Vulnerabilidades en Cisco

3365 resultados
Análisis Vexday

Com 3.204 CVEs catalogadas e 53 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Cisco está 3,7 vezes acima da média geral do catálogo, o que indica risco operacional significativamente elevado para organizações que dependem dessas tecnologias. Há ainda 199 vulnerabilidades de severidade crítica e 77 com prova de conceito pública disponível, ampliando a superfície de ataque explorável sem necessidade de capacidade ofensiva avançada. O tipo de falha mais recorrente é CWE-20 (validação de entrada inadequada), uma classe de vulnerabilidade frequentemente presente em componentes de rede e que tende a produzir impacto amplo quando explorada. A CVE mais perigosa em exploração ativa neste momento é CVE-2021-1498, com EPSS máximo de 1,0 — indicando probabilidade de exploração extremamente alta —, e deve ser tratada como prioridade imediata em qualquer processo de gestão de patches.

CVE-2025-20334HIGHA vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that will execute with rEPSS 0.5%CVE-2020-3532MEDIUMCisco Unified Communications Products Cross-Site Scripting VulnerabilityEPSS 0.5%CVE-2026-20124HIGHCisco IOS XE Software SNMP Denial of Service VulnerabilityEPSS 0.5%CVE-2019-1700MEDIUMCisco Firepower 9000 Series Firepower 2-Port 100G Double-Width Network Module Queue Wedge Denial of Service VulnerabilityEPSS 0.5%CVE-2023-20096MEDIUMCisco Unified Contact Center Express Stored Cross-Site Scripting VulnerabilityEPSS 0.5%CVE-2024-20373MEDIUMCisco IOS and Cisco IOS XE SNMP Extended ACL Bypass VulnerabilityEPSS 0.5%CVE-2025-20221MEDIUMA vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to bypass LEPSS 0.5%CVE-2020-3148HIGHCisco Prime Network Registrar Cross-Site Request Forgery VulnerabilityEPSS 0.5%CVE-2018-15401—Cisco Hosted Collaboration Mediation Fulfillment Cross-Site Request Forgery VulnerabilityEPSS 0.5%CVE-2020-3124MEDIUMCisco Hosted Collaboration Mediation Fulfillment Cross-Site Request Forgery VulnerabilityEPSS 0.5%CVE-2020-3261HIGHCisco Mobility Express Software Cross-Site Request Forgery VulnerabilityEPSS 0.5%CVE-2026-20136MEDIUMCisco Identity Services Engine Authenticated Privilege Escalation VulnerabilityEPSS 0.5%CVE-2024-20357MEDIUMA vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiate phone calls on an EPSS 0.5%CVE-2019-1972MEDIUMCisco Enterprise NFV Infrastructure Software Privilege Escalation VulnerabilityEPSS 0.5%CVE-2026-20146MEDIUMCisco Identity Services Engine Path Traversal VulnerabilityEPSS 0.5%CVE-2021-1131MEDIUMCisco Video Surveillance 8000 Series IP Cameras Cisco Discovery Protocol Denial of Service VulnerabilityEPSS 0.5%CVE-2024-20310MEDIUMA vulnerability in the web-based interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unEPSS 0.5%CVE-2024-20417MEDIUMCisco Identity Services Engine REST API Blind SQL Injection VulnerabitiesEPSS 0.5%CVE-2021-1256MEDIUMCisco Firepower Threat Defense Software Command File Overwrite VulnerabilityEPSS 0.5%CVE-2025-20161MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.5%