Skip to content
English

Products › Network and edge

Network and edge

Switches, routers and SD-WAN

The core of the corporate network: switches, routers, SD-WAN and Wi-Fi controllers.

For example: Cisco IOS XE, Juniper Junos, MikroTik RouterOS, Arista EOS.

Category RSS feed

Pace of additions

Number of “Switches and routers” vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on September 28, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 4, 2025 to Oct 3, 20251
Oct 4, 2025 to Nov 2, 20250
Nov 3, 2025 to Dec 2, 20250
Dec 3, 2025 to Jan 1, 20261
Jan 2, 2026 to Jan 31, 20261
Feb 1, 2026 to Mar 2, 20262
Mar 3, 2026 to Apr 1, 20260
Apr 2, 2026 to May 1, 20263
May 2, 2026 to May 31, 20261
Jun 1, 2026 to Jun 30, 20266
Jul 1, 2026 to Jul 30, 20262
Jul 31, 2026 to Aug 29, 20260
Aug 30, 2026 to Sep 28, 2026 (in progress)5

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1MikroTik RouterOS

    CVE-2026-67279

    Recently added

    Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 25, 2026
    CISA deadline
    3 days
    CVSS severity
    6.5 (medium)
  2. Rank 2Arista SD-WAN (VeloCloud)

    CVE-2026-93952

    Recently addedHunt for compromise (CISA)

    Arista VeloCloud Orchestrator Improper Input Validation Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 22, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  3. Rank 3Zyxel Switches (GS, XGS)

    CVE-2026-7273

    Recently addedHunt for compromise (CISA)

    Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 21, 2026
    CISA deadline
    3 days
    CVSS severity
    8.8 (high)
  4. Rank 4MikroTik RouterOS

    CVE-2026-86060

    Recently addedHunt for compromise (CISA)

    MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 10, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  5. Rank 5MikroTik RouterOS

    CVE-2026-67277

    Recently added

    MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 10, 2026
    CISA deadline
    3 days
    CVSS severity
    8.2 (high)
  6. Rank 6Arista SD-WAN (VeloCloud)

    CVE-2026-16812

    Hunt for compromise (CISA)

    Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 27, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  7. Rank 7Ubiquiti UniFi OS / UniFi Network

    CVE-2026-34908

    Ubiquiti UniFi OS Improper Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 23, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  8. Rank 8Ubiquiti UniFi OS / UniFi Network

    CVE-2026-34909

    Ubiquiti UniFi OS Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 23, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  9. Rank 9Ubiquiti UniFi OS / UniFi Network

    CVE-2026-34910

    Ubiquiti UniFi OS Improper Input Validation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 23, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  10. Rank 10Cisco Catalyst SD-WAN

    CVE-2026-20182

    Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 14, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
Show 79 more vulnerabilities
  1. Rank 11Cisco Catalyst SD-WAN

    CVE-2026-20127

    Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 25, 2026
    CISA deadline
    2 days
    CVSS severity
    10.0 (critical)
  2. Rank 12Sierra Wireless AirLink ALEOS

    CVE-2018-4063

    CVE from 2018, added in 2025

    Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 12, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  3. Rank 13Cisco IOS / IOS XE

    CVE-2008-4128

    Hunt for compromise (CISA)CVE from 2008, added in 2026

    Cisco IOS Cross-Site Request Forgery Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 13, 2026
    CISA deadline
    3 days
    CVSS severity
    8.1 (high)
  4. Rank 14Cisco Catalyst SD-WAN

    CVE-2026-20245

    Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 9, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  5. Rank 15Cisco Catalyst SD-WAN

    CVE-2022-20775

    CVE from 2022, added in 2026

    Cisco SD-WAN Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 25, 2026
    CISA deadline
    2 days
    CVSS severity
    7.8 (high)
  6. Rank 16Cisco IOS / IOS XE

    CVE-2025-20352

    Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Sep 29, 2025
    CISA deadline
    21 days
    CVSS severity
    7.7 (high)
  7. Rank 17Cisco Catalyst SD-WAN

    CVE-2026-20128

    Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 20, 2026
    CISA deadline
    3 days
    CVSS severity
    7.5 (high)
  8. Rank 18Cisco Catalyst SD-WAN

    CVE-2026-20133

    Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 20, 2026
    CISA deadline
    3 days
    CVSS severity
    7.5 (high)
  9. Rank 19Versa Networks Concerto

    CVE-2025-34026

    Versa Concerto Improper Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 22, 2026
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  10. Rank 20Cisco Catalyst SD-WAN

    CVE-2026-20262

    Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 15, 2026
    CISA deadline
    14 days
    CVSS severity
    6.5 (medium)
  11. Rank 21Arista EOS

    CVE-2026-7473

    Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 9, 2026
    CISA deadline
    14 days
    CVSS severity
    5.8 (medium)
  12. Rank 22Cisco Catalyst SD-WAN

    CVE-2026-20122

    Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 20, 2026
    CISA deadline
    3 days
    CVSS severity
    5.4 (medium)
  13. Rank 23Cisco IOS / IOS XE

    CVE-2023-20198

    Cisco IOS XE Web UI Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 16, 2023
    CISA deadline
    4 days
    CVSS severity
    10.0 (critical)
  14. Rank 24MRLG (Multi-Router Looking Glass) Multi-Router Looking Glass (MRLG)

    CVE-2014-3931

    CVE from 2014, added in 2025

    Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 7, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  15. Rank 25Aviatrix Controller

    CVE-2024-50603

    Aviatrix Controllers OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 16, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  16. Rank 26Juniper Junos OS

    CVE-2023-36845

    Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 13, 2023
    CISA deadline
    4 days
    CVSS severity
    9.8 (critical)
  17. Rank 27Ruckus Wireless Wi-Fi access points and controllers

    CVE-2023-25717

    Multiple Ruckus Wireless Products CSRF and RCE Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 12, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  18. Rank 28MikroTik RouterOS

    CVE-2018-7445

    CVE from 2018, added in 2022

    MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  19. Rank 29Ubiquiti airOS (airMAX)

    CVE-2010-5330

    CVE from 2010, added in 2022

    Ubiquiti AirOS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 15, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  20. Rank 30Cisco IOS / IOS XE

    CVE-2017-3881

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  21. Rank 31Citrix SD-WAN

    CVE-2017-6316

    CVE from 2017, added in 2022

    Citrix Multiple Products Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  22. Rank 32Citrix SD-WAN

    CVE-2019-12989

    CVE from 2019, added in 2022

    Citrix SD-WAN and NetScaler SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  23. Rank 33Juniper Junos OS

    CVE-2020-1631

    CVE from 2020, added in 2022

    Juniper Junos OS Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  24. Rank 34Cisco IOS / IOS XE

    CVE-2017-12240

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  25. Rank 35Cisco IOS / IOS XE

    CVE-2018-0151

    CVE from 2018, added in 2022

    Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  26. Rank 36Aviatrix Controller

    CVE-2021-40870

    Aviatrix Controller Unrestricted Upload of File

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  27. Rank 37Cisco IOS / IOS XE

    CVE-2018-0171

    CVE from 2018, added in 2021

    Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  28. Rank 38NETGEAR Switches (GS, JGS, MS)

    CVE-2020-26919

    Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  29. Rank 39MikroTik RouterOS

    CVE-2018-14847

    CVE from 2018, added in 2021

    MikroTik Router OS Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 1, 2021
    CISA deadline
    182 days
    CVSS severity
    9.1 (critical)
  30. Rank 40Cisco IOS / IOS XE

    CVE-2017-6742

    CVE from 2017, added in 2023

    Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 19, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  31. Rank 41Citrix SD-WAN

    CVE-2019-12991

    CVE from 2019, added in 2022

    Citrix SD-WAN and NetScaler Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  32. Rank 42Cisco IOS / IOS XE

    CVE-2017-6736

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  33. Rank 43Cisco IOS / IOS XE

    CVE-2017-6737

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  34. Rank 44Cisco IOS / IOS XE

    CVE-2017-6738

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  35. Rank 45Cisco IOS / IOS XE

    CVE-2017-6739

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  36. Rank 46Cisco IOS / IOS XE

    CVE-2017-6740

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  37. Rank 47Cisco IOS / IOS XE

    CVE-2017-6743

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  38. Rank 48Cisco IOS / IOS XE

    CVE-2017-6744

    CVE from 2017, added in 2022

    Cisco IOS Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  39. Rank 49Cisco IOS / IOS XE / IOS XR

    CVE-2018-0167

    CVE from 2018, added in 2022

    Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  40. Rank 50Cisco IOS XR

    CVE-2020-3118

    Cisco IOS XR Software Discovery Protocol Format String Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  41. Rank 51Cisco IOS / IOS XE

    CVE-2018-0155

    CVE from 2018, added in 2022

    Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.6 (high)
  42. Rank 52Cisco IOS / IOS XE

    CVE-2018-0158

    CVE from 2018, added in 2022

    Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.6 (high)
  43. Rank 53Cisco IOS / IOS XE

    CVE-2018-0172

    CVE from 2018, added in 2022

    Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.6 (high)
  44. Rank 54Cisco IOS / IOS XE

    CVE-2018-0173

    CVE from 2018, added in 2022

    Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.6 (high)
  45. Rank 55Cisco IOS / IOS XE

    CVE-2018-0174

    CVE from 2018, added in 2022

    Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.6 (high)
  46. Rank 56Cisco IOS XR

    CVE-2020-3566

    Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.6 (high)
  47. Rank 57Cisco IOS XR

    CVE-2020-3569

    Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.6 (high)
  48. Rank 58VMware (Broadcom) SD-WAN (VeloCloud)

    CVE-2018-6961

    CVE from 2018, added in 2022

    VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  49. Rank 59Cisco IOS / IOS XE / IOS XR

    CVE-2018-0175

    CVE from 2018, added in 2022

    Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.0 (high)
  50. Rank 60Cisco IOS / IOS XE / IOS XR

    CVE-2016-6415

    CVE from 2016, added in 2023

    Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 19, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  51. Rank 61Cisco IOS XR

    CVE-2010-3035

    CVE from 2010, added in 2022

    Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  52. Rank 62Cisco IOS / IOS XE

    CVE-2017-12231

    CVE from 2017, added in 2022

    Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  53. Rank 63Cisco IOS / IOS XE

    CVE-2017-12233

    CVE from 2017, added in 2022

    Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  54. Rank 64Cisco IOS / IOS XE

    CVE-2017-12234

    CVE from 2017, added in 2022

    Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  55. Rank 65Cisco IOS / IOS XE

    CVE-2017-12235

    CVE from 2017, added in 2022

    Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  56. Rank 66Cisco IOS / IOS XE

    CVE-2017-12237

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  57. Rank 67Cisco IOS / IOS XE

    CVE-2017-6627

    CVE from 2017, added in 2022

    Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  58. Rank 68Cisco IOS / IOS XE

    CVE-2018-0154

    CVE from 2018, added in 2022

    Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  59. Rank 69Cisco IOS / IOS XE

    CVE-2018-0156

    CVE from 2018, added in 2022

    Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  60. Rank 70Cisco IOS / IOS XE

    CVE-2018-0159

    CVE from 2018, added in 2022

    Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  61. Rank 71Versa Networks Director

    CVE-2024-39717

    Versa Director Dangerous File Type Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 23, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  62. Rank 72Cisco IOS / IOS XE

    CVE-2023-20273

    Cisco IOS XE Web UI Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 23, 2023
    CISA deadline
    4 days
    CVSS severity
    7.2 (high)
  63. Rank 73Cisco NX-OS

    CVE-2024-20399

    Cisco NX-OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 2, 2024
    CISA deadline
    21 days
    CVSS severity
    6.7 (medium)
  64. Rank 74Cisco IOS / IOS XE

    CVE-2023-20109

    Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 10, 2023
    CISA deadline
    21 days
    CVSS severity
    6.6 (medium)
  65. Rank 75Cisco IOS XR

    CVE-2022-20821

    Cisco IOS XR Open Port Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  66. Rank 76Cisco IOS / IOS XE

    CVE-2017-12232

    CVE from 2017, added in 2022

    Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  67. Rank 77Cisco IOS / IOS XE

    CVE-2017-12238

    CVE from 2017, added in 2022

    Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  68. Rank 78Cisco IOS / IOS XE

    CVE-2017-6663

    CVE from 2017, added in 2022

    Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  69. Rank 79Cisco IOS / IOS XE

    CVE-2018-0161

    CVE from 2018, added in 2022

    Cisco IOS Software Resource Management Errors Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    6.3 (medium)
  70. Rank 80Cisco IOS / IOS XE

    CVE-2004-1464

    CVE from 2004, added in 2023

    Cisco IOS Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 19, 2023
    CISA deadline
    21 days
    CVSS severity
    5.9 (medium)
  71. Rank 81Cisco IOS XR

    CVE-2009-2055

    CVE from 2009, added in 2022

    Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    5.9 (medium)
  72. Rank 82Cisco IOS / IOS XE

    CVE-2017-12319

    CVE from 2017, added in 2022

    Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    5.9 (medium)
  73. Rank 83Cisco IOS / IOS XE

    CVE-2018-0179

    CVE from 2018, added in 2022

    Cisco IOS Software Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    5.9 (medium)
  74. Rank 84Cisco IOS / IOS XE

    CVE-2018-0180

    CVE from 2018, added in 2022

    Cisco IOS Software Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    5.9 (medium)
  75. Rank 85Juniper Junos OS

    CVE-2023-36844

    Juniper Junos OS EX Series PHP External Variable Modification Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 13, 2023
    CISA deadline
    4 days
    CVSS severity
    5.3 (medium)
  76. Rank 86Juniper Junos OS

    CVE-2023-36846

    Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 13, 2023
    CISA deadline
    4 days
    CVSS severity
    5.3 (medium)
  77. Rank 87Juniper Junos OS

    CVE-2023-36847

    Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 13, 2023
    CISA deadline
    4 days
    CVSS severity
    5.3 (medium)
  78. Rank 88Juniper Junos OS

    CVE-2023-36851

    Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 13, 2023
    CISA deadline
    4 days
    CVSS severity
    5.3 (medium)
  79. Rank 89Juniper Junos OS

    CVE-2025-21590

    Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 13, 2025
    CISA deadline
    21 days
    CVSS severity
    4.4 (medium)

Filed under another category

These 4 vulnerabilities also concern this type of product, but are counted in their main category. My radar finds them when you follow this category.

  1. Citrix NetScaler ADC / Gateway

    CVE-2019-19781

    RansomwareCVE from 2019, added in 2021

    Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  2. Citrix NetScaler ADC / Gateway

    CVE-2020-8193

    Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.5 (medium)
  3. Citrix NetScaler ADC / Gateway

    CVE-2020-8195

    Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.5 (medium)
  4. Citrix NetScaler ADC / Gateway

    CVE-2020-8196

    Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    4.3 (medium)

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.