Vulnerability index

Browse CVEs

42 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Secure Workload CRITICAL 10.0
CVE-2026-20223

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to acces…

Fix: 3.10.8.3 / 4.0.3.17+
Fix from $2,300 2026-05-20
Intersight Device Connector HIGH 8.2
CVE-2026-5944

An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passth…

Fix: after 7.5.0
Fix from $1,950 2026-04-28
Unified Contact Center Express CRITICAL 9.8
CVE-2025-20358

A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass…

Fix: 12.5+
Fix from $2,300 2025-11-05
Catalyst Center HIGH 7.3
CVE-2025-20210

A vulnerability in the management API of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to read an…

Fix: 2.3.7.9+
Fix from $1,950 2025-05-07
Confd Basic CRITICAL 10.0
CVE-2025-32433 KEVEPSS 99%

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server ma…

Fix: 5.7.19.1 / 6.1.16.2+
Fix from $2,300 2025-04-16
Secure Client MEDIUM 6.8
CVE-2024-20391

A vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacker with physical access to an …

Fix: 5.1.3.62+
Fix from $1,600 2024-05-15
Business 140ac Access Point Firmware HIGH 8.8
CVE-2023-20003

A vulnerability in the social login configuration option for the guest users of Cisco Business Wireless Access Points (APs) could allow an unauthenti…

Fix: 10.8.1.0+
Fix from $1,950 2023-05-18
Spa112 Firmware CRITICAL 9.8
CVE-2023-20126EPSS 37%

A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execut…

Mitigation only
Fix from $2,300 2023-05-04
Catalyst Sd Wan Manager MEDIUM 5.3
CVE-2022-20830

A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an una…

Fix: 20.3.4.1 / 20.6.1+
Fix from $1,600 2022-10-10
Nexus Dashboard CRITICAL 9.8
CVE-2022-20857

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload conta…

Fix: 2.2+
Fix from $2,300 2022-07-21
Nexus Dashboard CRITICAL 9.8
CVE-2022-20858

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload conta…

Fix: 2.2+
Fix from $2,300 2022-07-21
Nexus Dashboard HIGH 8.8
CVE-2022-20861

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload conta…

Fix: 2.2+
Fix from $1,950 2022-07-21
Hyperflex Hx Data Platform MEDIUM 5.3
CVE-2021-1499EPSS 80%

A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to upload f…

Fix: 4.0 / 4.5+
Fix from $1,600 2021-05-06
Application Services Engine CRITICAL 9.8
CVE-2021-1393

Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged access to host-level…

Fix: 1.1+
Fix from $2,300 2021-02-24
Application Services Engine MEDIUM 6.5
CVE-2021-1396

Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged access to host-level…

Fix: 1.1+
Fix from $1,600 2021-02-24
Finesse MEDIUM 6.1
CVE-2021-1246

Cisco Finesse, Cisco Virtualized Voice Browser, and Cisco Unified CVP OpenSocial Gadget Editor Unauthenticated Access Vulnerability A vulnerabilit…

Fix: 12.0+
Fix from $1,600 2021-01-13
Iot Field Network Director CRITICAL 9.8
CVE-2020-3531

A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to access the back-end data…

Fix: 4.6.1+
Fix from $2,300 2020-11-18
Iot Field Network Director HIGH 7.5
CVE-2020-3392

A vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive information on…

Fix: 4.6.1+
Fix from $1,950 2020-11-18
Vision Dynamic Signage Director MEDIUM 6.5
CVE-2020-3598

A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to acc…

Fix: 6.2.0+
Fix from $1,600 2020-10-08
Vision Dynamic Signage Director MEDIUM 6.5
CVE-2019-16004

A vulnerability in the REST API endpoint of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to bypass authentic…

Fix: 6.2.0+
Fix from $1,600 2020-09-23
Cyber Vision Center MEDIUM 5.8
CVE-2020-3448

A vulnerability in an access control mechanism of Cisco Cyber Vision Center Software could allow an unauthenticated, remote attacker to bypass authen…

Fix: 3.0.4+
Fix from $1,600 2020-08-17
Data Center Network Manager MEDIUM 5.3
CVE-2020-3461

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to …

Fix: 11.4+
Fix from $1,600 2020-07-31
Data Center Network Manager CRITICAL 9.8
CVE-2020-3376

A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypa…

Mitigation only
Fix from $2,300 2020-07-31
Unified Customer Voice Portal HIGH 7.5
CVE-2020-3402

A vulnerability in the Java Remote Method Invocation (RMI) interface of Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, rem…

Fix: after 12.5
Fix from $1,950 2020-07-02
Application Policy Infrastructure Controller MEDIUM 5.5
CVE-2020-3335

A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attacker to read sensitive informa…

Fix: 1.1.2.20+
Fix from $1,600 2020-06-03
Application Policy Infrastructure Controller MEDIUM 5.3
CVE-2020-3333

A vulnerability in the API of Cisco Application Services Engine Software could allow an unauthenticated, remote attacker to update event policies on …

Fix: 1.1.2.20+
Fix from $1,600 2020-06-03
Webex Meetings Online HIGH 7.5
CVE-2020-3142

A vulnerability in Cisco Webex Meetings Suite sites and Cisco Webex Meetings Online sites could allow an unauthenticated, remote attendee to join a p…

Fix: 39.11.5 / 40.1.3+
Fix from $1,950 2020-01-26
Ucs Director MEDIUM 5.3
CVE-2019-16003

A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attacker to download system log fi…

Fix: 6.7.3.1+
Fix from $1,600 2020-01-26
Identity Services Engine Software MEDIUM 5.3
CVE-2019-15282

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacke…

Fix: 2.4+
Fix from $1,600 2019-10-16
Integrated Management Controller Supervisor HIGH 7.5
CVE-2019-12634

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS D…

Fix: after 6.7.2.0
Fix from $1,950 2019-08-21