Vulnerabilidades en Cisco

3366 resultados
Análisis Vexday

Com 3.204 CVEs catalogadas e 53 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Cisco está 3,7 vezes acima da média geral do catálogo, o que indica risco operacional significativamente elevado para organizações que dependem dessas tecnologias. Há ainda 199 vulnerabilidades de severidade crítica e 77 com prova de conceito pública disponível, ampliando a superfície de ataque explorável sem necessidade de capacidade ofensiva avançada. O tipo de falha mais recorrente é CWE-20 (validação de entrada inadequada), uma classe de vulnerabilidade frequentemente presente em componentes de rede e que tende a produzir impacto amplo quando explorada. A CVE mais perigosa em exploração ativa neste momento é CVE-2021-1498, com EPSS máximo de 1,0 — indicando probabilidade de exploração extremamente alta —, e deve ser tratada como prioridade imediata em qualquer processo de gestão de patches.

CVE-2026-20070MEDIUMCisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Services Cross-Site Scripting VulnerabilityEPSS 0.3%CVE-2020-3350MEDIUMCisco AMP for Endpoints and ClamAV Privilege Escalation VulnerabilityEPSS 0.3%CVE-2026-20102MEDIUMCisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SAML Reflected Cross-Site Scripting VulnerabilityEPSS 0.3%CVE-2022-20762HIGHCisco Ultra Cloud Core - Subscriber Microservices Infrastructure Privilege Escalation VulnerabilityEPSS 0.3%CVE-2019-1810MEDIUMCisco Nexus 3000 Series and 9000 Series Switches in NX-OS Mode CLI Command Software Image Signature Verification VulnerabilityEPSS 0.3%CVE-2019-12622MEDIUMCisco RoomOS Software Privilege Escalation VulnerabilityEPSS 0.3%CVE-2023-20251MEDIUMA vulnerability in the memory buffer of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attackeEPSS 0.3%CVE-2025-20279MEDIUMCisco Unifed Contact Center Express Stored Cross-Site Scripting VulnerabilityEPSS 0.3%CVE-2023-20113MEDIUMCisco SD-WAN vManage Software Cross-Site Request Forgery VulnerabilityEPSS 0.3%CVE-2021-34752MEDIUMCisco Firepower Threat Defense Command Injection VulnerabilitiesEPSS 0.3%CVE-2025-20267MEDIUMCisco Identity Services Stored Cross-Site Scripting VulnerabilityEPSS 0.3%CVE-2024-20281HIGHA vulnerability in the web-based management interface of Cisco Nexus Dashboard and Cisco Nexus Dashboard hosted services could allow an unauEPSS 0.3%CVE-2021-1126MEDIUMCisco Firepower Management Center Information Disclosure VulnerabilityEPSS 0.3%CVE-2021-1488MEDIUMCisco Adaptive Security Appliance Software and Firepower Threat Defense Software for Firepower 1000 and 2100 Series Appliances Command Injection VulnerabilityEPSS 0.3%CVE-2023-20064MEDIUMCisco IOS XR Software Bootloader Unauthenticated Information Disclosure VulnerabilityEPSS 0.3%CVE-2021-34771MEDIUMCisco IOS XR Software Unauthorized Information Disclosure VulnerabilityEPSS 0.3%CVE-2024-20434MEDIUMA vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on tEPSS 0.3%CVE-2023-20056MEDIUMCisco Access Point Software Denial of Service VulnerabilityEPSS 0.3%CVE-2024-20313HIGHA vulnerability in the OSPF version 2 (OSPFv2) feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause aEPSS 0.3%CVE-2019-15962MEDIUMCisco TelePresence Collaboration Endpoint Software Arbitrary File Write VulnerabilityEPSS 0.3%