Записи cisco
6 752 опубликованных записей вендора cisco.
Профиль для исследователя
- Попали в KEV
- 104 · 1,5 %
- С эксплойтом
- 151 · 2,2 %
- Pre-auth RCE
- 648
- С записью об исправлении
- 1 %
- Медиана: публикация → KEV
- 996 дн.
Повторяющиеся классы
- CWE-20 Improper Input Validation1 020
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')693
- CWE-399 Resource Management Errors512
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer357
- CWE-264 Permissions, Privileges, and Access Controls349
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor301
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 752 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2021-44228Готовый эксплойт | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Критическая10,0 | KEV | 100,0 % | 10 дек. 2021 г. |
100Срочно | CVE-2023-20198Готовый эксплойт | Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.cisco · ios xe · CWE-420 | Критическая10,0 | KEV | 99,6 % | 16 окт. 2023 г. |
100Срочно | CVE-2025-32433Готовый эксплойт | Erlang/OTP SSH Vulnerable to Pre-Authentication RCEerlang · erlang\/otp · CWE-306 | Критическая10,0 | KEV | 98,8 % | 16 апр. 2025 г. |
99Срочно | CVE-2021-1498Готовый эксплойт | Cisco HyperFlex HX Command Injection Vulnerabilitiescisco · hyperflex hx data platform · CWE-78 | Критическая9,8 | KEV | 100,0 % | 6 мая 2021 г. |
99Срочно | CVE-2021-1497Готовый эксплойт | Cisco HyperFlex HX Command Injection Vulnerabilitiescisco · hyperflex hx data platform · CWE-78 | Критическая9,8 | KEV | 99,9 % | 6 мая 2021 г. |
99Срочно | CVE-2022-22965Готовый эксплойт | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.vmware · spring framework · CWE-94 | Критическая9,8 | KEV | 99,6 % | 1 апр. 2022 г. |
99Срочно | CVE-2018-0171Готовый эксплойт | A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attackercisco · ios · CWE-20 | Критическая9,8 | KEV | 99,5 % | 28 мар. 2018 г. |
99Срочно | CVE-2017-3881Готовый эксплойт | A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthecisco · ios · CWE-20 | Критическая9,8 | KEV | 99,0 % | 17 мар. 2017 г. |
99Срочно | CVE-2025-20281Готовый эксплойт | Cisco ISE API Unauthenticated Remote Code Execution Vulnerabilitycisco · identity services engine · CWE-74 | Критическая10,0 | KEV | 97,6 % | 25 июн. 2025 г. |
98Срочно | CVE-2024-20439Готовый эксплойт | A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by uscisco · smart license utility · CWE-912 | Критическая9,8 | KEV | 97,1 % | 4 сент. 2024 г. |
97Срочно | CVE-2026-20182Готовый эксплойт | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerabilitycisco · catalyst sd-wan manager · CWE-287 | Критическая10,0 | KEV | 91,5 % | 14 мая 2026 г. |
97Срочно | CVE-2026-20127Готовый эксплойт | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerabilitycisco · catalyst sd-wan manager · CWE-287 | Критическая10,0 | KEV | 88,5 % | 25 февр. 2026 г. |
96Срочно | CVE-2026-20079Готовый эксплойт | Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerabilitycisco · secure firewall management center · CWE-288 | Критическая10,0 | KEV | 88,2 % | 4 мар. 2026 г. |
94Срочно | CVE-2020-3161Готовый эксплойт | Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerabilitycisco · ip phone 8865 firmware · CWE-20 | Критическая9,8 | KEV | 83,9 % | 15 апр. 2020 г. |
92Срочно | CVE-2017-9805Готовый эксплойт | The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStreaapache · struts · CWE-502 | Высокая8,1 | KEV | 99,4 % | 15 сент. 2017 г. |
91Срочно | CVE-2016-6366Готовый эксплойт | Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V,cisco · pix firewall software · CWE-120 | Высокая8,8 | KEV | 87,6 % | 18 авг. 2016 г. |
91Срочно | CVE-2022-20699Готовый эксплойт | Cisco Small Business RV Series Routers Vulnerabilitiescisco · rv340 firmware · CWE-121 | Критическая9,8 | KEV | 72,5 % | 10 февр. 2022 г. |
90Срочно | CVE-2023-44487Готовый эксплойт | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Высокая7,5 | KEV | 100,0 % | 10 окт. 2023 г. |
90Срочно | CVE-2020-3452Готовый эксплойт | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerabilitycisco · adaptive security appliance software · CWE-20 | Высокая7,5 | KEV | 100,0 % | 22 июл. 2020 г. |
90Срочно | CVE-2018-0296Готовый эксплойт | A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to causecisco · adaptive security appliance software · CWE-20 | Высокая7,5 | KEV | 99,9 % | 7 июн. 2018 г. |
90Срочно | CVE-2019-1653Готовый эксплойт | Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerabilitycisco · rv320 firmware · CWE-284 | Высокая7,5 | KEV | 99,9 % | 24 янв. 2019 г. |
90Срочно | CVE-2026-20230Готовый эксплойт | Cisco Unified Communications Manager Server-Side Request Forgery Vulnerabilitycisco · unified communications manager · CWE-918 | Высокая8,6 | KEV | 88,2 % | 3 июн. 2026 г. |
90Срочно | CVE-2025-20362Готовый эксплойт | Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTcisco · adaptive security appliance software · CWE-862 | Высокая8,6 | KEV | 87,1 % | 25 сент. 2025 г. |
90Срочно | CVE-2025-20333Готовый эксплойт | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Dcisco · adaptive security appliance software · CWE-120 | Критическая9,9 | KEV | 70,7 % | 25 сент. 2025 г. |
90Срочно | CVE-2025-20337Готовый эксплойт | Cisco ISE API Unauthenticated Remote Code Execution Vulnerabilitycisco · identity services engine · CWE-74 | Критическая10,0 | KEV | 67,8 % | 16 июл. 2025 г. |
- CVE-2021-44228100Срочно
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %apache · log4j10 дек. 2021 г.
- CVE-2023-20198100Срочно
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %cisco · ios xe16 окт. 2023 г.
- CVE-2025-32433100Срочно
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 99 %erlang · erlang\/otp16 апр. 2025 г.
- CVE-2021-149899Срочно
Cisco HyperFlex HX Command Injection Vulnerabilities
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %cisco · hyperflex hx data platform6 мая 2021 г.
- CVE-2021-149799Срочно
Cisco HyperFlex HX Command Injection Vulnerabilities
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %cisco · hyperflex hx data platform6 мая 2021 г.
- CVE-2022-2296599Срочно
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vmware · spring framework1 апр. 2022 г.
- CVE-2018-017199Срочно
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %cisco · ios28 мар. 2018 г.
- CVE-2017-388199Срочно
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthe
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %cisco · ios17 мар. 2017 г.
- CVE-2025-2028199Срочно
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 98 %cisco · identity services engine25 июн. 2025 г.
- CVE-2024-2043998Срочно
A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by us
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %cisco · smart license utility4 сент. 2024 г.
- CVE-2026-2018297Срочно
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 92 %cisco · catalyst sd-wan manager14 мая 2026 г.
- CVE-2026-2012797Срочно
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 88 %cisco · catalyst sd-wan manager25 февр. 2026 г.
- CVE-2026-2007996Срочно
Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 88 %cisco · secure firewall management center4 мар. 2026 г.
- CVE-2020-316194Срочно
Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 84 %cisco · ip phone 8865 firmware15 апр. 2020 г.
- CVE-2017-980592Срочно
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStrea
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 99 %apache · struts15 сент. 2017 г.
- CVE-2016-636691Срочно
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V,
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 88 %cisco · pix firewall software18 авг. 2016 г.
- CVE-2022-2069991Срочно
Cisco Small Business RV Series Routers Vulnerabilities
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 72 %cisco · rv340 firmware10 февр. 2022 г.
- CVE-2023-4448790Срочно
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 окт. 2023 г.
- CVE-2020-345290Срочно
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %cisco · adaptive security appliance software22 июл. 2020 г.
- CVE-2018-029690Срочно
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %cisco · adaptive security appliance software7 июн. 2018 г.
- CVE-2019-165390Срочно
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %cisco · rv320 firmware24 янв. 2019 г.
- CVE-2026-2023090Срочно
Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability
ВысокаяCVSS 8,6KEVГотовый эксплойтEPSS 88 %cisco · unified communications manager3 июн. 2026 г.
- CVE-2025-2036290Срочно
Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FT
ВысокаяCVSS 8,6KEVГотовый эксплойтEPSS 87 %cisco · adaptive security appliance software25 сент. 2025 г.
- CVE-2025-2033390Срочно
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat D
КритическаяCVSS 9,9KEVГотовый эксплойтEPSS 71 %cisco · adaptive security appliance software25 сент. 2025 г.
- CVE-2025-2033790Срочно
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 68 %cisco · identity services engine16 июл. 2025 г.