Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.0
CVE-2015-6368
Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to read files via a crafted HTTP request, ak…
Firepower Extensible Operating System
Mitigation only
MEDIUM 5.0
CVE-2015-6364
Cisco Content Delivery System Manager Software 3.2 on Videoscape Distribution Suite Service Manager allows remote attackers to obtain sensitive infor…
Videoscape Distribution Suite Service Manager
after 3.2.0
MEDIUM 5.0
CVE-2015-6355
The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote attackers to obtain potentially sensitive version i…
Unified Computing System
Mitigation only
MEDIUM 6.8
CVE-2015-6328
The web framework in Cisco Prime Collaboration Assurance (PCA) 10.5(1) allows remote authenticated users to bypass intended access restrictions and r…
Prime Collaboration Assurance
Mitigation only
MEDIUM 5.0
CVE-2015-6276
Cisco TelePresence IX5000 8.0.3 stores a private key associated with an X.509 certificate under the web root with insufficient access control, which …
Telepresence System Software Ix
Mitigation only
MEDIUM 6.8
CVE-2015-4308
The webGUI configuration-export feature in Cisco Edge Bluebird Operating System 1.2 on Edge 340 devices allows remote authenticated users to obtain s…
Edge Bluebird Operating System
Mitigation only
MEDIUM 5.0
CVE-2015-4229
The web framework in Cisco Unified Communications Domain Manager 8.1(4)ER1 allows remote attackers to obtain sensitive information by visiting a bvsm…
Unified Communications Domain Manager
Mitigation only
MEDIUM 5.0
CVE-2015-4216
The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual A…
Content Security Management Virtual Appliance
Mitigation only
MEDIUM 5.0
CVE-2015-4218
The web-based user interface in Cisco Jabber through 9.6(3) and 9.7 through 9.7(5) on Windows allows remote attackers to obtain sensitive information…
Jabber
Mitigation only
MEDIUM 5.0
CVE-2015-4212
Cisco WebEx Meeting Center allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by discovering credential…
Webex Meeting Center
No fix yet
HIGH 7.5
CVE-2015-4208
Cisco WebEx Meeting Center does not properly restrict the content of URLs in GET requests, which allows remote attackers to obtain sensitive informat…
Webex Meeting Center
Mitigation only
MEDIUM 6.4
CVE-2015-4209
Cisco WebEx Meeting Center does not properly determine authorization for reading a host calendar, which allows remote attackers to obtain sensitive i…
Webex Meeting Center
Mitigation only
MEDIUM 5.0
CVE-2015-4207
Cisco WebEx Meeting Center places a meeting's access number in a URL, which allows remote attackers to obtain sensitive information and bypass intend…
Webex Meeting Center
Mitigation only
MEDIUM 5.0
CVE-2015-4202
Cisco IOS 12.2SCH on uBR10000 router Cable Modem Termination Systems (CMTS) does not properly restrict access to the IP Detail Record (IPDR) service,…
iOS
Mitigation only
MEDIUM 5.0
CVE-2015-4194
The web-based administrative interface in Cisco WebEx Meeting Center provides different error messages for failed login attempts depending on whether…
Webex Meeting Center
Mitigation only
MEDIUM 5.0
CVE-2015-0764
Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to read arbitrary files via a crafted resource request, aka Bug ID CSCus95603.
Unified Meetingplace
Mitigation only
MEDIUM 5.0
CVE-2015-0763
Cisco Unified MeetingPlace 8.6(1.2) does not properly validate session IDs in http URLs, which allows remote attackers to obtain sensitive session in…
Unified Meetingplace
Mitigation only
MEDIUM 5.0
CVE-2015-0745
Cisco Headend System Release allows remote attackers to read temporary script files or archive files, and consequently obtain sensitive information, …
Headend Digital Broadband Delivery System
Mitigation only
MEDIUM 5.0
CVE-2015-0757
The web framework in Cisco Identity Services Engine (ISE) 1.2(1.901) and 1.3(0.722) does not properly implement session handlers, which allows remote…
Identity Services Engine Software
Mitigation only
MEDIUM 5.0
CVE-2015-0628
The proxy engine on Cisco Web Security Appliance (WSA) devices allows remote attackers to bypass intended proxying restrictions via a malformed HTTP …
Web Security Appliance
Mitigation only
MEDIUM 5.0
CVE-2015-0602
The mobility extension on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to obtain sensitive information by s…
Unified Ip Phones 9900 Series Firmware
after 9.4
MEDIUM 5.0
CVE-2015-0597
The Forgot Password feature in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to enumerate administrative accounts via c…
Webex Meetings Server
after 1.5
MEDIUM 5.0
CVE-2015-0595
The XMLAPI in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading return messages …
Webex Meetings Server
after 1.5
MEDIUM 6.8
CVE-2014-8008EPSS 8%
Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manager (CUCM) allows remote authen…
Unified Communications Manager
Mitigation only
MEDIUM 5.0
CVE-2015-0590
Cisco WebEx Meeting Center allows remote attackers to activate disabled meeting attributes, and consequently obtain sensitive information, by providi…
Webex Meeting Center
Mitigation only
MEDIUM 5.0
CVE-2015-0583
Cisco WebEx Meeting Center does not properly restrict the content of URLs, which allows remote attackers to obtain sensitive information via vectors …
Webex Meeting Center
Mitigation only
MEDIUM 5.0
CVE-2014-8035
The web framework in Cisco WebEx Meetings Server produces different returned messages for URL requests depending on whether a username exists, which …
Webex Meetings Server
Mitigation only
MEDIUM 5.0
CVE-2014-8017
The periodic-backup feature in Cisco Identity Services Engine (ISE) allows remote attackers to discover backup-encryption passwords via a crafted req…
Identity Services Engine Software
Mitigation only
MEDIUM 5.0
CVE-2014-8009
The Management subsystem in Cisco Unified Computing System 2.1(3f) and earlier allows remote attackers to obtain sensitive information by reading log…
Unified Computing System
after 2.1
MEDIUM 5.0
CVE-2014-7992EPSS 27%
The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information fro…
iOS
Mitigation only