Vulnerability index

Browse CVEs

59 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Umbrella Virtual Appliance MEDIUM 6.0
CVE-2026-20246

A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affec…

Fix: 3.8.5+
Fix from $1,600 2026-06-17
Identity Services Engine CRITICAL 10.0
CVE-2025-20282EPSS 27%

A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an aff…

Mitigation only
Fix from $2,300 2025-06-25
Secure Firewall Management Center HIGH 7.2
CVE-2024-20374

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center…

Mitigation only
Fix from $1,950 2024-10-23
Nexus Dashboard MEDIUM 6.0
CVE-2024-20282

A vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid rescue-user credentials to elevate privileges to roo…

Fix: 3.1+
Fix from $1,600 2024-04-03
Appdynamics HIGH 7.8
CVE-2023-20274

A vulnerability in the installer script of Cisco AppDynamics PHP Agent could allow an authenticated, local attacker to elevate privileges on an affec…

Mitigation only
Fix from $1,950 2023-11-21
Secure Firewall Management Center CRITICAL 9.9
CVE-2023-20048EPSS 16%

A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to ex…

Fix: after 7.3.1.1
Fix from $2,300 2023-11-01
Ios Xe HIGH 8.8
CVE-2023-20235

A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastructure in Cisco IOS XE Softwa…

Fix: 17.3.1+
Fix from $1,950 2023-10-04
Identity Services Engine MEDIUM 6.7
CVE-2023-20193

A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, write, or delete arbitrary fi…

Fix: after 3.3
Fix from $1,600 2023-09-07
Emergency Responder HIGH 7.2
CVE-2023-20266

A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Managem…

Mitigation only
Fix from $1,950 2023-08-30
Broadworks Application Delivery Platform HIGH 7.8
CVE-2023-20216

A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevat…

Fix: 23.0.2023.05 / 24.0.2023.05+
Fix from $1,950 2023-08-03
Secure Workload MEDIUM 6.5
CVE-2023-20136

A vulnerability in the OpenAPI of Cisco Secure Workload could allow an authenticated, remote attacker with the privileges of a read-only user to exec…

Fix: 3.7.1.40+
Fix from $1,600 2023-06-28
Nexus Dashboard MEDIUM 6.7
CVE-2022-20906

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vul…

Fix: 2.2+
Fix from $1,600 2022-07-22
Nexus Dashboard MEDIUM 6.7
CVE-2022-20907

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vul…

Fix: 2.2+
Fix from $1,600 2022-07-22
Identity Services Engine MEDIUM 6.5
CVE-2022-20819

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain…

Fix: 2.4.0.357 / 2.6.0.156+
Fix from $1,600 2022-06-15
Secure Firewall Threat Defense HIGH 8.8
CVE-2022-20759EPSS 29%

A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower …

Fix: 6.4.0.15 / 6.6.5.2+
Fix from $1,950 2022-05-03
Catalyst Sd Wan Manager HIGH 7.3
CVE-2022-20739

A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to execute arbitrary commands on the underly…

Fix: 20.6.1+
Fix from $1,950 2022-04-15
Identity Services Engine MEDIUM 6.5
CVE-2022-20782

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain…

Mitigation only
Fix from $1,600 2022-04-06
Anyconnect Secure Mobility Client HIGH 7.8
CVE-2021-40124

A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local…

Fix: 4.10.03104+
Fix from $1,950 2021-11-04
Smart Software Manager On Prem HIGH 8.8
CVE-2021-34766

A vulnerability in the web UI of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileg…

Fix: 8-202108+
Fix from $1,950 2021-10-06
Application Policy Infrastructure Controller HIGH 8.8
CVE-2021-1579

A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Con…

Fix: 3.2 / 4.2+
Fix from $1,950 2021-08-25
Appdynamics .net Agent HIGH 7.8
CVE-2021-34745

A vulnerability in the AppDynamics .NET Agent for Windows could allow an attacker to leverage an authenticated, local user account to gain SYSTEM pri…

Fix: 21.7+
Fix from $1,950 2021-08-18
Confd HIGH 7.8
CVE-2021-1572

A vulnerability in ConfD could allow an authenticated, local attacker to execute arbitrary commands at the level of the account under which ConfD is …

Fix: after 7.5.2
Fix from $1,950 2021-08-04
Wap125 Firmware HIGH 7.2
CVE-2021-1401

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could …

Fix: after 1.1.2.4
Fix from $1,950 2021-05-06
Content Security Management Appliance MEDIUM 6.7
CVE-2021-1447

A vulnerability in the user account management system of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an authentic…

Fix: 12.8.1-002 / 13.8.1-068+
Fix from $1,600 2021-05-06
Wap125 Firmware HIGH 8.8
CVE-2021-1400

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could …

Fix: after 1.1.2.4
Fix from $1,950 2021-05-06
Ios Xe Sd Wan MEDIUM 6.6
CVE-2021-1371

A vulnerability in the role-based access control of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker with read-only privileg…

Mitigation only
Fix from $1,600 2021-03-24
Aci Multi Site Orchestrator CRITICAL 10.0
CVE-2021-1388EPSS 14%

A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthentic…

Fix: 3.0+
Fix from $2,300 2021-02-24
Anyconnect Secure Mobility Client MEDIUM 5.5
CVE-2021-1258

A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges …

Fix: 4.9.03047 / 4.9.03049+
Fix from $1,600 2021-01-13
Jabber CRITICAL 9.9
CVE-2020-27132

Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary …

No fix yet
Fix from $2,300 2020-12-11
Jabber CRITICAL 9.9
CVE-2020-27133

Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary …

No fix yet
Fix from $2,300 2020-12-11