7.4

CVSS3.1

CVE-2025-20191 - Multiple Cisco Products Denial of Service Vulnerability

A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS XE Software, Cisco NX-OS Software, and Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected…

πŸ“… Published: May 7, 2025, 5:18 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-20187 - Cisco SD-WAN Manager Software Arbitrary File Creation Vulnerability

A vulnerability in the application data endpoints of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to improper validation of requests to APIs. An attacker could…

πŸ“… Published: May 7, 2025, 5:18 p.m. πŸ”„ Last Modified: Aug. 4, 2025, 2:29 p.m.

7.8

CVSS3.1

CVE-2025-20122 - Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability

A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to gain privileges of the root user on the underlying operating system. This vulnerability is due to insufficient input validation. An authenticated attacker w…

πŸ“… Published: May 7, 2025, 5:18 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

8.8

CVSS3.1

CVE-2025-32819 -

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.

πŸ“… Published: May 7, 2025, 5:18 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

5.5

CVSS3.1

CVE-2025-20213 - Cisco Catalyst SDWAN Manager Arbitrary File Overwrite Vulnerability

A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. To exploit this vulnerability, the attacker must have valid read-only credentials wit…

πŸ“… Published: May 7, 2025, 5:18 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

8.6

CVSS3.1

CVE-2025-20182 - Cisco Adaptive Security Appliance Software, Firepower Threat Defense Software and IOS XE Software I…

A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol processing of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of s…

πŸ“… Published: May 7, 2025, 5:18 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 4:12 p.m.

5.9

CVSS3.1

CVE-2025-20157 - Cisco Catalyst vManage Certificate Validation Vulnerability

A vulnerability in certificate validation processing of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability is due to improper validation of certificates that are used by the Sma…

πŸ“… Published: May 7, 2025, 5:17 p.m. πŸ”„ Last Modified: Aug. 4, 2025, 2:46 p.m.

7.3

CVSS3.1

CVE-2025-20210 - Cisco Catalyst Center Unprotected API Endpoint

A vulnerability in the management API of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to read and modify the outgoing proxy configuration settings. This vulnerability is due to the lack of authentication in an API endpoint. An attacker could e…

πŸ“… Published: May 7, 2025, 5:16 p.m. πŸ”„ Last Modified: Aug. 13, 2025, 7:05 p.m.

5.7

CVSS4.0

CVE-2025-46551 - JRuby-OpenSSL has hostname verification disabled by default

JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. Starting in JRuby-OpenSSL version 0.12.1 and prior to version 0.15.4 (corresponding to JRuby versions starting in 9.3.4.0 prior to 9.4.12.1 and 10.0.0.0 prior to 10.0.0.1), when verifying SSL certificates, JRuby…

πŸ“… Published: May 7, 2025, 4:12 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 3:36 p.m.

8

CVSS3.1

CVE-2025-46827 - Graylog Allows Session Takeover via Insufficient HTML Sanitization

Graylog is a free and open log management platform. Prior to versions 6.0.14, 6.1.10, and 6.2.0, it is possible to obtain user session cookies by submitting an HTML form as part of an Event Definition Remediation Step field. For this attack to succeed, the attacker needs a user account with permiss…

πŸ“… Published: May 7, 2025, 3:29 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 7:29 p.m.
Total resulsts: 347731
Page 5360 of 34,774
Β« previous page Β» next page
Filters