Cisco Security Vulnerabilities (CVEs)

Track 564 security vulnerabilities affecting Cisco products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

102 Critical
295 High
167 Medium
🔔 Get Alerts for Cisco
CVE-2024-20261 5.8

A vulnerability in Cisco Firepower Threat Defense (FTD) software allows attackers to bypass file policies that should block encrypted archive files. U...

May 22, 2024
CVE-2024-20326 7.8

This vulnerability allows authenticated low-privileged local attackers to read and write arbitrary files as root on affected Cisco systems. It affects...

May 16, 2024
CVE-2024-20392 6.1

An HTTP response splitting vulnerability in Cisco Secure Email Gateway's web management API allows unauthenticated attackers to conduct cross-site scr...

May 15, 2024
CVE-2024-20383 4.8

This vulnerability allows authenticated attackers to conduct cross-site scripting (XSS) attacks against users of Cisco Secure Email and Web Manager's ...

May 15, 2024
CVE-2024-20366 7.8

This vulnerability in Cisco Crosswork NSO's Tail-f HCC function pack allows authenticated local attackers to escalate privileges to root by manipulati...

May 15, 2024
CVE-2024-20257 4.8

This cross-site scripting (XSS) vulnerability in Cisco Secure Email Gateway's web management interface allows authenticated attackers to inject malici...

May 15, 2024
CVE-2024-20376 7.5

An unauthenticated remote attacker can send a crafted request to the web-based management interface of vulnerable Cisco IP Phone firmware, causing the...

May 1, 2024
CVE-2024-20313 7.4

An unauthenticated attacker on the same network segment can send specially crafted OSPFv2 packets to vulnerable Cisco IOS XE devices, causing them to ...

Apr 24, 2024
CVE-2024-20348 7.5

This vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) allows unauthenticated remote attackers to read arbitrary files via the Out-of-Ba...

Apr 3, 2024
CVE-2024-20308 8.6

A heap underflow vulnerability in Cisco IOS/IOS XE IKEv1 fragmentation handling allows unauthenticated remote attackers to trigger device reloads via ...

Mar 27, 2024
CVE-2024-20314 8.6

This vulnerability in Cisco IOS XE Software's IPv4 SD-Access fabric edge node allows unauthenticated remote attackers to cause a denial of service by ...

Mar 27, 2024
CVE-2024-20311 8.6

An unauthenticated remote attacker can send specially crafted LISP packets to vulnerable Cisco devices, causing them to reload and creating a denial o...

Mar 27, 2024
CVE-2024-20303 7.4

An unauthenticated attacker on the same wireless network can send continuous mDNS packets to Cisco IOS XE Wireless LAN Controllers, causing high CPU u...

Mar 27, 2024
CVE-2024-20271 8.6

An unauthenticated remote attacker can send specially crafted IPv4 packets to Cisco Access Points, causing them to crash and reload, resulting in deni...

Mar 27, 2024
CVE-2024-20259 8.6

An unauthenticated remote attacker can send a crafted DHCP request packet to cause Cisco IOS XE devices with DHCP snooping and endpoint analytics enab...

Mar 27, 2024
CVE-2024-20327 7.4

An unauthenticated adjacent attacker can crash the ppp_ma process on Cisco ASR 9000 routers running IOS XR with BNG and PPPoE termination, causing den...

Mar 13, 2024
CVE-2024-20320 7.8

This vulnerability allows authenticated local attackers with low privileges on affected Cisco routers to elevate their privileges to root by exploitin...

Mar 13, 2024
CVE-2024-20337 8.2

This CRLF injection vulnerability in Cisco Secure Client's SAML authentication allows unauthenticated attackers to execute arbitrary script code in us...

Mar 6, 2024
CVE-2024-20321 8.6

This vulnerability in Cisco NX-OS Software allows unauthenticated remote attackers to cause denial of service by flooding eBGP traffic, which can drop...

Feb 29, 2024
CVE-2024-20255 8.2

An unauthenticated CSRF vulnerability in Cisco Expressway Series and TelePresence VCS SOAP API allows attackers to trick authenticated users into exec...

Feb 7, 2024
CVE-2024-20252 9.6

Multiple CSRF vulnerabilities in Cisco Expressway Series and TelePresence VCS allow unauthenticated remote attackers to trick authenticated users into...

Feb 7, 2024
CVE-2024-20253 9.9

This critical vulnerability in Cisco Unified Communications and Contact Center Solutions allows unauthenticated remote attackers to execute arbitrary ...

Jan 26, 2024
CVE-2024-20272 7.3

An unauthenticated remote attacker can upload arbitrary files and execute commands on Cisco Unity Connection systems via a vulnerable API in the web m...

Jan 17, 2024
CVE-2023-31488 9.8

This critical vulnerability in Hyland Perceptive Filters allows attackers to execute arbitrary code by sending a specially crafted document that trigg...

Jan 10, 2024
CVE-2023-20219 7.2

This vulnerability allows authenticated remote attackers with valid device credentials (no admin privileges required) to execute arbitrary commands on...

Nov 1, 2023
CVE-2023-20175 8.8

This vulnerability in Cisco ISE allows authenticated users with at least Read-only privileges to execute arbitrary commands on the underlying operatin...

Nov 1, 2023
CVE-2023-20083 8.6

A vulnerability in Cisco Firepower Threat Defense (FTD) Software's ICMPv6 inspection with Snort 2 allows remote attackers to cause 100% CPU usage via ...

Nov 1, 2023
CVE-2023-20048 9.9

This vulnerability allows authenticated remote attackers to execute unauthorized configuration commands on Firepower Threat Defense devices managed by...

Nov 1, 2023
CVE-2023-20244 8.6

An unauthenticated remote attacker can send crafted packets to Cisco Firepower Threat Defense (FTD) Software on Firepower 2100 Series Firewalls, causi...

Nov 1, 2023
CVE-2023-20155 7.5

This vulnerability in Cisco Firepower Management Center allows unauthenticated attackers to cause denial of service by overwhelming a logging API, pot...

Nov 1, 2023
CVE-2023-20086 8.6

An unauthenticated remote attacker can send crafted ICMPv6 messages to Cisco ASA or FTD devices with IPv6 enabled, causing the device to reload and cr...

Nov 1, 2023
CVE-2023-20273 7.2

This vulnerability in Cisco IOS XE Software allows authenticated remote attackers to execute arbitrary commands with root privileges via the web UI. A...

Oct 25, 2023
CVE-2023-20198 10.0

CVE-2023-20198 is a critical vulnerability in Cisco IOS XE Software web UI that allows unauthenticated attackers to gain initial access and create loc...

Oct 16, 2023
CVE-2023-44487 7.5

CVE-2023-44487 is an HTTP/2 protocol vulnerability that allows attackers to cause denial of service by rapidly resetting streams, consuming server res...

Oct 10, 2023
CVE-2023-20259 8.6

An unauthenticated remote attacker can send crafted HTTP requests to a specific API endpoint in Cisco Unified Communications products, causing high CP...

Oct 4, 2023
CVE-2023-20101 9.8

This vulnerability allows unauthenticated remote attackers to log into Cisco Emergency Responder systems using static root credentials that cannot be ...

Oct 4, 2023
CVE-2023-20254 7.2

This vulnerability allows authenticated remote attackers to access other tenants' data and configurations in Cisco Catalyst SD-WAN Manager when multi-...

Sep 27, 2023
CVE-2023-20252 9.8

This critical vulnerability in Cisco Catalyst SD-WAN Manager allows unauthenticated remote attackers to bypass authentication via SAML API flaws, gain...

Sep 27, 2023
CVE-2023-20227 8.6

An unauthenticated remote attacker can send crafted L2TP packets to vulnerable Cisco IOS XE devices, causing them to reload unexpectedly and creating ...

Sep 27, 2023
CVE-2023-20223 8.6

This vulnerability in Cisco DNA Center allows unauthenticated remote attackers to read and modify data in an internal service repository due to insuff...

Sep 27, 2023
CVE-2023-20186 8.0

This vulnerability allows authenticated remote attackers with level 15 privileges to bypass AAA command authorization checks when using SCP, enabling ...

Sep 27, 2023
CVE-2023-20033 8.6

This vulnerability in Cisco Catalyst 3650 and 3850 Series Switches running IOS XE allows unauthenticated remote attackers to cause a denial of service...

Sep 27, 2023
CVE-2023-20243 8.6

An unauthenticated remote attacker can cause Cisco ISE to stop processing RADIUS packets by sending crafted RADIUS accounting requests, resulting in d...

Sep 6, 2023
CVE-2023-20200 7.7

A vulnerability in Cisco FXOS Software and UCS 6300 Series Fabric Interconnects allows authenticated remote attackers to cause denial of service by se...

Aug 23, 2023
CVE-2023-20168 7.1

An unauthenticated local attacker can cause Cisco NX-OS devices to crash and reload by entering a crafted string at the login prompt when TACACS+ or R...

Aug 23, 2023
CVE-2023-20212 7.5

A memory management logic error in ClamAV's AutoIt module allows remote attackers to cause denial of service by submitting crafted AutoIt files. This ...

Aug 18, 2023
CVE-2023-20224 7.8

This vulnerability allows authenticated local attackers on Cisco ThousandEyes Enterprise Agent virtual appliances to escalate privileges to root by ex...

Aug 16, 2023
CVE-2023-20211 8.1

This vulnerability allows authenticated remote attackers to perform SQL injection attacks on Cisco Unified Communications Manager (Unified CM) and its...

Aug 16, 2023
CVE-2023-20197 7.5

This vulnerability in ClamAV's HFS+ filesystem parser allows remote attackers to cause denial of service by submitting crafted HFS+ images. The scanni...

Aug 16, 2023
CVE-2023-20214 9.1

An unauthenticated remote attacker can exploit insufficient request validation in the REST API of Cisco SD-WAN vManage software to gain read or limite...

Aug 3, 2023

Why Monitor Cisco Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 564+ known vulnerabilities affecting Cisco products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Cisco packages in under 60 seconds. No agents required - completely agentless scanning that works across Cisco deployments.

Free vulnerability database: Access detailed information about every Cisco CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Cisco CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Cisco CVEs Free