Vulnerability index

Browse CVEs

3,250 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Email Security Appliance Firmeware HIGH 7.5
CVE-2016-1315

The proxy engine in Cisco Advanced Malware Protection (AMP), when used with Email Security Appliance (ESA) 9.5.0-201, 9.6.0-051, and 9.7.0-125, allow…

Mitigation only
Fix from $1,950 2016-02-12
Adaptive Security Appliance Software CRITICAL 9.8
CVE-2016-1287EPSS 77%

Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0 before 9.0(4.38), 9.1 before…

No fix yet
Fix from $2,300 2016-02-11
Application Policy Infrastructure Controller Enterprise Module MEDIUM 6.1
CVE-2016-1318

Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.1 allows remote attacker…

Mitigation only
Fix from $1,600 2016-02-09
Telepresence Video Communication Server Software MEDIUM 5.3
CVE-2016-1316

Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7, as used in conjunction with Jabber Guest, allows remote attackers to obtain se…

Mitigation only
Fix from $1,600 2016-02-09
Webex Meetings Server MEDIUM 6.1
CVE-2016-1309

Multiple cross-site scripting (XSS) vulnerabilities in Cisco WebEx Meetings Server 2.5.1.5 allow remote attackers to inject arbitrary web script or H…

Mitigation only
Fix from $1,600 2016-02-07
Application Policy Infrastructure Controller Enterprise Module MEDIUM 6.1
CVE-2016-1305

Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.1 allows remote attacker…

Mitigation only
Fix from $1,600 2016-02-07
Prime Security Manager HIGH 8.8
CVE-2016-1301

The RBAC implementation in Cisco ASA-CX Content-Aware Security software before 9.3.1.1(112) and Cisco Prime Security Manager (PRSM) software before 9…

Mitigation only
Fix from $1,950 2016-02-07
Jabber Guest MEDIUM 6.1
CVE-2016-1311

Cross-site scripting (XSS) vulnerability in the management interface in Cisco Jabber Guest Server 10.6(8) allows remote attackers to inject arbitrary…

Mitigation only
Fix from $1,600 2016-02-06
Unity Connection MEDIUM 6.1
CVE-2016-1304

Cross-site scripting (XSS) vulnerability in Cisco Unity Connection 10.5(2.3009) allows remote attackers to inject arbitrary web script or HTML via a …

Mitigation only
Fix from $1,600 2016-01-30
500 Series Switch Firmware HIGH 7.5
CVE-2016-1303

The web GUI on Cisco Small Business 500 devices 1.2.0.92 allows remote attackers to cause a denial of service via a crafted HTTP request, aka Bug ID …

Mitigation only
Fix from $1,950 2016-01-30
Unity Connection MEDIUM 6.1
CVE-2016-1300

Cross-site scripting (XSS) vulnerability in Cisco Unity Connection (UC) 10.5(2.3009) allows remote attackers to inject arbitrary web script or HTML v…

Mitigation only
Fix from $1,600 2016-01-27
300 Series Managed Switch Firmware MEDIUM 5.3
CVE-2016-1299

The web-management GUI implementation on Cisco Small Business SG300 devices 1.4.1.x allows remote attackers to cause a denial of service (HTTPS outag…

Mitigation only
Fix from $1,600 2016-01-27
Wide Area Application Services HIGH 7.5
CVE-2015-6421

cifs-ao in the CIFS optimization functionality on Cisco Wide Area Application Service (WAAS) and Virtual WAAS (vWAAS) devices 5.x before 5.3.5d and 5…

Mitigation only
Fix from $1,950 2016-01-27
Rv Series Router Firmware CRITICAL 9.8
CVE-2015-6319

SQL injection vulnerability in the web-based management interface on Cisco RV220W devices allows remote attackers to execute arbitrary SQL commands v…

Mitigation only
Fix from $2,300 2016-01-27
Unified Contact Center Express MEDIUM 6.1
CVE-2016-1298

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Contact Center Express 10.0(1), 10.5(1), 10.6(1), and 11.0(1) allow remote attac…

Mitigation only
Fix from $1,600 2016-01-26
Application Policy Infrastructure Controller Enterprise Module MEDIUM 6.1
CVE-2015-6337

Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0.10 allows remote attac…

Mitigation only
Fix from $1,600 2016-01-26
Identity Services Engine Software MEDIUM 6.5
CVE-2015-6317

Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct re…

Mitigation only
Fix from $1,600 2016-01-23
Firepower Extensible Operating System CRITICAL 9.8
CVE-2015-6435EPSS 9%

An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(…

No fix yet
Fix from $2,300 2016-01-22
Modular Encoding Platform D9036 Software CRITICAL 9.8
CVE-2015-6412

Cisco Modular Encoding Platform D9036 Software before 02.04.70 has hardcoded (1) root and (2) guest passwords, which makes it easier for remote attac…

Mitigation only
Fix from $2,300 2016-01-22
Web Security Appliance HIGH 7.5
CVE-2016-1296

The proxy engine on Cisco Web Security Appliance (WSA) devices with software 8.5.3-055, 9.1.0-000, and 9.5.0-235 allows remote attackers to bypass in…

Mitigation only
Fix from $1,950 2016-01-20
Adaptive Security Appliance Software MEDIUM 5.3
CVE-2016-1295

Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote attackers to obtain sensitive information via an AnyConnect authentication attempt…

Mitigation only
Fix from $1,600 2016-01-16
Firesight System Software MEDIUM 6.1
CVE-2016-1294

Cross-site scripting (XSS) vulnerability in the Management Center in Cisco FireSIGHT System Software 6.0.1 allows remote attackers to inject arbitrar…

Mitigation only
Fix from $1,600 2016-01-16
Firesight System Software MEDIUM 6.1
CVE-2016-1293

Multiple cross-site scripting (XSS) vulnerabilities in the Management Center in Cisco FireSIGHT System Software 6.0.0 and 6.0.1 allow remote attacker…

Mitigation only
Fix from $1,600 2016-01-16
Aironet Access Point Software HIGH 7.3
CVE-2015-6336

Cisco Aironet 1800 devices with software 7.2, 7.3, 7.4, 8.1(112.3), 8.1(112.4), and 8.1(15.14) have a default account, which makes it easier for remo…

Mitigation only
Fix from $1,950 2016-01-15
Identity Services Engine Software CRITICAL 9.8
CVE-2015-6323

The Admin portal in Cisco Identity Services Engine (ISE) 1.1.x, 1.2.0 before patch 17, 1.2.1 before patch 8, 1.3 before patch 5, and 1.4 before patch…

Mitigation only
Fix from $2,300 2016-01-15
Aironet Access Point Software HIGH 7.5
CVE-2015-6320

The IP ingress packet handler on Cisco Aironet 1800 devices with software 8.1(112.3) and 8.1(112.4) allows remote attackers to cause a denial of serv…

Mitigation only
Fix from $1,950 2016-01-15
Wireless Lan Controller Software CRITICAL 9.8
CVE-2015-6314

Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 before 8.1.131.0 allow remote attackers to change conf…

Mitigation only
Fix from $2,300 2016-01-15
Prime Infrastructure MEDIUM 6.1
CVE-2015-6434

Cisco Prime Infrastructure does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking atta…

Mitigation only
Fix from $1,600 2016-01-08
Unified Communications Manager MEDIUM 6.5
CVE-2015-6433

SQL injection vulnerability in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to execute arbitrary SQL comm…

Mitigation only
Fix from $1,600 2016-01-08
Ios Xr HIGH 7.5
CVE-2015-6432

Cisco IOS XR 4.2.0, 4.3.0, 5.0.0, 5.1.0, 5.2.0, 5.2.2, 5.2.4, 5.3.0, and 5.3.2 does not properly restrict the number of Path Computation Elements (PC…

Mitigation only
Fix from $1,950 2016-01-05