Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Cisco

25,873 known vulnerabilities

289
CRITICAL
1,422
HIGH
2,148
MEDIUM
17
LOW

Top Products

ios xe 395 secure firewall threat defense 271 nx-os 184 adaptive security appliance software 178 secure firewall management center 172 ios 167 identity services engine 164 rv130w 131 rv130w firmware 130 rv110w firmware 130
3,877 CVEs · Page 4/78
9.8
CVE-2025-20354

A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated,

8.6
CVE-2025-20343

A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Servi

4.3
CVE-2025-20305

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obta

5.4
CVE-2025-20304

Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticat

5.4
CVE-2025-20303

Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticat

4.8
CVE-2025-20289

Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticat

6.1
CVE-2025-20351

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phon

7.5
CVE-2025-20350

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phon

4.9
CVE-2025-20329

A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software cou

5.4
CVE-2025-20357

A vulnerability in the web-based management interface of Cisco Cyber Vision Center could allow an authenticated, remote

5.4
CVE-2025-20356

A vulnerability in the web-based management interface of Cisco Cyber Vision Center could allow an authenticated, remote

9.0
CVE-2025-20363

A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Fi

6.5
CVE-2025-20362 KEV

Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Softwar

9.9
CVE-2025-20333 KEV

A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secu

7.7
CVE-2025-20352 KEV

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Softwa

6.0
CVE-2025-20338

A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative pri

5.3
CVE-2025-20336

A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and C

5.3
CVE-2025-20335

A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and C

6.1
CVE-2025-20330

A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service

5.4
CVE-2025-20328

A vulnerability in the user profile component of Cisco Webex Meetings could have allowed an authenticated, remote attack

4.3
CVE-2025-20326

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and

4.3
CVE-2025-20291

A vulnerability in Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to redirect a targeted We

4.3
CVE-2025-20287

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow a

4.8
CVE-2025-20280

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri

4.3
CVE-2025-20270

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri

5.0
CVE-2025-20348

A vulnerability in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) co

5.4
CVE-2025-20347

A vulnerability in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) co

6.5
CVE-2025-20344

A vulnerability in the backup restore functionality of Cisco Nexus Dashboard could allow an authenticated, remote attack

6.5
CVE-2025-20269

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri

4.9
CVE-2025-20306

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could al

4.3
CVE-2025-20302

A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, low-pri

6.5
CVE-2025-20301

A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, low-pri

10.0
CVE-2025-20265

A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could a

6.1
CVE-2025-20235

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could al

4.9
CVE-2025-20218

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could al

8.5
CVE-2025-20148

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could al

7.7
CVE-2025-20127

A vulnerability in the TLS 1.3 implementation for a specific cipher for Cisco Secure Firewall Adaptive Security Applianc

10.0
CVE-2025-20337 KEV

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to exec

5.8
CVE-2025-20288

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticate

4.1
CVE-2025-20285

A vulnerability in the IP Access Restriction feature of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote

6.5
CVE-2025-20284

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execut

6.5
CVE-2025-20283

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execut

6.3
CVE-2025-20274

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated,

4.3
CVE-2025-20272

A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (E

10.0
CVE-2025-20309

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Ma

4.8
CVE-2025-20307

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an

6.1
CVE-2025-20310

A vulnerability in the web UI of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker t

6.0
CVE-2025-20308

A vulnerability in Cisco Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute

10.0
CVE-2025-20282

A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upl

10.0
CVE-2025-20281 KEV

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to exec

Frequently Asked Questions

How many CVEs affect Cisco?

Cisco has 25,873 CVE records in our database, including 1527 critical and 9659 high severity vulnerabilities. 90 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Cisco vulnerabilities?

Cisco has 1527 critical severity (CVSS 9.0+) and 9659 high severity (CVSS 7.0-8.9) vulnerabilities. 90 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Cisco vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Cisco products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Cisco Vulnerabilities

CyberStrike scans your infrastructure for Cisco vulnerabilities and provides real-time remediation guidance.

Get Started