Cisco
25,873 known vulnerabilities
Top Products
A vulnerability in the SNORT detection engine of Cisco Firepower System Software could allow an unauthenticated, remote
A vulnerability exists in the process of creating default IP blocks during device initialization for Cisco ASA Next-Gene
Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could all
Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could all
Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could all
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access sensitive data
A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to conduct a cross-site scr
A vulnerability in the handling of 802.11w Protected Management Frames (PAF) by Cisco Aironet 3800 Series Access Points
A vulnerability in the Access Network Query Protocol (ANQP) ingress frame processing functionality of Cisco Wireless LAN
A vulnerability in the implementation of Protected Extensible Authentication Protocol (PEAP) functionality for standalon
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) Discovery Request parsing functionali
A vulnerability in the packet processing code of Cisco IOS Software for Cisco Aironet Access Points could allow an unaut
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Wireless LAN Controllers could allow
A vulnerability in the Smart Licensing Manager service of the Cisco Firepower 4100 Series Next-Generation Firewall (NGFW
A vulnerability in the web framework code for the SQL database interface of the Cisco Prime Collaboration Provisioning a
A vulnerability in the implementation of 802.11v Basic Service Set (BSS) Transition Management functionality in Cisco Wi
A vulnerability in Extensible Authentication Protocol (EAP) ingress frame processing for the Cisco Aironet 1560, 2800, a
A vulnerability in 802.11 association request frame processing for the Cisco Aironet 1560, 2800, and 3800 Series Access
A vulnerability within the firewall configuration of the Cisco Application Policy Infrastructure Controller Enterprise M
A vulnerability in the restricted shell of the Cisco Identity Services Engine (ISE) that is accessible via SSH could all
A vulnerability in the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewal
Cisco WebEx Meetings Server before 1.1 uses meeting IDs with insufficient entropy, which makes it easier for remote atta
Cisco Small Business SA520 and SA540 devices with firmware 2.1.71 and 2.2.0.7 allow ../ directory traversal in scgi-bin/
The Cisco AMP For Endpoints application allows an authenticated, local attacker to access a static key value stored in t
A vulnerability in the authentication, authorization, and accounting (AAA) implementation of Cisco Firepower Extensible
A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker t
A vulnerability in Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to conduct a cross-site sc
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site s
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to cause a denial of serv
A vulnerability in conditional, verbose debug logging for the IPsec feature of Cisco IOS XE Software could allow an auth
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express could allow an unauthentic
A vulnerability in the cluster database (CDB) management component of Cisco Expressway Series Software and Cisco TelePre
A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to retrieve user profi
A vulnerability in the web interface of Cisco Network Analysis Module Software could allow an unauthenticated, remote at
A vulnerability in the web interface of Cisco Jabber for Windows Client could allow an authenticated, local attacker to
A vulnerability in the web framework code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to co
A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute u
A vulnerability in the implementation of Session Initiation Protocol (SIP) functionality in Cisco Small Business SPA50x,
A vulnerability in the implementation of Session Initiation Protocol (SIP) functionality in Cisco Small Business SPA51x
A vulnerability in the web console of the Cisco Cloud Services Platform (CSP) 2100 could allow an authenticated, remote
Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allow
A vulnerability in the gRPC code of Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series Routers
A vulnerability in the web UI of Cisco Spark Messaging Software could allow an authenticated, remote attacker to perform
A vulnerability in the Network Access Manager (NAM) of Cisco AnyConnect Secure Mobility Client could allow an authentica
A vulnerability in the Independent Computing Architecture (ICA) accelerator feature for the Cisco Wide Area Application
A vulnerability in the routine that loads DLL files in Cisco Meeting App for Windows could allow an authenticated, local
A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an
A vulnerability in the Web Admin Interface of Cisco Meeting Server could allow an unauthenticated, remote attacker to ca
A vulnerability in the web interface of Cisco License Manager software could allow an unauthenticated, remote attacker t
A vulnerability in the web-based UI of Cisco Unified Communications Manager could allow an unauthenticated, remote attac
Frequently Asked Questions
How many CVEs affect Cisco?
Cisco has 25,873 CVE records in our database, including 1527 critical and 12515 high severity vulnerabilities. 90 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Cisco vulnerabilities?
Cisco has 1527 critical severity (CVSS 9.0+) and 12515 high severity (CVSS 7.0-8.9) vulnerabilities. 90 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Cisco vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Cisco products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Cisco Vulnerabilities
CyberStrike scans your infrastructure for Cisco vulnerabilities and provides real-time remediation guidance.
Get Started