Vulnerabilities in Cisco

3,365 results
Vexday analysis

Com 3.204 CVEs catalogadas e 53 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Cisco está 3,7 vezes acima da média geral do catálogo, o que indica risco operacional significativamente elevado para organizações que dependem dessas tecnologias. Há ainda 199 vulnerabilidades de severidade crítica e 77 com prova de conceito pública disponível, ampliando a superfície de ataque explorável sem necessidade de capacidade ofensiva avançada. O tipo de falha mais recorrente é CWE-20 (validação de entrada inadequada), uma classe de vulnerabilidade frequentemente presente em componentes de rede e que tende a produzir impacto amplo quando explorada. A CVE mais perigosa em exploração ativa neste momento é CVE-2021-1498, com EPSS máximo de 1,0 — indicando probabilidade de exploração extremamente alta —, e deve ser tratada como prioridade imediata em qualquer processo de gestão de patches.

CVE-2019-1636HIGHCisco Webex Teams URI Handler Insecure Library Loading VulnerabilityEPSS 46.9%CVE-2019-15276HIGHCisco Wireless LAN Controller HTTP Parsing Engine Denial of Service VulnerabilityEPSS 46.3%CVE-2017-6737HIGHA vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to rEPSS 45.2%KEVCVE-2026-20131CRITICALCisco Secure Firewall Management Center Software Remote Code Execution VulnerabilityEPSS 42.7%KEVCVE-2020-3331CRITICALCisco RV110W and RV215W Series Routers Arbitrary Code Execution VulnerabilityEPSS 41.7%CVE-2019-1898MEDIUMCisco RV110W, RV130W, and RV215W Routers Unauthenticated syslog File Access VulnerabilityEPSS 41.7%CVE-2023-20209MEDIUMA vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) couEPSS 40.8%CVE-2019-1936HIGHCisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Command Injection VulnerabilityEPSS 39.5%CVE-2025-20352HIGHA vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the fEPSS 39.4%KEVCVE-2020-3240CRITICALMultiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big DataEPSS 38.7%CVE-2019-15977CRITICALCisco Data Center Network Manager Authentication Bypass VulnerabilitiesEPSS 38.1%CVE-2019-15978HIGHCisco Data Center Network Manager Command Injection VulnerabilitiesEPSS 37.5%CVE-2023-20126CRITICALCisco SPA112 2-Port Phone Adapters Remote Command Execution VulnerabilityEPSS 36.7%CVE-2021-1384MEDIUMCisco IOx for IOS XE Software Command Injection VulnerabilityEPSS 35.4%CVE-2026-20316MEDIUMCisco Secure Firewall Management Center Software Static Credential VulnerabilityEPSS 35.1%KEVCVE-2024-20290HIGHA vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) EPSS 33.6%CVE-2024-20356HIGHA vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote aEPSS 32.7%CVE-2025-20393CRITICALCisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution VulnerabilityEPSS 32.4%KEVCVE-2026-20133MEDIUMA vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affectEPSS 31.8%KEVCVE-2022-20964MEDIUMA vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to injEPSS 30.6%