Lucene search

K

Cisco Security Vulnerabilities

cve
cve

CVE-2022-20635

Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the we...

6.1CVSS

6.2AI Score

0.001EPSS

2022-01-14 05:15 AM
88
cve
cve

CVE-2022-20636

Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the we...

6.1CVSS

6.2AI Score

0.001EPSS

2022-01-14 05:15 AM
46
cve
cve

CVE-2022-20637

Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the we...

6.1CVSS

6.2AI Score

0.001EPSS

2022-01-14 05:15 AM
62
cve
cve

CVE-2022-20638

Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the we...

6.1CVSS

6.2AI Score

0.001EPSS

2022-01-14 05:15 AM
59
cve
cve

CVE-2022-20639

Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the we...

6.1CVSS

6.2AI Score

0.001EPSS

2022-01-14 05:15 AM
52
cve
cve

CVE-2022-20640

Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the we...

6.1CVSS

6.2AI Score

0.001EPSS

2022-01-14 05:15 AM
35
cve
cve

CVE-2022-20641

Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the we...

6.1CVSS

6.2AI Score

0.001EPSS

2022-01-14 05:15 AM
83
cve
cve

CVE-2022-20642

Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the we...

6.1CVSS

6.2AI Score

0.001EPSS

2022-01-14 05:15 AM
91
cve
cve

CVE-2022-20643

Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the we...

6.1CVSS

6.2AI Score

0.001EPSS

2022-01-14 05:15 AM
56
cve
cve

CVE-2022-20644

Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the we...

6.1CVSS

6.2AI Score

0.001EPSS

2022-01-14 05:15 AM
56
cve
cve

CVE-2022-20645

Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the we...

6.1CVSS

6.2AI Score

0.001EPSS

2022-01-14 05:15 AM
68
cve
cve

CVE-2022-20646

Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the we...

6.1CVSS

6.2AI Score

0.001EPSS

2022-01-14 05:15 AM
46
cve
cve

CVE-2022-20647

Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the we...

6.1CVSS

6.2AI Score

0.001EPSS

2022-01-14 05:15 AM
124
cve
cve

CVE-2022-20650

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation of user supplied data that is sent to the NX-API. An attacker could exploit this ...

8.8CVSS

8.9AI Score

0.001EPSS

2022-02-23 06:15 PM
99
cve
cve

CVE-2022-20651

A vulnerability in the logging component of Cisco Adaptive Security Device Manager (ASDM) could allow an authenticated, local attacker to view sensitive information in clear text on an affected system. Cisco ADSM must be deployed in a shared workstation environment for this issue to be exploited. T...

5.5CVSS

6.2AI Score

0.0004EPSS

2022-06-22 02:15 PM
152
7
cve
cve

CVE-2022-20653

A vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification component of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerabi...

7.5CVSS

7.6AI Score

0.001EPSS

2022-02-17 03:15 PM
159
cve
cve

CVE-2022-20658

A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) and Cisco Unified Contact Center Domain Manager (Unified CCDM) could allow an authenticated, remote attacker to elevate their privileges to Administrator. This vulnerability is due...

9.6CVSS

9.1AI Score

0.001EPSS

2022-01-14 05:15 AM
148
cve
cve

CVE-2022-20659

A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnera...

6.1CVSS

6.1AI Score

0.001EPSS

2022-02-17 03:15 PM
57
cve
cve

CVE-2022-20660

A vulnerability in the information storage architecture of several Cisco IP Phone models could allow an unauthenticated, physical attacker to obtain confidential information from an affected device. This vulnerability is due to unencrypted storage of confidential information on an affected device. ...

4.6CVSS

4.4AI Score

0.001EPSS

2022-01-14 05:15 AM
71
cve
cve

CVE-2022-20661

Multiple vulnerabilities that affect Cisco Catalyst Digital Building Series Switches and Cisco Catalyst Micro Switches could allow an attacker to execute persistent code at boot time or to permanently prevent the device from booting, resulting in a permanent denial of service (DoS) condition. For m...

4.6CVSS

5.6AI Score

0.001EPSS

2022-04-15 03:15 PM
69
cve
cve

CVE-2022-20662

A vulnerability in the smart card login authentication of Cisco Duo for macOS could allow an unauthenticated attacker with physical access to bypass authentication. This vulnerability exists because the assigned user of a smart card is not properly matched with the authenticating user. An attacker ...

6.8CVSS

6.5AI Score

0.001EPSS

2022-09-30 07:15 PM
35
11
cve
cve

CVE-2022-20664

A vulnerability in the web management interface of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an authenticated, remote attacker to retrieve sensitive information from a Lightweight Directory Access Pro...

7.7CVSS

7.5AI Score

0.001EPSS

2022-06-15 06:15 PM
107
6
cve
cve

CVE-2022-20665

A vulnerability in the CLI of Cisco StarOS could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient input validation of CLI commands. An attacker could exploit this vulnerability by sending crafted commands to the CLI. A suc...

6.7CVSS

7AI Score

0.0004EPSS

2022-04-06 07:15 PM
67
cve
cve

CVE-2022-20666

Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient va...

6.1CVSS

5.9AI Score

0.001EPSS

2022-05-27 02:15 PM
81
4
cve
cve

CVE-2022-20667

Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient va...

6.1CVSS

5.9AI Score

0.001EPSS

2022-05-27 02:15 PM
156
4
cve
cve

CVE-2022-20668

Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient va...

6.1CVSS

5.9AI Score

0.001EPSS

2022-05-27 02:15 PM
62
4
cve
cve

CVE-2022-20669

Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient va...

6.1CVSS

5.9AI Score

0.001EPSS

2022-05-27 02:15 PM
81
4
cve
cve

CVE-2022-20670

Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient va...

6.1CVSS

5.9AI Score

0.001EPSS

2022-05-27 02:15 PM
46
2
cve
cve

CVE-2022-20671

Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient va...

6.1CVSS

5.9AI Score

0.001EPSS

2022-05-27 02:15 PM
68
2
cve
cve

CVE-2022-20672

Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient va...

6.1CVSS

5.9AI Score

0.001EPSS

2022-05-27 02:15 PM
61
3
cve
cve

CVE-2022-20673

Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient va...

6.1CVSS

5.9AI Score

0.001EPSS

2022-05-27 02:15 PM
78
2
cve
cve

CVE-2022-20674

Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient va...

6.1CVSS

5.9AI Score

0.001EPSS

2022-05-27 02:15 PM
60
2
cve
cve

CVE-2022-20675

A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Secure Email and Web Manager, formerly Security Management Appliance, could allow an unauthenticated, remote attacker to crash the Simple Network Management Protocol (SNMP) ser...

5.3CVSS

5.4AI Score

0.001EPSS

2022-04-06 07:15 PM
65
cve
cve

CVE-2022-20676

A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS XE Software could allow an authenticated, local attacker to escalate from privilege level 15 to root-level privileges. This vulnerability is due to insufficient input validation of data that is passed into the Tcl interpret...

6.7CVSS

7AI Score

0.0004EPSS

2022-04-15 03:15 PM
65
cve
cve

CVE-2022-20677

Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being au...

6.7CVSS

6.4AI Score

0.0004EPSS

2022-04-15 03:15 PM
85
cve
cve

CVE-2022-20678

A vulnerability in the AppNav-XE feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to the incorrect handling of certain TCP segments. An attacker could e...

8.6CVSS

7.5AI Score

0.001EPSS

2022-04-15 03:15 PM
78
cve
cve

CVE-2022-20679

A vulnerability in the IPSec decryption routine of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to buffer exhaustion that occurs while traffic on a configured ...

7.7CVSS

7.7AI Score

0.001EPSS

2022-04-15 03:15 PM
103
cve
cve

CVE-2022-20680

A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to access sensitive information on an affected device. This vulnerability is due to improper enforcement of Administrator privilege levels for low-value sensitive data....

6.5CVSS

6.5AI Score

0.001EPSS

2022-02-10 06:15 PM
67
cve
cve

CVE-2022-20681

A vulnerability in the CLI of Cisco IOS XE Software for Cisco Catalyst 9000 Family Switches and Cisco Catalyst 9000 Family Wireless Controllers could allow an authenticated, local attacker to elevate privileges to level 15 on an affected device. This vulnerability is due to insufficient validation ...

7.8CVSS

7.8AI Score

0.0004EPSS

2022-04-15 03:15 PM
111
cve
cve

CVE-2022-20682

A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This v...

8.6CVSS

8.4AI Score

0.001EPSS

2022-04-15 03:15 PM
90
cve
cve

CVE-2022-20683

A vulnerability in the Application Visibility and Control (AVC-FNF) feature of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to i...

8.6CVSS

8.4AI Score

0.002EPSS

2022-04-15 03:15 PM
73
cve
cve

CVE-2022-20684

A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause an affected device to unexpectedly reload, resulting in a denial of ...

7.4CVSS

6.5AI Score

0.001EPSS

2022-04-15 03:15 PM
58
cve
cve

CVE-2022-20686

Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device and cause the LLDP service to restart.These vulnerabilities ar...

5.3CVSS

6.1AI Score

0.001EPSS

2022-12-12 09:15 AM
210
2
cve
cve

CVE-2022-20687

Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device and cause the LLDP service to restart.These vulnerabilities ar...

5.3CVSS

6.1AI Score

0.001EPSS

2022-12-12 09:15 AM
194
2
cve
cve

CVE-2022-20688

A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device and cause Cisco Discovery Protocol service to restart.This vulnerability is due to ...

5.3CVSS

6AI Score

0.001EPSS

2022-12-12 09:15 AM
212
2
cve
cve

CVE-2022-20689

Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, adjacent attacker to cause Cisco Discovery Protocol memory corruption on an affected device.These vulnerabilities are due to missing lengt...

8.8CVSS

8.7AI Score

0.001EPSS

2022-12-12 09:15 AM
200
2
cve
cve

CVE-2022-20690

Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, adjacent attacker to cause Cisco Discovery Protocol memory corruption on an affected device.These vulnerabilities are due to missing lengt...

8.8CVSS

8.8AI Score

0.001EPSS

2022-12-12 09:15 AM
198
2
cve
cve

CVE-2022-20691

A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unauthenticated, adjacent attacker to cause a DoS condition of an affected device.This vulnerability is due to missing length validation of certain Cisco Discover...

6.5CVSS

6.4AI Score

0.001EPSS

2022-12-12 09:15 AM
195
2
cve
cve

CVE-2022-20692

A vulnerability in the NETCONF over SSH feature of Cisco IOS XE Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service condition (DoS) on an affected device. This vulnerability is due to insufficient resource management. An attacker could exploit this vul...

7.7CVSS

6.4AI Score

0.001EPSS

2022-04-15 03:15 PM
55
cve
cve

CVE-2022-20693

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input t...

7.2CVSS

7.2AI Score

0.001EPSS

2022-04-15 03:15 PM
939
Total number of security vulnerabilities6096