Cisco Security Vulnerabilities (CVEs)
Track 564 security vulnerabilities affecting Cisco products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.
This vulnerability allows authenticated administrators on affected Cisco Small Business routers to execute arbitrary code with root privileges by send...
Oct 2, 2024This vulnerability allows authenticated administrators on Cisco Small Business routers to send crafted HTTP requests that cause the device to unexpect...
Oct 2, 2024This vulnerability allows authenticated administrators on Cisco Small Business routers to send crafted HTTP requests that cause the device to unexpect...
Oct 2, 2024This vulnerability allows authenticated administrators on affected Cisco Small Business routers to execute arbitrary code with root privileges by send...
Oct 2, 2024This vulnerability allows authenticated low-privileged attackers to upload or delete files on Cisco NDFC devices via a specific REST API endpoint with...
Oct 2, 2024This vulnerability in Cisco Nexus Dashboard Insights allows attackers who obtain tech support files to view remote controller admin credentials in cle...
Oct 2, 2024An authenticated attacker with Read-Only Administrator privileges in Cisco Identity Services Engine (ISE) can exploit improper data protection mechani...
Oct 2, 2024This vulnerability allows authenticated remote attackers with network-admin privileges to execute arbitrary commands on Cisco Nexus Dashboard Fabric C...
Oct 2, 2024This vulnerability allows authenticated remote attackers with low privileges to execute arbitrary code as root on Cisco Nexus Dashboard Fabric Control...
Oct 2, 2024This vulnerability in Cisco Small Business VPN routers allows authenticated remote attackers to escalate privileges from guest to admin by exploiting ...
Oct 2, 2024An authenticated low-privileged attacker can execute arbitrary CLI commands with network-admin privileges on Cisco NDFC-managed devices via command in...
Oct 2, 2024This vulnerability allows authenticated low-privileged attackers to access sensitive configuration information through a specific REST API endpoint in...
Oct 2, 2024This vulnerability allows authenticated administrators to execute arbitrary commands through the Redfish API on affected Cisco UCS servers, potentiall...
Oct 2, 2024An unauthenticated remote attacker can bypass security policies or cause denial of service on Cisco IOS XE devices with UTD Snort IPS Engine by sendin...
Sep 25, 2024This vulnerability allows unauthenticated remote attackers to bypass configured IPv4 access control lists on affected Cisco switches when Resilient Et...
Sep 25, 2024An unauthenticated remote attacker can cause Cisco routers to crash and reload by sending specially crafted fragmented IPv4 packets, resulting in deni...
Sep 25, 2024An unauthenticated remote attacker can send specially crafted IPv4 DHCP packets to Cisco IOS XE SD-Access fabric edge nodes, causing high CPU utilizat...
Sep 25, 2024An unauthenticated remote attacker can cause Cisco IOS XE devices to crash and reload by sending crafted HTTP requests to specific URLs when the Telem...
Sep 25, 2024This vulnerability allows unauthenticated remote attackers to cause a denial of service (DoS) by sending crafted traffic through SD-WAN IPsec tunnels ...
Sep 25, 2024This vulnerability allows an unauthenticated remote attacker to impersonate a Cisco Catalyst Center appliance due to a static SSH host key. Attackers ...
Sep 25, 2024An unauthenticated remote attacker can send specially crafted RSVP packets to vulnerable Cisco devices, causing a buffer overflow that forces the devi...
Sep 25, 2024This vulnerability allows authenticated local attackers to execute arbitrary code with SYSTEM privileges on Windows systems running vulnerable Cisco M...
Sep 12, 2024This vulnerability allows authenticated attackers with Administrator privileges on Cisco Routed PON Manager or direct MongoDB access to execute arbitr...
Sep 11, 2024This vulnerability in Cisco IOS XR Software allows authenticated local attackers with valid credentials to read any file on the underlying Linux file ...
Sep 11, 2024This vulnerability allows authenticated remote attackers to bypass authorization checks in the JSON-RPC API of affected Cisco products, enabling unaut...
Sep 11, 2024This vulnerability in Cisco IOS XR Software allows authenticated local attackers with low-privileged accounts to gain root-level file system access th...
Sep 11, 2024This vulnerability in Cisco IOS XR Software allows unauthenticated remote attackers to send crafted Mtrace2 packets that exhaust UDP packet memory, ca...
Sep 11, 2024This vulnerability in Cisco Duo Epic for Hyperdrive allows authenticated local attackers to view sensitive information stored unencrypted in a registr...
Sep 4, 2024CVE-2024-20439 allows unauthenticated remote attackers to log into Cisco Smart Licensing Utility systems using undocumented static administrative cred...
Sep 4, 2024This vulnerability allows authenticated administrators on Cisco Identity Services Engine (ISE) to execute arbitrary commands on the underlying operati...
Sep 4, 2024This CVE describes a Python sandbox escape vulnerability in Cisco NX-OS Software that allows authenticated local attackers with Python execution privi...
Aug 28, 2024This vulnerability allows authenticated local attackers with Python execution privileges on Cisco NX-OS devices to escape the Python sandbox and execu...
Aug 28, 2024Multiple SQL injection vulnerabilities in Cisco ISE's REST API allow authenticated attackers to execute arbitrary SQL queries. This could lead to unau...
Aug 21, 2024This CSRF vulnerability in Cisco ISE's web management interface allows unauthenticated remote attackers to trick authenticated users into executing ma...
Aug 21, 2024An unauthenticated cross-site scripting (XSS) vulnerability in Cisco Unified Communications Manager web interface allows attackers to execute maliciou...
Aug 21, 2024An unauthenticated remote attacker can send a specially crafted SIP message to Cisco Unified Communications Manager systems, causing them to reload an...
Aug 21, 2024This vulnerability allows an authenticated attacker with low privileges to conduct cross-site scripting (XSS) attacks against users of Cisco ISE's web...
Aug 7, 2024This critical vulnerability allows unauthenticated remote attackers to execute arbitrary commands with root privileges on Cisco SPA300/500 series IP p...
Aug 7, 2024This critical vulnerability allows unauthenticated remote attackers to execute arbitrary commands with root privileges on affected Cisco IP phones. At...
Aug 7, 2024This critical vulnerability in Cisco Smart Software Manager On-Prem allows unauthenticated remote attackers to change any user's password, including a...
Jul 17, 2024This vulnerability in Cisco AsyncOS for Secure Web Appliance allows authenticated local attackers with guest credentials to execute arbitrary commands...
Jul 17, 2024A vulnerability in Cisco Webex App's protocol handlers could allow remote attackers to capture sensitive information like credentials by tricking user...
Jul 17, 2024This critical vulnerability in Cisco Secure Email Gateway allows unauthenticated remote attackers to overwrite arbitrary files on the underlying opera...
Jul 17, 2024This vulnerability allows attackers to intercept and manipulate TLS communications between Cisco iNode Manager and intelligent nodes due to hard-coded...
Jul 17, 2024This vulnerability allows authenticated local attackers with root-system privileges on Cisco IOS XR devices to bypass Secure Boot functionality and lo...
Jul 10, 2024This vulnerability allows authenticated users with Administrator credentials to execute arbitrary commands as root on Cisco NX-OS devices through comm...
Jul 1, 2024This vulnerability in Cisco Finesse's web management interface allows an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS...
Jun 5, 2024This SQL injection vulnerability in Cisco Firepower Management Center (FMC) allows authenticated attackers with at least Read Only credentials to exec...
May 22, 2024This vulnerability allows authenticated remote attackers to bypass SAML authorization controls in Cisco ASA/FTD VPN services. Attackers can intercept ...
May 22, 2024This vulnerability allows unauthenticated remote attackers to bypass Cisco Snort IPS rules by sending specially crafted HTTP packets. Affected systems...
May 22, 2024Why Monitor Cisco Security Vulnerabilities?
Real-time CVE tracking: Our automated system monitors 564+ known vulnerabilities affecting Cisco products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.
Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Cisco packages in under 60 seconds. No agents required - completely agentless scanning that works across Cisco deployments.
Free vulnerability database: Access detailed information about every Cisco CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.
🚀 Get Started in 60 Seconds
- Register free account & add your servers
- Run one-time scan or schedule automatic monitoring (every 1-24 hours)
- Receive instant alerts when new Cisco CVEs affect your systems
- Access dashboard with severity breakdown & fix instructions