← Back

Cisco

cisco

6,588 CVEs • 6,222 products

Products (6,222)

Click to collapse
Toggle
Ios
ios
Ios Xe
ios_xe
Nx Os
nx_os
Ios Xr
ios_xr
Asyncos
asyncos
Asa 5500
asa_5500
Jabber
jabber

CVEs (6,588)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Unified Computing System
Apr 29, 2026
Oct 13, 2013
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges and execute arbitrary commands via crafted parameters to a file-related command, aka Bug ID CSCtq86489.
1Cisco
1Unified Computing System
Apr 29, 2026
Oct 13, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The fabric-interconnect component in Cisco Unified Computing System (UCS) uses the same privilege level for execution of every script, which allows local users to gain privileges and execute arbitrary commands via an uns...Show more
The fabric-interconnect component in Cisco Unified Computing System (UCS) uses the same privilege level for execution of every script, which allows local users to gain privileges and execute arbitrary commands via an unspecified script-execution approach, aka Bug ID CSCtq86477.Show less
1Cisco
1Unified Computing System
Apr 29, 2026
Oct 13, 2013
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to cause a denial of service (component crash) via crafted "debug hardware" parameters, aka Bug ID CSCtq86468.
1Cisco
3Unified Ip Phone 9951
Unified Ip Phone 9971Unified Ip Phones 9900 Series Firmware
Apr 29, 2026
Oct 11, 2013
N/A· v4
N/A· v3
6.0 MEDIUM· v2
The image-upgrade functionality on Cisco 9900 Unified IP phones allows local users to gain privileges by placing shell commands in an unspecified parameter, aka Bug ID CSCuh10334.
1Cisco
3Unified Ip Phone 9951
Unified Ip Phone 9971Unified Ip Phones 9900 Series Firmware
Apr 29, 2026
Oct 11, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in the web-application interface on Cisco 9900 IP phones allows remote attackers to cause a denial of service (webapp interface outage) via long values in unspecified fields, aka Bug ID CSCuh10343.
1Cisco
1Unified Communications Manager
Apr 29, 2026
Oct 11, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to read arbitrary files via directory traversal sequences in an unspe...Show more
Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to read arbitrary files via directory traversal sequences in an unspecified input string, aka Bug ID CSCui78815.Show less
1Cisco
2Ios
Ios Xe
Apr 29, 2026
Oct 10, 2013
N/A· v4
N/A· v3
5.7 MEDIUM· v2
The OSPF functionality in Cisco IOS and IOS XE allows remote attackers to cause a denial of service (device reload) via crafted options in an LSA type 11 packet, aka Bug ID CSCui21030.
1Cisco
2Unified Ip Phone 9951
Unified Ip Phone 9971
Apr 29, 2026
Oct 10, 2013
N/A· v4
N/A· v3
7.1 HIGH· v2
Cisco 9900 fourth-generation IP phones do not properly perform SDP negotiation, which allows remote attackers to cause a denial of service (device reboot) via crafted SDP packets, aka Bug ID CSCuf06698.
1Cisco
1Identity Services Engine Software
Apr 29, 2026
Oct 10, 2013
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCug90502.
1Cisco
1Identity Services Engine Software
Apr 29, 2026
Oct 10, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the troubleshooting page in Cisco Identity Services Engine (ISE) 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, ak...Show more
Cross-site scripting (XSS) vulnerability in the troubleshooting page in Cisco Identity Services Engine (ISE) 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCug77655.Show less
1Cisco
1Identity Services Engine Software
Apr 29, 2026
Oct 10, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Sponsor Portal in Cisco Identity Services Engine (ISE) 1.2 and earlier does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified oth...Show more
The Sponsor Portal in Cisco Identity Services Engine (ISE) 1.2 and earlier does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCui82666.Show less
1Cisco
1Ios
Apr 29, 2026
Oct 10, 2013
N/A· v4
N/A· v3
5.7 MEDIUM· v2
The remember feature in the DHCP server in Cisco IOS allows remote attackers to cause a denial of service (device reload) by acquiring a lease and then sending a DHCPRELEASE message, aka Bug ID CSCuh46822.
1Cisco
1Prime Central For Hosted Collaboration Solution
Apr 29, 2026
Oct 10, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The portal in Cisco Prime Central for Hosted Collaboration Solution (HCS) places cleartext credentials in temporary files, which allows local users to obtain sensitive information by leveraging weak file permissions to r...Show more
The portal in Cisco Prime Central for Hosted Collaboration Solution (HCS) places cleartext credentials in temporary files, which allows local users to obtain sensitive information by leveraging weak file permissions to read these files, aka Bug IDs CSCuh33735 and CSCuh34230.Show less
1Cisco
1Nx Os
Apr 29, 2026
Oct 5, 2013
N/A· v4
N/A· v3
6.2 MEDIUM· v2
Directory traversal vulnerability in the CLI parser in Cisco NX-OS allows local users to create arbitrary script files via a relative pathname in the "file name" parameter, aka Bug IDs CSCua71557 and CSCua71551.
1Cisco
1Nx Os
Apr 29, 2026
Oct 5, 2013
N/A· v4
N/A· v3
6.2 MEDIUM· v2
The CLI parser in Cisco NX-OS allows local users to bypass intended access restrictions, and overwrite or create arbitrary files, via shell output redirection, aka Bug IDs CSCts56672 and CSCts56669.
1Cisco
1Nx Os
Apr 29, 2026
Oct 5, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The BGP implementation in Cisco NX-OS does not properly filter AS paths, which allows remote attackers to cause a denial of service (BGP service reset and resync) via a malformed UPDATE message, aka Bug ID CSCtn13055.
1Cisco
1Nx Os
Apr 29, 2026
Oct 5, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The RIP service engine in Cisco NX-OS allows remote attackers to cause a denial of service (engine restart) via a malformed (1) RIPv4 or (2) RIPv6 message, aka Bug ID CSCtj73415.
1Cisco
5Nexus 7000
Nexus 7000 10 SlotNexus 7000 18 Slot+2 more
Apr 29, 2026
Oct 5, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The management interface in Cisco NX-OS on Nexus 7000 devices allows remote authenticated users to obtain sensitive configuration-file information by leveraging the network-operator role, aka Bug ID CSCti09089.
1Cisco
1Unified Computing System
Apr 29, 2026
Oct 5, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in the web-management interface in the fabric interconnect (FI) component in Cisco Unified Computing System (UCS) allows remote attackers to hijack the authentication of ar...Show more
Cross-site request forgery (CSRF) vulnerability in the web-management interface in the fabric interconnect (FI) component in Cisco Unified Computing System (UCS) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCtg20755.Show less
1Cisco
1Nx Os
Apr 29, 2026
Oct 5, 2013
N/A· v4
N/A· v3
7.2 HIGH· v2
Cisco NX-OS allows local users to gain privileges and execute arbitrary commands via shell metacharacters in unspecified command parameters, aka Bug IDs CSCtf19827 and CSCtf27788.