Vulnerabilidades en Cisco

3366 resultados
Análisis Vexday

Com 3.204 CVEs catalogadas e 53 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Cisco está 3,7 vezes acima da média geral do catálogo, o que indica risco operacional significativamente elevado para organizações que dependem dessas tecnologias. Há ainda 199 vulnerabilidades de severidade crítica e 77 com prova de conceito pública disponível, ampliando a superfície de ataque explorável sem necessidade de capacidade ofensiva avançada. O tipo de falha mais recorrente é CWE-20 (validação de entrada inadequada), uma classe de vulnerabilidade frequentemente presente em componentes de rede e que tende a produzir impacto amplo quando explorada. A CVE mais perigosa em exploração ativa neste momento é CVE-2021-1498, com EPSS máximo de 1,0 — indicando probabilidade de exploração extremamente alta —, e deve ser tratada como prioridade imediata em qualquer processo de gestão de patches.

CVE-2021-1237HIGHCisco AnyConnect Secure Mobility Client for Windows DLL Injection VulnerabilityEPSS 0.4%CVE-2024-20361MEDIUMA vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) Software could allowEPSS 0.4%CVE-2025-20151MEDIUMCisco IOS and IOS XE Software SNMPv3 Configuration Restriction VulnerabilityEPSS 0.4%CVE-2025-20210HIGHCisco Catalyst Center Unprotected API EndpointEPSS 0.4%CVE-2019-1654HIGHCisco Aironet Series Access Points Development Shell Access VulnerabilityEPSS 0.4%CVE-2019-1677MEDIUMCisco Webex Meetings for Android Cross-Site Scripting VulnerabilityEPSS 0.4%CVE-2019-16011HIGHCisco IOS XE SD-WAN Software Command Injection VulnerabilityEPSS 0.4%CVE-2023-20005MEDIUMMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthentiEPSS 0.4%CVE-2024-20298MEDIUMCisco Firepower Management Center Software Cross-Site Scripting VulnerabilityEPSS 0.4%CVE-2024-20269MEDIUMCisco Firepower Management Center Software Cross-Site Scripting VulnerabilityEPSS 0.4%CVE-2023-20074MEDIUMMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthentiEPSS 0.4%CVE-2026-20284CRITICALCisco Identity Search Engine SXP REST API SQL Injection VulnerabilityEPSS 0.4%CVE-2026-20097MEDIUMCisco Integrated Management Controller Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-20300MEDIUMCisco Firepower Management Center Software Cross-Site Scripting VulnerabilityEPSS 0.4%CVE-2024-20264MEDIUMCisco Firepower Management Center Software Cross-Site Scripting VulnerabilityEPSS 0.4%CVE-2023-20041MEDIUMMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthentiEPSS 0.4%CVE-2026-20098HIGHCisco Meeting Management Arbitrary File Upload VulnerabilityEPSS 0.4%CVE-2018-15368—Cisco IOS XE Software Privileged EXEC Mode Root Shell Access VulnerabilityEPSS 0.4%CVE-2026-20058MEDIUMCisco Secure Firewall Threat Defense Software Snort 3 Visual Basic for Application Denial of Service VulnerabilityEPSS 0.4%CVE-2024-20392MEDIUMA vulnerability in the web-based management API of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remEPSS 0.4%