Cisco
cisco
6,580 CVEs • 6,222 products
Products (6,222)
Click to collapseToggle
Products (6,222)
Click to collapse
CVEs (6,580)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 1Unified Communications Manager May 6, 2026 Jul 14, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Directory traversal vulnerability in the Real-Time Monitoring Tool (RTMT) in Cisco Unified Communications Manager (CM) 10.0(1) allows remote authenticated users to read arbitrary files via a crafted URL, aka Bug ID CSCup...Show more |
1Cisco 1Unified Communications Manager May 6, 2026 Jul 14, 2014 N/A· v4 N/A· v3 5.5 MEDIUM· v2 Directory traversal vulnerability in the Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager 10.0(1) allows remote authenticated users to delete arbitrary files via a c...Show more |
1Cisco 1Adaptive Security Appliance Software May 6, 2026 Jul 14, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The WebVPN CIFS implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0(.4.1) and earlier allows remote CIFS servers to cause a denial of service (device reload) via a long share list, aka Bug ID CSCuj8334...Show more |
1Cisco 1Adaptive Security Appliance Software May 6, 2026 Jul 14, 2014 N/A· v4 N/A· v3 5.4 MEDIUM· v2 Cisco Adaptive Security Appliance (ASA) Software 8.4(.6) and earlier, when using an unsupported configuration with overlapping criteria for filtering and inspection, allows remote attackers to cause a denial of service (...Show more |
1Cisco 1Unified Communications Manager May 6, 2026 Jul 10, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Directory traversal vulnerability in dna/viewfilecontents.do in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote authenticated users to read arbitrary files via a crafted U...Show more |
1Cisco 1Unified Communications Manager May 6, 2026 Jul 10, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote authenticated users to bypass intended upload restrictions via a crafted parameter, aka Bug ID CSC...Show more |
1Cisco 1Unified Communications Manager May 6, 2026 Jul 10, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in viewfilecontents.do in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote attackers to inject arbitrary web script or HTML via an...Show more |
1Cisco 2Webex Meeting Center Webex Meetings ServerMay 6, 2026 Jul 10, 2014 N/A· v4 N/A· v3 5.1 MEDIUM· v2 Heap-based buffer overflow in the file-sharing feature in WebEx Meetings Client in Cisco WebEx Meetings Server and WebEx Meeting Center allows remote attackers to execute arbitrary code via crafted data, aka Bug IDs CSCu...Show more |
1Cisco 2Webex Meeting Center Webex Meetings ServerMay 6, 2026 Jul 10, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The File Transfer feature in WebEx Meetings Client in Cisco WebEx Meetings Server and WebEx Meeting Center does not verify that a requested file was an offered file, which allows remote attackers to read arbitrary files...Show more |
1Cisco 16Spa901 1 Line Ip Phone Spa922 1 Line Ip Phone With 1 Port EthernetSpa941 4 Line Ip Phone With 1 Port Ethernet+13 moreMay 6, 2026 Jul 9, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the web user interface on Cisco Small Business SPA300 and SPA500 phones allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuo52582. |
1Cisco 16Spa901 1 Line Ip Phone Spa922 1 Line Ip Phone With 1 Port EthernetSpa941 4 Line Ip Phone With 1 Port Ethernet+13 moreMay 6, 2026 Jul 9, 2014 N/A· v4 N/A· v3 6.9 MEDIUM· v2 The debug console interface on Cisco Small Business SPA300 and SPA500 phones does not properly perform authentication, which allows local users to execute arbitrary debug-shell commands, or read or modify data in memory...Show more |
The NTP implementation in Cisco IOS and IOS XE does not properly support use of the access-group command for a "deny all" configuration, which allows remote attackers to bypass intended restrictions on time synchronizati...Show more |
1Cisco 8Asr 9000 Rsp440 Router Asr 9001Asr 9006+5 moreMay 6, 2026 Jul 7, 2014 N/A· v4 N/A· v3 6.4 MEDIUM· v2 Cisco IOS XR on Trident line cards in ASR 9000 devices lacks a static punt policer, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted packets, aka Bug ID CSCun83985. |
1Cisco 2Unified Cdm Application Software Unified Communications Domain ManagerMay 6, 2026 Jul 7, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 10 does not properly implement access control, which allows remote attackers to modi...Show more |
1Cisco 2Unified Cdm Platform Software Unified Communications Domain ManagerMay 6, 2026 Jul 7, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 Cisco Unified Communications Domain Manager (CDM) in Unified CDM Platform Software before 4.4.2 has a hardcoded SSH private key, which makes it easier for remote attackers to obtain access to the support and root account...Show more |
1Cisco 2Unified Cdm Application Software Unified Communications Domain ManagerMay 6, 2026 Jul 7, 2014 N/A· v4 N/A· v3 9.0 HIGH· v2 The Administration GUI in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 8.1.4 does not properly implement access control, which allows remote authentica...Show more |
1Cisco 1Universal Small Cell Series Firmware May 6, 2026 Jul 2, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The DHCP client implementation in Universal Small Cell firmware on Cisco Small Cell products allows remote attackers to execute arbitrary commands via crafted DHCP messages, aka Bug ID CSCup47513. |
Form Data Viewer in Cisco Intelligent Automation for Cloud in Cisco Cloud Portal places passwords in form data, which allows remote authenticated users to obtain sensitive information by reading HTML source code, aka Bug...Show more |
Cisco Intelligent Automation for Cloud in Cisco Cloud Portal does not properly restrict the content of MyServices action URLs, which allows remote authenticated users to obtain sensitive information by reading (1) web-se...Show more |
Cisco IOS allows remote authenticated users to cause a denial of service (device reload) via malformed IPsec packets, aka Bug ID CSCui79745. |