Cisco
cisco
6,590 CVEs • 6,223 products
Products (6,223)
Click to collapseToggle
Products (6,223)
Click to collapse
CVEs (6,590)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 2Unified Ip Conference Station 7937g Unified Ip Conference Station 7937g FirmwareApr 29, 2026 Jul 23, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Cisco Unified IP Conference Station 7937G allows remote attackers to cause a denial of service (networking outage) via a flood of TCP packets, aka Bug ID CSCuh42052. |
The default configuration of the Group Encrypted Transport VPN (GET VPN) feature on Cisco IOS uses an improper mechanism for enabling Group Domain of Interpretation (GDOI) traffic flow, which allows remote attackers to b...Show more |
1Cisco 3Unified Ip Phone 9951 Unified Ip Phone 9971Unified Ip Phones 9900 Series FirmwareApr 29, 2026 Jul 18, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Serviceability servlet on Cisco 9900 IP phones does not properly restrict paths, which allows remote attackers to read arbitrary files by specifying a pathname in a file request, aka Bug ID CSCuh52810. |
1Cisco 2Identity Services Engine Identity Services Engine SoftwareApr 29, 2026 Jul 18, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in the web framework on the Cisco Identity Services Engine (ISE) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuh25506. |
Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) and the IM & Presence Service in Cisco Unified Presence Server through 9.1(2) use the same CTI and database-encryption key across different customers' ins...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Jul 18, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to gain privileges by leveraging unspecified file-permission and environment-variable issues fo...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Jul 18, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to gain privileges by leveraging unspecified file-permission and environment-variable issues fo...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Jul 18, 2013 N/A· v4 N/A· v3 6.5 MEDIUM· v2 SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuh81766. |
1Cisco 2Idsm 2 Intrusion Prevention SystemApr 29, 2026 Jul 18, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 The IDSM-2 drivers in Cisco Intrusion Prevention System (IPS) Software on Cisco Catalyst 6500 devices with an IDSM-2 module allow remote attackers to cause a denial of service (device hang) via malformed IPv4 TCP packets...Show more |
1Cisco 2Intrusion Prevention System Ips NmeApr 29, 2026 Jul 18, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 Cisco Intrusion Prevention System (IPS) Software on IPS NME devices before 7.0(9)E4 allows remote attackers to cause a denial of service (device reload) via malformed IPv4 packets that trigger incorrect memory allocation...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Jul 18, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, leading to discovery of encrypted crede...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Jul 18, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple untrusted search path vulnerabilities in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allow local users to gain privileges by leveraging unspecified file-permission and environment-variable...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Jul 18, 2013 N/A· v4 N/A· v3 6.5 MEDIUM· v2 An unspecified function in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitrary commands via unknown vectors, aka Bug ID CSCuh73440. |
1Cisco 9Asa 5500 X Series Ips Ssp Software Asa 5585 XIdsm 2+6 moreApr 29, 2026 Jul 18, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 The IP stack in Cisco Intrusion Prevention System (IPS) Software in ASA 5500-X IPS-SSP software and hardware modules before 7.1(5)E4, IPS 4500 sensors before 7.1(6)E4, and IPS 4300 sensors before 7.1(5)E4 allows remote a...Show more |
1Cisco 9Asa 5500 X Series Ips Ssp Software Asa 5585 XIdsm 2+6 moreApr 29, 2026 Jul 18, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 Cisco Intrusion Prevention System (IPS) Software in ASA 5500-X IPS-SSP software modules before 7.1(7)sp1E4 allows remote attackers to cause a denial of service (Analysis Engine process hang or device reload) via fragment...Show more |
1Cisco 1Secure Access Control System Apr 29, 2026 Jul 15, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The web interface in Cisco Secure Access Control System (ACS) does not properly suppress error-condition details, which allows remote authenticated users to obtain sensitive information via an unspecified request that tr...Show more |
1Cisco 1Secure Access Control System Apr 29, 2026 Jul 12, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in Administration and View pages in Cisco Secure Access Control System (ACS) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCud75177. |
1Cisco 1Secure Access Control System Apr 29, 2026 Jul 12, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the web interface in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified field, aka Bug ID CSCud75174. |
1Cisco 1Secure Access Control System Apr 29, 2026 Jul 12, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Administration pages in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCud75...Show more |
1Cisco 1Secure Access Control System Apr 29, 2026 Jul 12, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the Help index page in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCud751...Show more |