scripting (XSS) vulnerability in sendPwMail.do in Cisco WebEx Meetings Server allows remote attackers to inject arbitrary web script or HTML via the email parameter, aka Bug ID CSCuj40381. |
Open redirect vulnerability in the web interface in Cisco Secure Access Control System (ACS) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter, aka...Show more |
Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Secure Access Control System (ACS) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CS...Show more |
The RBAC component in Cisco Secure Access Control System (ACS) allows remote authenticated users to obtain Network Device Administrator privileges for Create, Delete, Read, and Update operations via crafted HTTP requests...Show more |
1Cisco 6Meraki Mr Meraki Mr FirmwareMeraki Ms+3 moreMay 6, 2026 Dec 24, 2014 N/A· v4 N/A· v3 7.7 HIGH· v2 Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote authenticated users to install arbitrary firmware by leveraging unspecified HTTP handler access on the local network, aka Cisco-Meraki defe...Show more |
1Cisco 6Meraki Mr Meraki Mr FirmwareMeraki Ms+3 moreMay 6, 2026 Dec 24, 2014 N/A· v4 N/A· v3 7.2 HIGH· v2 Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow physically proximate attackers to obtain shell access by opening a device's case and connecting a cable to a serial port, aka Cisco-Meraki defect...Show more |
1Cisco 6Meraki Mr Meraki Mr FirmwareMeraki Ms+3 moreMay 6, 2026 Dec 24, 2014 N/A· v4 N/A· v3 5.4 MEDIUM· v2 Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote attackers to execute arbitrary commands by leveraging knowledge of a cross-device secret and a per-device secret, and sending a request to...Show more |
1Cisco 3Meraki Mr Firmware Meraki Ms FirmwareMeraki Mx FirmwareMay 6, 2026 Dec 24, 2014 N/A· v4 N/A· v3 3.3 LOW· v2 Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote attackers to obtain sensitive credential information by leveraging unspecified HTTP handler access on the local network, aka Cisco-Meraki d...Show more |
Cross-site scripting (XSS) vulnerability in the Guest Server in Cisco Jabber allows remote attackers to inject arbitrary web script or HTML via a (1) GET or (2) POST parameter, aka Bug ID CSCus08074. |
The API in the Guest Server in Cisco Jabber, when HTML5 is used, allows remote attackers to obtain sensitive information by sniffing the network during an HTTP (1) GET or (2) POST response, aka Bug ID CSCus19801. |
The API in the Guest Server in Cisco Jabber, when the HTML5 CORS feature is used, allows remote attackers to obtain sensitive information by sniffing the network during an HTTP (1) GET or (2) POST request, aka Bug ID CSC...Show more |
1Cisco 1Unified Communications Domain Manager May 6, 2026 Dec 22, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in Business Voice Services Manager (BVSM) pages in the Application Software in Cisco Unified Communications Domain Manager 8 allow remote attackers to inject arbitrary...Show more |
1Cisco 1Identity Services Engine Software May 6, 2026 Dec 22, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The periodic-backup feature in Cisco Identity Services Engine (ISE) allows remote attackers to discover backup-encryption passwords via a crafted request that triggers inclusion of a password in a reply, aka Bug ID CSCur...Show more |
1Cisco 1Identity Services Engine Software May 6, 2026 Dec 22, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The Sponsor Portal in Cisco Identity Services Engine (ISE) allows remote authenticated users to obtain access to an arbitrary sponsor's guest account via a modified HTTP request, aka Bug ID CSCur64400. |
1Cisco 1Enterprise Content Delivery System May 6, 2026 Dec 20, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in Cisco Enterprise Content Delivery System (ECDS) allows remote attackers to read arbitrary files via a crafted URL, aka Bug ID CSCuo90148. |