Vulnerability index

Browse CVEs

3,250 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Small Business 220 Series Smart Plus Switches HIGH 7.5
CVE-2016-1472

The web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to cause a denial of serv…

Mitigation only
Fix from $1,950 2016-09-02
Small Business 220 Series Smart Plus Switches MEDIUM 6.1
CVE-2016-1471

Cross-site scripting (XSS) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allow…

No fix yet
Fix from $1,600 2016-09-02
Small Business 220 Series Smart Plus Switches HIGH 8.8
CVE-2016-1470

Cross-site request forgery (CSRF) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.…

No fix yet
Fix from $1,950 2016-09-02
Anyconnect Secure Mobility Client HIGH 7.8
CVE-2016-6369

Cisco AnyConnect Secure Mobility Client before 4.2.05015 and 4.3.x before 4.3.02039 mishandles pathnames, which allows local users to gain privileges…

Mitigation only
Fix from $1,950 2016-08-25
Secure Firewall Management Center MEDIUM 6.1
CVE-2016-6365

Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.0.2, 5.3.1, and 5.4.0 allows remote attackers…

Mitigation only
Fix from $1,600 2016-08-23
Ios Xr HIGH 7.5
CVE-2016-6355

Memory leak in Cisco IOS XR 5.1.x through 5.1.3, 5.2.x through 5.2.5, and 5.3.x through 5.3.2 on ASR 9001 devices allows remote attackers to cause a …

Mitigation only
Fix from $1,950 2016-08-23
Unified Communications Manager HIGH 7.5
CVE-2016-6364

The User Data Services (UDS) API implementation in Cisco Unified Communications Manager 11.5 allows remote attackers to bypass intended access restri…

Mitigation only
Fix from $1,950 2016-08-23
Webex Meetings Server HIGH 7.5
CVE-2016-1484

Cisco WebEx Meetings Server 2.6 allows remote attackers to bypass intended access restrictions and obtain sensitive application information via unspe…

Mitigation only
Fix from $1,950 2016-08-23
Connected Streaming Analytics MEDIUM 6.5
CVE-2016-1477

Cisco Connected Streaming Analytics 1.1.1 allows remote authenticated users to discover a notification service password by reading administrative pag…

Mitigation only
Fix from $1,600 2016-08-23
Aironet Access Point Software MEDIUM 6.5
CVE-2016-6363

The rate-limit feature in the 802.11 protocol implementation on Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.121.0 and 8.3.x b…

Mitigation only
Fix from $1,600 2016-08-22
Aironet Access Point Software HIGH 7.8
CVE-2016-6362

Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.110.0, 8.2.12x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow local users to …

Mitigation only
Fix from $1,950 2016-08-22
Aironet Access Point Software MEDIUM 6.5
CVE-2016-6361

The Aggregated MAC Protocol Data Unit (AMPDU) implementation on Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.121.0 and 8.3.x b…

Mitigation only
Fix from $1,600 2016-08-22
Transport Gateway Installation Software MEDIUM 6.1
CVE-2016-6359

Cross-site scripting (XSS) vulnerability in Cisco Transport Gateway Installation Software 4.1(4.0) on Smart Call Home Transport Gateway devices allow…

Mitigation only
Fix from $1,600 2016-08-22
Identity Services Engine Software MEDIUM 6.1
CVE-2016-1485

Cross-site scripting (XSS) vulnerability in Cisco Identity Services Engine 1.3(0.876) allows remote attackers to inject arbitrary web script or HTML …

Mitigation only
Fix from $1,600 2016-08-22
Ip Phone 8800 Series Firmware HIGH 7.5
CVE-2016-1479

Cisco IP Phone 8800 devices with software 11.0(1) allow remote attackers to cause a denial of service (memory corruption) via a crafted HTTP request,…

Mitigation only
Fix from $1,950 2016-08-22
Ip Phone 8800 Series Firmware MEDIUM 5.4
CVE-2016-1476

Cross-site scripting (XSS) vulnerability on Cisco IP Phone 8800 devices with software 11.0 allows remote authenticated users to inject arbitrary web …

Mitigation only
Fix from $1,600 2016-08-22
Secure Firewall Management Center HIGH 8.8
CVE-2016-1458

The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.3.1.2, and 5.4.x before 5.4.0.1 and Cisco Adaptiv…

Mitigation only
Fix from $1,950 2016-08-18
Secure Firewall Management Center HIGH 8.8
CVE-2016-1457

The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA…

Mitigation only
Fix from $1,950 2016-08-18
Application Policy Infrastructure Controller Enterprise Module HIGH 8.8
CVE-2016-1365

The Grapevine update process in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0 allows remote authenticated users …

Mitigation only
Fix from $1,950 2016-08-18
iOS HIGH 7.5
CVE-2016-1478

Cisco IOS 15.5(3)S3, 15.6(1)S2, 15.6(2)S1, and 15.6(2)T1 does not properly dequeue invalid NTP packets, which allows remote attackers to cause a deni…

Mitigation only
Fix from $1,950 2016-08-08
Telepresence Video Communication Server HIGH 8.8
CVE-2016-1468

The administrative web interface in Cisco TelePresence Video Communication Server Expressway X8.5.2 allows remote authenticated users to execute arbi…

Mitigation only
Fix from $1,950 2016-08-08
Unified Communications Manager Im And Presence Service HIGH 7.5
CVE-2016-1466

Cisco Unified Communications Manager IM and Presence Service 9.1(1) SU6, 9.1(1) SU6a, 9.1(1) SU7, 10.5(2) SU2, 10.5(2) SU2a, 11.0(1) SU1, and 11.5(1)…

Mitigation only
Fix from $1,950 2016-08-08
Rv180 Vpn Router Firmware HIGH 8.8
CVE-2016-1430

Cisco RV180 and RV180W devices allow remote authenticated users to execute arbitrary commands as root via a crafted HTTP request, aka Bug ID CSCuz485…

Mitigation only
Fix from $1,950 2016-08-08
Rv180 Vpn Router Firmware HIGH 7.5
CVE-2016-1429EPSS 7%

Directory traversal vulnerability in the web interface on Cisco RV180 and RV180W devices allows remote attackers to read arbitrary files via a crafte…

Mitigation only
Fix from $1,950 2016-08-08
Rv110w Wireless N Vpn Firewall Firmware HIGH 8.8
CVE-2015-6397

Cisco RV110W, RV130W, and RV215W devices have an incorrect RBAC configuration for the default account, which allows remote authenticated users to obt…

Mitigation only
Fix from $1,950 2016-08-08
Rv110w Wireless N Vpn Firewall Firmware HIGH 7.8
CVE-2015-6396

The CLI command parser on Cisco RV110W, RV130W, and RV215W devices allows local users to execute arbitrary shell commands as an administrator via cra…

No fix yet
Fix from $1,950 2016-08-08
Videoscape Session Resource Manager MEDIUM 6.5
CVE-2016-1467

Cisco Videoscape Session Resource Manager (VSRM) allows remote attackers to cause a denial of service (device restart) by sending a traffic flood to …

Mitigation only
Fix from $1,600 2016-07-28
Nx Os MEDIUM 6.5
CVE-2016-1465

Cisco Nexus 1000v Application Virtual Switch (AVS) devices before 5.2(1)SV3(1.5i) allow remote attackers to cause a denial of service (ESXi hyperviso…

Mitigation only
Fix from $1,600 2016-07-28
Firesight System Software HIGH 7.5
CVE-2016-1463

Cisco FireSIGHT System Software 5.3.0, 5.3.1, 5.4.0, 6.0, and 6.0.1 allows remote attackers to bypass Snort rules via crafted parameters in the heade…

Mitigation only
Fix from $1,950 2016-07-28
Prime Service Catalog MEDIUM 6.1
CVE-2016-1462

Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Prime Service Catalog (PSC) 11.0 allows remote attackers to i…

Mitigation only
Fix from $1,600 2016-07-28