← Back

Cisco

cisco

6,580 CVEs • 6,222 products

Products (6,222)

Click to collapse
Toggle
Ios
ios
Ios Xe
ios_xe
Nx Os
nx_os
Ios Xr
ios_xr
Asyncos
asyncos
Asa 5500
asa_5500
Jabber
jabber

CVEs (6,580)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Prime Infrastructure
May 6, 2026
Dec 20, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Cisco Prime Infrastructure allows remote authenticated users to read device-discovery passwords by examining the HTML source code of the Quick Discovery options page, aka Bug ID CSCum00019.
1Cisco
1Adaptive Security Appliance Software
May 6, 2026
Dec 20, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The syslog-management subsystem in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to obtain an administrator password by waiting for an administrator to copy a file, and then (1) sniffing the ne...Show more
The syslog-management subsystem in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to obtain an administrator password by waiting for an administrator to copy a file, and then (1) sniffing the network for a syslog message or (2) reading a syslog message in a file on a syslog server, aka Bug IDs CSCuq22357 and CSCur41860.Show less
1Cisco
1Ironport Email Security Appliances
May 6, 2026
Dec 19, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Cisco IronPort Email Security Appliance (ESA) allows remote attackers to cause a denial of service (CPU consumption) via long Subject headers in e-mail messages, aka Bug ID CSCzv93864.
1Cisco
1Ios Xr
May 6, 2026
Dec 18, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco IOS XR allows remote attackers to cause a denial of service (RSVP process reload) via a malformed RSVP packet, aka Bug ID CSCub63710.
1Cisco
1Adaptive Security Appliance Software
May 6, 2026
Dec 18, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the WebVPN Portal Login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via crafted attributes in a cook...Show more
Cross-site scripting (XSS) vulnerability in the WebVPN Portal Login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via crafted attributes in a cookie, aka Bug ID CSCuh24695.Show less
1Cisco
1Isb8320 E High Definition Ip Only Dvr
May 6, 2026
Dec 17, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Disaster Recovery (DRA) feature on the Cisco ISB8320-E High-Definition IP-Only DVR allows remote attackers to bypass authentication by establishing a TELNET session during a recovery boot, aka Bug ID CSCup85422.
1Cisco
1Prime Security Manager
May 6, 2026
Dec 13, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Prime Security Manager (aka PRSM) 9.2.1-2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) Access Polic...Show more
Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Prime Security Manager (aka PRSM) 9.2.1-2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) Access Policies or (2) Device Summary Dashboard parameter, aka Bug ID CSCuq80661.Show less
1Cisco
1Unified Communications Domain Manager
May 6, 2026
Dec 10, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
The web framework in Cisco Unified Communications Domain Manager 8 allows remote authenticated administrators to execute arbitrary OS commands via crafted values, aka Bug ID CSCuq50205.
1Cisco
1Unified Computing System
May 6, 2026
Dec 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Management subsystem in Cisco Unified Computing System 2.1(3f) and earlier allows remote attackers to obtain sensitive information by reading log files, aka Bug ID CSCur99239.
1Cisco
1Unified Computing System
May 6, 2026
Dec 10, 2014
N/A· v4
N/A· v3
7.2 HIGH· v2
Cisco Integrated Management Controller in Cisco Unified Computing System 2.2(2c)A and earlier allows local users to obtain shell access via a crafted map-nfs command, aka Bug ID CSCup05998.
1Cisco
1Adaptive Security Appliance Software
May 6, 2026
Nov 28, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(.2) and earlier does not properly allocate memory blocks during HTTP packet handling, which allows remote attackers to cause a denial of...Show more
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(.2) and earlier does not properly allocate memory blocks during HTTP packet handling, which allows remote attackers to cause a denial of service (memory consumption) via crafted packets, aka Bug ID CSCuq68888.Show less
1Cisco
1Ios Xr
May 6, 2026
Nov 26, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Race condition in the lighttpd module in Cisco IOS XR 5.1 and earlier on Network Convergence System 6000 devices allows remote attackers to cause a denial of service (process reload) by establishing many TCP sessions, ak...Show more
Race condition in the lighttpd module in Cisco IOS XR 5.1 and earlier on Network Convergence System 6000 devices allows remote attackers to cause a denial of service (process reload) by establishing many TCP sessions, aka Bug ID CSCuq45239.Show less
1Cisco
1Ios Xr
May 6, 2026
Nov 25, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco IOS XR allows remote attackers to cause a denial of service (LISP process reload) by establishing many LISP TCP sessions, aka Bug ID CSCuq90378.
1Cisco
1Openh264
May 6, 2026
Nov 25, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in decode_slice.cpp in Cisco OpenH264 1.2.0 and earlier allows remote attackers to execute arbitrary code via an encoded media file.
1Cisco
1Openh264
May 6, 2026
Nov 25, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in decode.cpp in Cisco OpenH264 1.2.0 and earlier allows remote attackers to execute arbitrary code via an encoded media file.
1Cisco
1Unified Communications Manager Im And Presence Service
May 6, 2026
Nov 21, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco Unified Communications Manager IM and Presence Service 9.1(1) produces different returned messages for URL requests depending on whether a username exists, which allows remote attackers to enumerate user accounts v...Show more
Cisco Unified Communications Manager IM and Presence Service 9.1(1) produces different returned messages for URL requests depending on whether a username exists, which allows remote attackers to enumerate user accounts via a series of requests, aka Bug ID CSCur63497.Show less
1Cisco
1Unified Computing System
May 6, 2026
Nov 18, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Integrated Management Controller in Cisco Unified Computing System allows remote attackers to hijack the authentication of arbitrary users, ak...Show more
Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Integrated Management Controller in Cisco Unified Computing System allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuq45477.Show less
1Cisco
1Ios
May 6, 2026
Nov 18, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information from process memory via a session on TCP port 2067, aka Bug ID CSCur14014.
1Cisco
1Ios
May 6, 2026
Nov 15, 2014
N/A· v4
N/A· v3
7.1 HIGH· v2
Cisco IOS on Aironet access points, when "dot11 aaa authenticator" debugging is enabled, allows remote attackers to cause a denial of service via a malformed EAP packet, aka Bug ID CSCul15509.
1Cisco
1Ios
May 6, 2026
Nov 15, 2014
N/A· v4
N/A· v3
6.1 MEDIUM· v2
The DHCP implementation in Cisco IOS on Aironet access points does not properly handle error conditions with short leases and unsuccessful lease-renewal attempts, which allows remote attackers to cause a denial of servic...Show more
The DHCP implementation in Cisco IOS on Aironet access points does not properly handle error conditions with short leases and unsuccessful lease-renewal attempts, which allows remote attackers to cause a denial of service (device restart) by triggering a transition into a recovery state that was intended to involve a network-interface restart but actually involves a full device restart, aka Bug ID CSCtn16281.Show less