Cisco
cisco
6,588 CVEs • 6,222 products
Products (6,222)
Click to collapseToggle
Products (6,222)
Click to collapse
CVEs (6,588)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 1Unified Communications Manager Apr 29, 2026 Feb 13, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in the CallManager Interactive Voice Response (CMIVR) interface in Cisco Unified Communications Manager (UCM) allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka B...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Feb 13, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Feb 13, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Cisco Unified Communications Manager (UCM) does not require authentication for reading WAR files, which allows remote attackers to obtain sensitive information via unspecified access to a "file storage location," aka Bug...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Feb 13, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The bulk administration interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to bypass authentication and read arbitrary files by using an unspecified prompt, aka Bug ID CSC...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Feb 13, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (UCM) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bu...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Feb 13, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The log4jinit web application in Cisco Unified Communications Manager (UCM) does not properly validate authentication, which allows remote attackers to cause a denial of service (performance degradation) via unspecified...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Feb 4, 2014 N/A· v4 N/A· v3 6.0 MEDIUM· v2 Cisco Unified Communications Manager (aka Unified CM) 9.1 (2.10000.28) and earlier allows local users to gain privileges by leveraging incorrect file permissions, aka Bug IDs CSCul24917 and CSCul24908. |
Cisco WebEx Meetings Server allows remote authenticated users to bypass authorization checks and (1) join arbitrary meetings, or (2) terminate a meeting without having a host role, via a crafted URL, aka Bug ID CSCuj4234...Show more |
1Cisco 1Identity Services Engine Software Apr 29, 2026 Jan 29, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Cisco Identity Services Engine (ISE) 1.2 patch 2 and earlier allows remote attackers to inject arbitrary web script or HTML via a report containing a crafted URL that is not pr...Show more |
Cross-site scripting (XSS) vulnerability in the HTTP control interface in the NAC Web Agent component in Cisco Identity Services Engine (ISE) allows remote attackers to inject arbitrary web script or HTML via a crafted U...Show more |
1Cisco 1Secure Access Control System Apr 29, 2026 Jan 25, 2014 N/A· v4 N/A· v3 5.5 MEDIUM· v2 The portal interface in Cisco Secure Access Control System (ACS) does not properly manage sessions, which allows remote authenticated users to hijack sessions and gain privileges via unspecified vectors, aka Bug ID CSCue...Show more |
1Cisco 1Video Surveillance Indoor Fixed Dome Ip Hd Camera Apr 29, 2026 Jan 25, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Cisco Video Surveillance 5000 HD IP Dome cameras allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CS...Show more |
1Cisco 1Video Surveillance Operations Manager Apr 29, 2026 Jan 24, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Cisco Video Surveillance Operations Manager (VSOM) does not require authentication for MySQL database connections, which allows remote attackers to obtain sensitive information, modify data, or cause a denial of service...Show more |
1Cisco 1Telepresence Video Communication Server Apr 29, 2026 Jan 23, 2014 N/A· v4 N/A· v3 6.4 MEDIUM· v2 The Expressway component in Cisco TelePresence Video Communication Server (VCS) uses the same default X.509 certificate across different customers' installations, which makes it easier for remote attackers to conduct man...Show more |
The Label Distribution Protocol (LDP) functionality in Cisco NX-OS allows remote attackers to cause a denial of service (temporary LDP session outage) via LDP discovery traffic containing malformed Hello messages, aka Bu...Show more |
Cisco NX-OS allows local users to bypass intended TACACS+ command restrictions via a series of multiple commands, aka Bug ID CSCum47367. |
1Cisco 2Telepresence Video Communication Server Software Telepresence Video Communication Servers SoftwareApr 29, 2026 Jan 22, 2014 N/A· v4 N/A· v3 7.1 HIGH· v2 The SIP module in Cisco TelePresence Video Communication Server (VCS) before 8.1 allows remote attackers to cause a denial of service (process failure) via a crafted SDP message, aka Bug ID CSCue97632. |
1Cisco 14Telepresence System 1000 Telepresence System 1100Telepresence System 1300 65+11 moreApr 29, 2026 Jan 22, 2014 N/A· v4 N/A· v3 8.3 HIGH· v2 The System Status Collection Daemon (SSCD) in Cisco TelePresence System 500-37, 1000, 1300-65, and 3xxx before 1.10.2(42), and 500-32, 1300-47, TX1310 65, and TX9xxx before 6.0.4(11), allows remote attackers to execute a...Show more |
1Cisco 1Telepresence Isdn Gateway Software Apr 29, 2026 Jan 22, 2014 N/A· v4 N/A· v3 7.1 HIGH· v2 Cisco TelePresence ISDN Gateway with software before 2.2(1.92) allows remote attackers to cause a denial of service (D-channel call outage) via a crafted Q.931 STATUS message, aka Bug ID CSCui50360. |
The Search and Play interface in Cisco MediaSense does not properly enforce authorization requirements, which allows remote authenticated users to download arbitrary recordings via a request to this interface. |