Brand
Cisco: actively exploited vulnerabilities
99 vulnerabilities in Cisco products (IOS / IOS XE, ASA / Firepower (FTD), RV routers (Small Business)…) are in CISA’s catalog of exploited vulnerabilities, 6 of them added in the last 90 days. Last added: September 16, 2026.
The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).
-
19 vulnerabilities added in the last 12 months
-
99 exploited vulnerabilities in the catalog, in total
-
3 added in the last 30 days
By category
Add just one Cisco category to your radar, or open its page.
- Switches, routers and SD-WAN 57 vulnerabilities
- Firewalls, VPNs and remote access 19 vulnerabilities
- Home and small-office routers, cameras and IoT 10 vulnerabilities
- Identity and access 4 vulnerabilities
- Collaboration, telephony and video conferencing 3 vulnerabilities
- Email 2 vulnerabilities
- Monitoring, ITSM and asset management 2 vulnerabilities
- Virtualization, VDI and cloud 2 vulnerabilities
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
- IOS / IOS XE 39 vulnerabilities · Switches and routers
- ASA / Firepower (FTD) 14 vulnerabilities · Firewalls and VPNs
- RV routers (Small Business) 10 vulnerabilities · Home routers and IoT
- Catalyst SD-WAN 8 vulnerabilities · Switches and routers
- IOS XR 6 vulnerabilities · Switches and routers
- Identity Services Engine (ISE) 3 vulnerabilities · Identity and access
- IOS / IOS XE / IOS XR 3 vulnerabilities · Switches and routers
- Secure Firewall Management Center (FMC) 3 vulnerabilities · Firewalls and VPNs
- AnyConnect Secure Mobility Client 2 vulnerabilities · Firewalls and VPNs
- HyperFlex HX 2 vulnerabilities · Virtualization and VDI
- Secure Email Gateway 2 vulnerabilities · Email
- Unified Communications Manager 2 vulnerabilities · Collaboration and video
Show 5 more products
- IP Phones 1 vulnerability · Collaboration and video
- NX-OS 1 vulnerability · Switches and routers
- Prime Data Center Network Manager (DCNM) 1 vulnerability · Monitoring and ITSM
- Secure Access Control System (ACS) 1 vulnerability · Identity and access
- Smart Licensing Utility 1 vulnerability · Monitoring and ITSM
Name used by CISA: Cisco. Product families: indicative classification by this site.
Pace of additions
| Period | Vulnerabilities added |
|---|---|
| Sep 4, 2025 to Oct 3, 2025 | 3 |
| Oct 4, 2025 to Nov 2, 2025 | 0 |
| Nov 3, 2025 to Dec 2, 2025 | 0 |
| Dec 3, 2025 to Jan 1, 2026 | 1 |
| Jan 2, 2026 to Jan 31, 2026 | 1 |
| Feb 1, 2026 to Mar 2, 2026 | 2 |
| Mar 3, 2026 to Apr 1, 2026 | 1 |
| Apr 2, 2026 to May 1, 2026 | 3 |
| May 2, 2026 to May 31, 2026 | 1 |
| Jun 1, 2026 to Jun 30, 2026 | 3 |
| Jul 1, 2026 to Jul 30, 2026 | 2 |
| Jul 31, 2026 to Aug 29, 2026 | 1 |
| Aug 30, 2026 to Sep 28, 2026 (in progress) | 3 |
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Cisco list.
Rank 1Cisco Identity Services Engine (ISE)
CVE-2026-76460Recently addedHunt for compromise (CISA)
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 16, 2026
- CISA deadline
- 3 days
- CVSS severity
- 10.0 (critical)
Rank 2Cisco Secure Email Gateway
CVE-2026-76461Recently addedHunt for compromise (CISA)
Cisco Secure Email Gateway SQL Injection Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 14, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 3Cisco Secure Firewall Management Center (FMC)
CVE-2026-20079Recently addedHunt for compromise (CISA)
Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 9, 2026
- CISA deadline
- 3 days
- CVSS severity
- 10.0 (critical)
Rank 4Cisco Catalyst SD-WAN
CVE-2026-20182Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- May 14, 2026
- CISA deadline
- 3 days
- CVSS severity
- 10.0 (critical)
Rank 5Cisco Secure Firewall Management Center (FMC)
CVE-2026-20131Ransomware
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Mar 19, 2026
- CISA deadline
- 3 days
- CVSS severity
- 10.0 (critical)
Rank 6Cisco Catalyst SD-WAN
CVE-2026-20127Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Feb 25, 2026
- CISA deadline
- 2 days
- CVSS severity
- 10.0 (critical)
Rank 7Cisco Secure Email Gateway
CVE-2025-20393Cisco Multiple Products Improper Input Validation Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Dec 17, 2025
- CISA deadline
- 7 days
- CVSS severity
- 10.0 (critical)
Rank 8Cisco Unified Communications Manager
CVE-2026-20045Cisco Unified Communications Products Code Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jan 21, 2026
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 9Cisco ASA / Firepower (FTD)
CVE-2026-20349Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Aug 11, 2026
- CISA deadline
- 3 days
- CVSS severity
- 8.6 (high)
Rank 10Cisco Unified Communications Manager
CVE-2026-20230Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jun 25, 2026
- CISA deadline
- 3 days
- CVSS severity
- 8.6 (high)
Show 89 more vulnerabilities
Rank 11Cisco IOS / IOS XE
CVE-2008-4128Hunt for compromise (CISA)CVE from 2008, added in 2026
Cisco IOS Cross-Site Request Forgery Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jul 13, 2026
- CISA deadline
- 3 days
- CVSS severity
- 8.1 (high)
Rank 12Cisco Catalyst SD-WAN
CVE-2026-20245Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jun 9, 2026
- CISA deadline
- 14 days
- CVSS severity
- 7.8 (high)
Rank 13Cisco Catalyst SD-WAN
CVE-2022-20775CVE from 2022, added in 2026
Cisco SD-WAN Path Traversal Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Feb 25, 2026
- CISA deadline
- 2 days
- CVSS severity
- 7.8 (high)
Rank 14Cisco IOS / IOS XE
CVE-2025-20352Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Sep 29, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.7 (high)
Rank 15Cisco Catalyst SD-WAN
CVE-2026-20128Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Apr 20, 2026
- CISA deadline
- 3 days
- CVSS severity
- 7.5 (high)
Rank 16Cisco Catalyst SD-WAN
CVE-2026-20133Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Apr 20, 2026
- CISA deadline
- 3 days
- CVSS severity
- 7.5 (high)
Rank 17Cisco Catalyst SD-WAN
CVE-2026-20262Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jun 15, 2026
- CISA deadline
- 14 days
- CVSS severity
- 6.5 (medium)
Rank 18Cisco Catalyst SD-WAN
CVE-2026-20122Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Apr 20, 2026
- CISA deadline
- 3 days
- CVSS severity
- 5.4 (medium)
Rank 19Cisco Secure Firewall Management Center (FMC)
CVE-2026-20316Ransomware
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jul 29, 2026
- CISA deadline
- 3 days
- CVSS severity
- 5.3 (medium)
Rank 20Cisco Identity Services Engine (ISE)
CVE-2025-20281Cisco Identity Services Engine Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 28, 2025
- CISA deadline
- 21 days
- CVSS severity
- 10.0 (critical)
Rank 21Cisco Identity Services Engine (ISE)
CVE-2025-20337Cisco Identity Services Engine Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 28, 2025
- CISA deadline
- 21 days
- CVSS severity
- 10.0 (critical)
Rank 22Cisco IOS / IOS XE
CVE-2023-20198Cisco IOS XE Web UI Privilege Escalation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 16, 2023
- CISA deadline
- 4 days
- CVSS severity
- 10.0 (critical)
Rank 23Cisco ASA / Firepower (FTD)
CVE-2025-20333Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 25, 2025
- CISA deadline
- 1 day
- CVSS severity
- 9.9 (critical)
Rank 24Cisco Smart Licensing Utility
CVE-2024-20439Cisco Smart Licensing Utility Static Credential Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 31, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 25Cisco IOS / IOS XE
CVE-2017-3881CVE from 2017, added in 2022
Cisco IOS and IOS XE Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 26Cisco RV routers (Small Business)
CVE-2018-0125CVE from 2018, added in 2022
Cisco VPN Routers Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 27Cisco Secure Access Control System (ACS)
CVE-2018-0147CVE from 2018, added in 2022
Cisco Secure Access Control System Java Deserialization Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 28Cisco IOS / IOS XE
CVE-2017-12240CVE from 2017, added in 2022
Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 29Cisco IOS / IOS XE
CVE-2018-0151CVE from 2018, added in 2022
Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 30Cisco RV routers (Small Business)
CVE-2022-20699Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 31Cisco RV routers (Small Business)
CVE-2022-20700Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 32Cisco IOS / IOS XE
CVE-2018-0171CVE from 2018, added in 2021
Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 33Cisco IP Phones
CVE-2020-3161Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 34Cisco HyperFlex HX
CVE-2021-1497Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 35Cisco HyperFlex HX
CVE-2021-1498Cisco HyperFlex HX Data Platform Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 36Cisco ASA / Firepower (FTD)
CVE-2023-20269Ransomware
Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 13, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.1 (critical)
Rank 37Cisco IOS / IOS XE
CVE-2017-6742CVE from 2017, added in 2023
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 19, 2023
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 38Cisco RV routers (Small Business)
CVE-2019-15271CVE from 2019, added in 2022
Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 8, 2022
- CISA deadline
- 14 days
- CVSS severity
- 8.8 (high)
Rank 39Cisco ASA / Firepower (FTD)
CVE-2016-6366CVE from 2016, added in 2022
Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 24, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 40Cisco IOS / IOS XE
CVE-2017-6736CVE from 2017, added in 2022
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 41Cisco IOS / IOS XE
CVE-2017-6737CVE from 2017, added in 2022
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 42Cisco IOS / IOS XE
CVE-2017-6738CVE from 2017, added in 2022
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 43Cisco IOS / IOS XE
CVE-2017-6739CVE from 2017, added in 2022
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 44Cisco IOS / IOS XE
CVE-2017-6740CVE from 2017, added in 2022
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 45Cisco IOS / IOS XE
CVE-2017-6743CVE from 2017, added in 2022
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 46Cisco IOS / IOS XE
CVE-2017-6744CVE from 2017, added in 2022
Cisco IOS Software SNMP Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 47Cisco IOS / IOS XE / IOS XR
CVE-2018-0167CVE from 2018, added in 2022
Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 14 days
- CVSS severity
- 8.8 (high)
Rank 48Cisco IOS XR
CVE-2020-3118Cisco IOS XR Software Discovery Protocol Format String Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 8.8 (high)
Rank 49Cisco ASA / Firepower (FTD)
CVE-2025-20362Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 25, 2025
- CISA deadline
- 1 day
- CVSS severity
- 8.6 (high)
Rank 50Cisco ASA / Firepower (FTD)
CVE-2024-20353Cisco ASA and FTD Denial of Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 24, 2024
- CISA deadline
- 7 days
- CVSS severity
- 8.6 (high)
Rank 51Cisco IOS / IOS XE
CVE-2018-0155CVE from 2018, added in 2022
Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 14 days
- CVSS severity
- 8.6 (high)
Rank 52Cisco IOS / IOS XE
CVE-2018-0158CVE from 2018, added in 2022
Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 14 days
- CVSS severity
- 8.6 (high)
Rank 53Cisco IOS / IOS XE
CVE-2018-0172CVE from 2018, added in 2022
Cisco IOS and IOS XE Software Improper Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 14 days
- CVSS severity
- 8.6 (high)
Rank 54Cisco IOS / IOS XE
CVE-2018-0173CVE from 2018, added in 2022
Cisco IOS and IOS XE Software Improper Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 14 days
- CVSS severity
- 8.6 (high)
Rank 55Cisco IOS / IOS XE
CVE-2018-0174CVE from 2018, added in 2022
Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 14 days
- CVSS severity
- 8.6 (high)
Rank 56Cisco IOS XR
CVE-2020-3566Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 8.6 (high)
Rank 57Cisco IOS XR
CVE-2020-3569Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 8.6 (high)
Rank 58Cisco IOS / IOS XE / IOS XR
CVE-2018-0175CVE from 2018, added in 2022
Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 14 days
- CVSS severity
- 8.0 (high)
Rank 59Cisco RV routers (Small Business)
CVE-2022-20703Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 14 days
- CVSS severity
- 8.0 (high)
Rank 60Cisco RV routers (Small Business)
CVE-2022-20708Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 14 days
- CVSS severity
- 8.0 (high)
Rank 61Cisco AnyConnect Secure Mobility Client
CVE-2020-3433RansomwareCVE from 2020, added in 2022
Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 24, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Rank 62Cisco ASA / Firepower (FTD)
CVE-2016-6367CVE from 2016, added in 2022
Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 24, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Rank 63Cisco RV routers (Small Business)
CVE-2022-20701Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 14 days
- CVSS severity
- 7.8 (high)
Rank 64Cisco ASA / Firepower (FTD)
CVE-2020-3259RansomwareCVE from 2020, added in 2024
Cisco ASA and FTD Information Disclosure Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 15, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 65Cisco IOS / IOS XE / IOS XR
CVE-2016-6415CVE from 2016, added in 2023
Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 19, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 66Cisco IOS XR
CVE-2010-3035CVE from 2010, added in 2022
Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 67Cisco Prime Data Center Network Manager (DCNM)
CVE-2015-0666CVE from 2015, added in 2022
Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 68Cisco IOS / IOS XE
CVE-2017-12231CVE from 2017, added in 2022
Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 69Cisco IOS / IOS XE
CVE-2017-12233CVE from 2017, added in 2022
Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 70Cisco IOS / IOS XE
CVE-2017-12234CVE from 2017, added in 2022
Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 71Cisco IOS / IOS XE
CVE-2017-12235CVE from 2017, added in 2022
Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 72Cisco IOS / IOS XE
CVE-2017-12237CVE from 2017, added in 2022
Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 73Cisco IOS / IOS XE
CVE-2017-6627CVE from 2017, added in 2022
Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 74Cisco IOS / IOS XE
CVE-2018-0154CVE from 2018, added in 2022
Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 14 days
- CVSS severity
- 7.5 (high)
Rank 75Cisco IOS / IOS XE
CVE-2018-0156CVE from 2018, added in 2022
Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 14 days
- CVSS severity
- 7.5 (high)
Rank 76Cisco IOS / IOS XE
CVE-2018-0159CVE from 2018, added in 2022
Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 14 days
- CVSS severity
- 7.5 (high)
Rank 77Cisco ASA / Firepower (FTD)
CVE-2018-0296CVE from 2018, added in 2021
Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.5 (high)
Rank 78Cisco RV routers (Small Business)
CVE-2019-1653CVE from 2019, added in 2021
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.5 (high)
Rank 79Cisco ASA / Firepower (FTD)
CVE-2020-3452Cisco ASA and FTD Read-Only Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.5 (high)
Rank 80Cisco RV routers (Small Business)
CVE-2023-20118CVE from 2023, added in 2025
Cisco Small Business RV Series Routers Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Rank 81Cisco IOS / IOS XE
CVE-2023-20273Cisco IOS XE Web UI Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 23, 2023
- CISA deadline
- 4 days
- CVSS severity
- 7.2 (high)
Rank 82Cisco RV routers (Small Business)
CVE-2019-1652CVE from 2019, added in 2022
Cisco Small Business Routers Improper Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 14 days
- CVSS severity
- 7.2 (high)
Rank 83Cisco NX-OS
CVE-2024-20399Cisco NX-OS Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 2, 2024
- CISA deadline
- 21 days
- CVSS severity
- 6.7 (medium)
Rank 84Cisco IOS / IOS XE
CVE-2023-20109Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 10, 2023
- CISA deadline
- 21 days
- CVSS severity
- 6.6 (medium)
Rank 85Cisco AnyConnect Secure Mobility Client
CVE-2020-3153RansomwareCVE from 2020, added in 2022
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 24, 2022
- CISA deadline
- 21 days
- CVSS severity
- 6.5 (medium)
Rank 86Cisco IOS XR
CVE-2022-20821Cisco IOS XR Open Port Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 23, 2022
- CISA deadline
- 21 days
- CVSS severity
- 6.5 (medium)
Rank 87Cisco IOS / IOS XE
CVE-2017-12232CVE from 2017, added in 2022
Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 6.5 (medium)
Rank 88Cisco IOS / IOS XE
CVE-2017-12238CVE from 2017, added in 2022
Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 6.5 (medium)
Rank 89Cisco IOS / IOS XE
CVE-2017-6663CVE from 2017, added in 2022
Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 6.5 (medium)
Rank 90Cisco IOS / IOS XE
CVE-2018-0161CVE from 2018, added in 2022
Cisco IOS Software Resource Management Errors Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 14 days
- CVSS severity
- 6.3 (medium)
Rank 91Cisco ASA / Firepower (FTD)
CVE-2014-2120CVE from 2014, added in 2024
Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 12, 2024
- CISA deadline
- 21 days
- CVSS severity
- 6.1 (medium)
Rank 92Cisco ASA / Firepower (FTD)
CVE-2020-3580Ransomware
Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 6.1 (medium)
Rank 93Cisco ASA / Firepower (FTD)
CVE-2024-20359Cisco ASA and FTD Privilege Escalation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 24, 2024
- CISA deadline
- 7 days
- CVSS severity
- 6.0 (medium)
Rank 94Cisco IOS / IOS XE
CVE-2004-1464CVE from 2004, added in 2023
Cisco IOS Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 19, 2023
- CISA deadline
- 21 days
- CVSS severity
- 5.9 (medium)
Rank 95Cisco IOS XR
CVE-2009-2055CVE from 2009, added in 2022
Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 5.9 (medium)
Rank 96Cisco IOS / IOS XE
CVE-2017-12319CVE from 2017, added in 2022
Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 5.9 (medium)
Rank 97Cisco IOS / IOS XE
CVE-2018-0179CVE from 2018, added in 2022
Cisco IOS Software Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 14 days
- CVSS severity
- 5.9 (medium)
Rank 98Cisco IOS / IOS XE
CVE-2018-0180CVE from 2018, added in 2022
Cisco IOS Software Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 14 days
- CVSS severity
- 5.9 (medium)
Rank 99Cisco ASA / Firepower (FTD)
CVE-2024-20481Cisco ASA and FTD Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 24, 2024
- CISA deadline
- 21 days
- CVSS severity
- 5.8 (medium)
Follow and verify
Get new Cisco vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.