← Back

Cisco

cisco

6,588 CVEs • 6,222 products

Products (6,222)

Click to collapse
Toggle
Ios
ios
Ios Xe
ios_xe
Nx Os
nx_os
Ios Xr
ios_xr
Asyncos
asyncos
Asa 5500
asa_5500
Jabber
jabber

CVEs (6,588)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Adaptive Security Appliance Software
Apr 29, 2026
Nov 13, 2013
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The phone-proxy implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier does not properly validate X.509 certificates, which allows remote attackers to cause a denial of service (connection...Show more
The phone-proxy implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier does not properly validate X.509 certificates, which allows remote attackers to cause a denial of service (connection-database corruption) via an invalid entry, aka Bug ID CSCui33299.Show less
1Cisco
1Adaptive Security Appliance Software
Apr 29, 2026
Nov 13, 2013
N/A· v4
N/A· v3
7.1 HIGH· v2
The auto-update implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier allows remote attackers to cause a denial of service (device reload) via crafted update data, aka Bug ID CSCui33308.
1Cisco
1Adaptive Security Appliance Software
Apr 29, 2026
Nov 13, 2013
N/A· v4
N/A· v3
5.4 MEDIUM· v2
The IPv6 implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1.3 and earlier, when NAT64 or NAT66 is enabled, does not properly process NAT rules, which allows remote attackers to cause a denial of servi...Show more
The IPv6 implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1.3 and earlier, when NAT64 or NAT66 is enabled, does not properly process NAT rules, which allows remote attackers to cause a denial of service (device reload) via crafted packets, aka Bug ID CSCue34342.Show less
1Cisco
2Content Services Gateway
Ios
Apr 29, 2026
Nov 13, 2013
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows remote attackers to bypass intended access restrictions via a crafted...Show more
Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows remote attackers to bypass intended access restrictions via a crafted series of packets, aka Bug ID CSCug90143.Show less
1Cisco
1Nx Os
Apr 29, 2026
Nov 8, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco NX-OS 5.0 and earlier on MDS 9000 devices allows remote attackers to cause a denial of service (supervisor CPU consumption) via Authentication Header (AH) authentication in a Virtual Router Redundancy Protocol (VRR...Show more
Cisco NX-OS 5.0 and earlier on MDS 9000 devices allows remote attackers to cause a denial of service (supervisor CPU consumption) via Authentication Header (AH) authentication in a Virtual Router Redundancy Protocol (VRRP) frame, aka Bug ID CSCte27874.Show less
1Cisco
1Ios Xr
Apr 29, 2026
Nov 8, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The OSPFv3 functionality in Cisco IOS XR 5.1 allows remote attackers to cause a denial of service (process crash) via a malformed LSA Type-1 packet, aka Bug ID CSCuj82176.
1Cisco
1Telepresence Vx Clinical Assistant
Apr 29, 2026
Nov 8, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
The WIL-A module in Cisco TelePresence VX Clinical Assistant 1.2 before 1.21 changes the admin password to an empty password upon a reboot, which makes it easier for remote attackers to obtain access via the administrati...Show more
The WIL-A module in Cisco TelePresence VX Clinical Assistant 1.2 before 1.21 changes the admin password to an empty password upon a reboot, which makes it easier for remote attackers to obtain access via the administrative interface, aka Bug ID CSCuj17238.Show less
1Cisco
1Wide Area Application Services Mobile
Apr 29, 2026
Nov 8, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in the web-management interface in the server in Cisco Wide Area Application Services (WAAS) Mobile before 3.5.5 allows remote attackers to upload and execute arbitrary files via a craft...Show more
Directory traversal vulnerability in the web-management interface in the server in Cisco Wide Area Application Services (WAAS) Mobile before 3.5.5 allows remote attackers to upload and execute arbitrary files via a crafted POST request, aka Bug ID CSCuh69773.Show less
1Cisco
1Ios
Apr 29, 2026
Nov 8, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
Multiple memory leaks in Cisco IOS 15.1 before 15.1(4)M7 allow remote attackers to cause a denial of service (memory consumption or device reload) by sending a crafted SIP message over (1) IPv4 or (2) IPv6, aka Bug IDs C...Show more
Multiple memory leaks in Cisco IOS 15.1 before 15.1(4)M7 allow remote attackers to cause a denial of service (memory consumption or device reload) by sending a crafted SIP message over (1) IPv4 or (2) IPv6, aka Bug IDs CSCuc42558 and CSCug25383.Show less
1Cisco
1Security Monitoring Analysis And Response System
Apr 29, 2026
Nov 6, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Query/NewQueryResult.jsp in Cisco Security Monitoring, Analysis and Response System (CS-MARS) allows remote attackers to inject arbitrary web script or HTML via the isnowLatenc...Show more
Cross-site scripting (XSS) vulnerability in Query/NewQueryResult.jsp in Cisco Security Monitoring, Analysis and Response System (CS-MARS) allows remote attackers to inject arbitrary web script or HTML via the isnowLatency parameter, aka Bug ID CSCul16173.Show less
1Cisco
1Prime Central For Hosted Collaboration Solution
Apr 29, 2026
Nov 6, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The ITM web server in Cisco Prime Central for Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (temporary HTTP service outage) via a flood of TCP packets, aka Bug ID CSCuh36313.
1Cisco
1Prime Central For Hosted Collaboration Solution
Apr 29, 2026
Nov 4, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Java process in the Impact server in Cisco Prime Central for Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (process crash) via a flood of TCP packets, aka Bug ID CSCug57345.
1Cisco
1Adaptive Security Appliance Cx Context Aware Security Software
Apr 29, 2026
Nov 4, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Safe Search enforcement feature in Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security Software does not properly perform filtering, which allows remote attackers to bypass intended policy restrictions...Show more
The Safe Search enforcement feature in Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security Software does not properly perform filtering, which allows remote attackers to bypass intended policy restrictions via unspecified vectors, aka Bug ID CSCui94622.Show less
1Cisco
1Anyconnect Secure Mobility Client
Apr 29, 2026
Nov 4, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Buffer overflow in the Active Template Library (ATL) framework in the VPNAPI COM module in Cisco AnyConnect Secure Mobility Client 2.x allows user-assisted remote attackers to execute arbitrary code via a crafted HTML do...Show more
Buffer overflow in the Active Template Library (ATL) framework in the VPNAPI COM module in Cisco AnyConnect Secure Mobility Client 2.x allows user-assisted remote attackers to execute arbitrary code via a crafted HTML document, aka Bug ID CSCuj58139.Show less
1Cisco
1Unified Communications Manager
Apr 29, 2026
Nov 1, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to cause a denial of service (service restart) via a crafted SIP message, aka Bug ID CSCub54349.
1Cisco
1Adaptive Security Appliance Software
Apr 29, 2026
Nov 1, 2013
N/A· v4
N/A· v3
6.3 MEDIUM· v2
Cisco Adaptive Security Appliance (ASA) Software, when certain same-security-traffic and management-access options are enabled, allows remote authenticated users to cause a denial of service (stack overflow and device re...Show more
Cisco Adaptive Security Appliance (ASA) Software, when certain same-security-traffic and management-access options are enabled, allows remote authenticated users to cause a denial of service (stack overflow and device reload) by using the clientless SSL VPN portal for internal-resource browsing, aka Bug ID CSCui51199.Show less
1Cisco
1Ios
Apr 29, 2026
Nov 1, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The IKEv2 implementation in Cisco IOS, when AES-GCM or AES-GMAC is used, allows remote attackers to bypass certain IPsec anti-replay features via IPsec tunnel traffic, aka Bug ID CSCuj47795.
1Cisco
7Asr 1001
Asr 1002Asr 1002 X+4 more
Apr 29, 2026
Oct 31, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) by sending malformed EoGRE packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCuf08269.
1Cisco
7Asr 1001
Asr 1002Asr 1002 X+4 more
Apr 29, 2026
Oct 31, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
The TCP reassembly feature in Cisco IOS XE 3.7 before 3.7.3S and 3.8 before 3.8.1S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) via large TCP packets that are processed by the...Show more
The TCP reassembly feature in Cisco IOS XE 3.7 before 3.7.3S and 3.8 before 3.8.1S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) via large TCP packets that are processed by the (1) NAT or (2) ALG component, aka Bug ID CSCud72509.Show less
1Cisco
7Asr 1001
Asr 1002Asr 1002 X+4 more
Apr 29, 2026
Oct 31, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
The PPTP ALG implementation in Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) by sending many PPTP packets over NAT, aka Bug ID CSCuh19936.