Vulnerability index

Browse CVEs

3,250 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Wireless Lan Controller Software MEDIUM 6.5
CVE-2016-1460

Cisco Wireless LAN Controller (WLC) devices 7.4(121.0) and 8.0(0.30220.385) allow remote attackers to cause a denial of service via crafted wireless …

Mitigation only
Fix from $1,600 2016-07-28
Unified Computing System Performance Manager HIGH 8.8
CVE-2016-1374

The web framework in Cisco Unified Computing System (UCS) Performance Manager 2.0.0 and earlier allows remote authenticated users to execute arbitrar…

Mitigation only
Fix from $1,950 2016-07-28
iOS MEDIUM 5.3
CVE-2016-1459

Cisco IOS 12.4 and 15.0 through 15.5 and IOS XE 3.13 through 3.17 allow remote authenticated users to cause a denial of service (device reload) via c…

Mitigation only
Fix from $1,600 2016-07-17
Webex Meetings Server HIGH 8.8
CVE-2016-1448

Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.7 allows remote attackers to hijack the authentication of arbitrary …

Mitigation only
Fix from $1,950 2016-07-17
Ios Xr HIGH 7.8
CVE-2016-1456

The CLI in Cisco IOS XR 6.x through 6.0.1 allows local users to execute arbitrary OS commands in a privileged context by leveraging unspecified conta…

Mitigation only
Fix from $1,950 2016-07-15
Asr 5000 MEDIUM 6.5
CVE-2016-1452

Cisco ASR 5000 devices with software 18.3 through 20.0.0 allow remote attackers to make configuration changes over SNMP by leveraging knowledge of th…

Mitigation only
Fix from $1,600 2016-07-15
Meeting Server MEDIUM 6.1
CVE-2016-1451

Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Meeting Server (formerly Acano Conferencing Server) 1.7 throu…

Mitigation only
Fix from $1,600 2016-07-15
Webex Meetings Server HIGH 7.5
CVE-2016-1450

Cisco WebEx Meetings Server 2.6 allows remote authenticated users to conduct command-injection attacks via vectors related to an upload's file type, …

Mitigation only
Fix from $1,950 2016-07-15
Webex Meetings Server MEDIUM 6.1
CVE-2016-1449

Cross-site scripting (XSS) vulnerability in Cisco WebEx Meetings Server 2.6 allows remote attackers to inject arbitrary web script or HTML via a craf…

Mitigation only
Fix from $1,600 2016-07-15
Webex Meetings Server MEDIUM 6.1
CVE-2016-1447

Cross-site scripting (XSS) vulnerability in the administrator interface in Cisco WebEx Meetings Server 2.6 allows remote attackers to inject arbitrar…

Mitigation only
Fix from $1,600 2016-07-15
Webex Meetings Server HIGH 8.8
CVE-2016-1446

SQL injection vulnerability in Cisco WebEx Meetings Server 2.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified ve…

Mitigation only
Fix from $1,950 2016-07-15
Ios Xr HIGH 7.5
CVE-2016-1426

Cisco IOS XR 5.x through 5.2.5 on NCS 6000 devices allows remote attackers to cause a denial of service (timer consumption and Route Processor reload…

Mitigation only
Fix from $1,950 2016-07-15
Telepresence Video Communication Server MEDIUM 6.5
CVE-2016-1444

The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 and Expressway X8.1 through X8.…

Mitigation only
Fix from $1,600 2016-07-07
Amp Threat Grid Appliance HIGH 8.1
CVE-2016-1443

The virtual network stack on Cisco AMP Threat Grid Appliance devices before 2.1.1 allows remote attackers to bypass a sandbox protection mechanism, a…

Mitigation only
Fix from $1,950 2016-07-07
Prime Infrastructure HIGH 8.8
CVE-2016-1442

The administrative web interface in Cisco Prime Infrastructure (PI) before 3.1.1 allows remote authenticated users to execute arbitrary commands via …

Mitigation only
Fix from $1,950 2016-07-07
iOS MEDIUM 6.5
CVE-2016-1425

Cisco IOS 15.0(2)SG5, 15.1(2)SG3, 15.2(1)E, 15.3(3)S, and 15.4(1.13)S allows remote attackers to cause a denial of service (device crash) via a craft…

Mitigation only
Fix from $1,600 2016-07-03
Rv130w Firmware MEDIUM 6.5
CVE-2016-1398

Buffer overflow in the web-based management interface on Cisco RV110W devices with firmware through 1.2.1.4, RV130W devices with firmware through 1.0…

Mitigation only
Fix from $1,600 2016-07-03
Epc3928 Firmware HIGH 8.1
CVE-2016-1337

Cisco EPC3928 devices allow remote attackers to obtain sensitive configuration and credential information by making requests during the early part of…

No fix yet
Fix from $1,950 2016-07-03
Epc3928 Firmware HIGH 7.5
CVE-2016-1336EPSS 9%

goform/Docsis_system on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long LanguageSelect parameter…

No fix yet
Fix from $1,950 2016-07-03
Epc3928 Firmware HIGH 7.5
CVE-2016-1328EPSS 9%

goform/WClientMACList on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long h_sortWireless paramete…

No fix yet
Fix from $1,950 2016-07-03
Cloud Network Automation Provisioner HIGH 8.2
CVE-2016-1441

Cisco Cloud Network Automation Provisioner (CNAP) 1.0(0) in Cisco Configuration Assistant (CCA) allows remote attackers to bypass intended filesystem…

Mitigation only
Fix from $1,950 2016-07-03
Firesight System Software HIGH 8.6
CVE-2016-1394

Cisco Firepower System Software 6.0.0 through 6.1.0 has a hardcoded account, which allows remote attackers to obtain CLI access by leveraging knowled…

Mitigation only
Fix from $1,950 2016-07-03
Web Security Appliance MEDIUM 5.3
CVE-2016-1440

The proxy process on Cisco Web Security Appliance (WSA) devices through 9.1.0-070 allows remote attackers to cause a denial of service (CPU consumpti…

Mitigation only
Fix from $1,600 2016-07-02
Prime Collaboration Provisioning CRITICAL 9.8
CVE-2016-1416

Cisco Prime Collaboration Provisioning 10.6 SP2 (aka 10.6.0.10602) mishandles LDAP authentication, which allows remote attackers to obtain administra…

Mitigation only
Fix from $2,300 2016-07-02
Prime Infrastructure HIGH 8.8
CVE-2016-1408

Cisco Prime Infrastructure 1.2 through 3.1 and Evolved Programmable Network Manager (EPNM) 1.2 and 2.0 allow remote authenticated users to execute ar…

Mitigation only
Fix from $1,950 2016-07-02
Prime Infrastructure CRITICAL 9.8
CVE-2016-1289EPSS 6%

The API in Cisco Prime Infrastructure 1.2 through 3.0 and Evolved Programmable Network Manager (EPNM) 1.2 allows remote attackers to execute arbitrar…

Mitigation only
Fix from $2,300 2016-07-02
Asyncos HIGH 7.5
CVE-2016-1438

Cisco AsyncOS 9.7.0-125 on Email Security Appliance (ESA) devices allows remote attackers to bypass intended spam filtering via crafted executable co…

Mitigation only
Fix from $1,950 2016-06-23
Unified Contact Center Enterprise MEDIUM 6.1
CVE-2016-1439

Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Contact Center Enterprise through 10.5(2) allows remote attacke…

Mitigation only
Fix from $1,600 2016-06-23
Prime Collaboration Deployment MEDIUM 6.5
CVE-2016-1437

SQL injection vulnerability in the SQL database in Cisco Prime Collaboration Deployment before 11.5.1 allows remote authenticated users to execute ar…

Mitigation only
Fix from $1,600 2016-06-23
Asr 5000 Software HIGH 7.5
CVE-2016-1436

The General Packet Radio Switching Tunneling Protocol 1 (aka GTPv1) implementation on Cisco ASR 5000 Packet Data Network Gateway devices before 19.4 …

Mitigation only
Fix from $1,950 2016-06-23