4.3

CVSS3.1

CVE-2025-20214 -

A vulnerability in the Network Configuration Access Control Module (NACM) of Cisco IOS XE Software could allow an authenticated, remote attacker to obtain unauthorized read access to configuration or operational data. This vulnerability exists because a subtle change in inner API call behavior c…

πŸ“… Published: May 7, 2025, 5:34 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 2:36 p.m.

4.7

CVSS3.1

CVE-2025-20137 -

A vulnerability in the access control list (ACL) programming of Cisco IOS Software that is running on Cisco Catalyst 1000 Switches and Cisco Catalyst 2960L Switches could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to the use of both an IPv4 AC…

πŸ“… Published: May 7, 2025, 5:31 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 2:08 p.m.

7.1

CVSS3.1

CVE-2025-32821 -

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the appliance.

πŸ“… Published: May 7, 2025, 5:22 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

8.3

CVSS3.1

CVE-2025-32820 -

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writable.

πŸ“… Published: May 7, 2025, 5:20 p.m. πŸ”„ Last Modified: May 19, 2025, 3:12 p.m.

5.4

CVSS3.1

CVE-2025-20147 - Cisco SD-WAN vManage Stored Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to conduct a stored cross-site scripting attack (XSS) on an affected system.  This vulnerability is due to improper sanitizati…

πŸ“… Published: May 7, 2025, 5:19 p.m. πŸ”„ Last Modified: July 31, 2025, 6:14 p.m.

4.7

CVSS3.1

CVE-2025-20216 - Cisco Catalyst SD-WAN Manager Reflected HTML Injection Vulnerability

A vulnerability in the web interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to inject HTML into the browser of an authenticated user. This vulnerability is due to improper sanitization of input to the web interface. An att…

πŸ“… Published: May 7, 2025, 5:18 p.m. πŸ”„ Last Modified: July 29, 2025, 1:47 p.m.

8.6

CVSS3.1

CVE-2025-20154 - Cisco IOS, IOS XE and IOS XR Software TWAMP Denial of Service Vulnerability

A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. For Cisco IOS XR Software, this…

πŸ“… Published: May 7, 2025, 5:18 p.m. πŸ”„ Last Modified: July 31, 2025, 4:44 p.m.

4.3

CVSS3.1

CVE-2025-20151 - Cisco IOS and IOS XE Software SNMPv3 Configuration Restriction Vulnerability

A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to poll an affected device using SNMP, even if the device is configured to deny SNMP traffic from …

πŸ“… Published: May 7, 2025, 5:18 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 2:33 p.m.

7.4

CVSS3.1

CVE-2025-20191 - Multiple Cisco Products Denial of Service Vulnerability

A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS XE Software, Cisco NX-OS Software, and Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected…

πŸ“… Published: May 7, 2025, 5:18 p.m. πŸ”„ Last Modified: May 8, 2025, 2:39 p.m.

6.5

CVSS3.1

CVE-2025-20187 - Cisco SD-WAN Manager Software Arbitrary File Creation Vulnerability

A vulnerability in the application data endpoints of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to improper validation of requests to APIs. An attacker could…

πŸ“… Published: May 7, 2025, 5:18 p.m. πŸ”„ Last Modified: Aug. 4, 2025, 2:29 p.m.
Total resulsts: 343968
Page 4983 of 34,397
Β« previous page Β» next page
Filters