VYPR
Vendor·Networking & Cybersecurity·US

Cisco Systems, Inc.

CNA· ciscoCSCOFounded 1984San Jose, CA, USA
Products
3,515
CVEs
6,961
Across products
6,332
Status
Public

Products

3,515
View all 3,515 products →

Recent CVEs

6,961
View all 6,961 CVEs →
  • CVE-2021-44228CriKEVDec 10, 2021
    risk 0.94cvss 10.0epss 1.00

    Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log…

  • CVE-2023-20198CriKEVOct 16, 2023
    risk 0.88cvss 10.0epss 1.00

    Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two…

  • CVE-2026-20182CriKEVMay 14, 2026
    risk 0.87cvss 10.0epss 0.92

    May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this…

  • CVE-2026-20127CriKEVFeb 25, 2026
    risk 0.87cvss 10.0epss 0.88

    A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to…

  • CVE-2021-1498CriKEVMay 6, 2021
    risk 0.87cvss 9.8epss 1.00

    Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this…

  • CVE-2021-1497CriKEVMay 6, 2021
    risk 0.87cvss 9.8epss 1.00

    Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this…

  • CVE-2018-0171CriKEVMar 28, 2018
    risk 0.87cvss 9.8epss 0.99

    A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary code on an affected…

  • CVE-2017-3881CriKEVMar 17, 2017
    risk 0.87cvss 9.8epss 0.99

    A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. The Cluster Management…

  • CVE-2022-20699CriKEVFeb 10, 2022
    risk 0.86cvss 10.0epss 0.72

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2026-20131CriKEVMar 4, 2026
    risk 0.85cvss 10.0epss 0.31

    A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure…

  • CVE-2025-20281CriKEVJun 25, 2025
    risk 0.85cvss 10.0epss 0.97

    A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This…

  • CVE-2020-3161CriKEVApr 15, 2020
    risk 0.85cvss 9.8epss 0.84

    A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper…

  • CVE-2024-20439CriKEVSep 4, 2024
    risk 0.83cvss 9.8epss 0.92

    A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an administrative…

  • CVE-2025-20337CriKEVJul 16, 2025
    risk 0.82cvss 10.0epss 0.66

    A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This…

  • CVE-2025-20333CriKEVSep 25, 2025
    risk 0.80cvss 9.9epss 0.40

    A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability…

  • CVE-2022-22965CriKEVApr 1, 2022
    risk 0.80cvss 9.8epss 1.00

    A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar,…

  • CVE-2018-0125CriKEVFeb 8, 2018
    risk 0.80cvss 9.8epss 0.55

    A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root…

  • CVE-2025-20393CriKEVDec 17, 2025
    risk 0.79cvss 10.0epss 0.30

    A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This…

  • CVE-2016-6366HigKEVAug 18, 2016
    risk 0.79cvss 8.8epss 0.88

    Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted…

  • CVE-2022-20708CriKEVFeb 10, 2022
    risk 0.78cvss 10.0epss 0.15

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…