4.8

CVSS3.1

CVE-2025-20204 - Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.  This vulnerability is due to insufficient validation of user-supplied i…

📅 Published: Feb. 5, 2025, 4:14 p.m. 🔄 Last Modified: March 28, 2025, 1:42 p.m.

3.4

CVSS3.1

CVE-2025-20185 - Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Privilege Escala…

A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, local attacker to elevate privileges to root. The attacker must authent…

📅 Published: Feb. 5, 2025, 4:14 p.m. 🔄 Last Modified: Aug. 6, 2025, 4:53 p.m.

6.5

CVSS3.1

CVE-2025-20184 - Cisco Secure Email and Web Manager and Secure Web Appliance Command Injection Vulnerability

A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Web Appliance could allow an authenticated, remote attacker to perform command injection attacks against an affected device. The attacker must authenticate with valid admi…

📅 Published: Feb. 5, 2025, 4:14 p.m. 🔄 Last Modified: Aug. 8, 2025, 5:11 p.m.

5.8

CVSS3.1

CVE-2025-20183 - Cisco Secure Web Appliance Range Request Bypass Vulnerability

A vulnerability in a policy-based Cisco Application Visibility and Control (AVC) implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to evade the antivirus scanner and download a malicious file onto an endpoint.  The vulner…

📅 Published: Feb. 5, 2025, 4:14 p.m. 🔄 Last Modified: Aug. 5, 2025, 7:28 p.m.

4.8

CVSS3.1

CVE-2025-20180 - Cisco Secure Email and Web Manager and Secure Email Gateway Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability …

📅 Published: Feb. 5, 2025, 4:14 p.m. 🔄 Last Modified: Aug. 15, 2025, 8:36 p.m.

6.1

CVSS3.1

CVE-2025-20179 - Cisco Expressway Series Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly …

📅 Published: Feb. 5, 2025, 4:14 p.m. 🔄 Last Modified: Feb. 5, 2025, 5:21 p.m.

9.1

CVSS3.1

CVE-2025-20125 - Cisco Identity Services Engine Insufficient Authorization Bypass Vulnerability

A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information, change node configurations, and restart the node. This vulnerability is due to a lack of authorization in a specific API and improper validation …

📅 Published: Feb. 5, 2025, 4:12 p.m. 🔄 Last Modified: March 28, 2025, 1:37 p.m.

9.9

CVSS3.1

CVE-2025-20124 - Cisco Identity Services Engine Java Deserialization Vulnerability

A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands as the root user on an affected device. This vulnerability is due to insecure deserialization of user-supplied Java byte streams by the affected software. An attacker could exploit …

📅 Published: Feb. 5, 2025, 4:12 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:09 p.m.

8.7

CVSS4.0

CVE-2024-39564 - Junos OS and Junos OS Evolved: Receipt of malformed BGP path attributes leads to RPD crash

This is a similar, but different vulnerability than the issue reported as CVE-2024-39549. A double-free vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a malformed BGP Path attribute update which allocates memory used t…

📅 Published: Feb. 5, 2025, 3:31 p.m. 🔄 Last Modified: Jan. 26, 2026, 6:28 p.m.

5.5

CVSS3.1

CVE-2024-42207 - HCL iAutomate is affected by a session fixation vulnerability

HCL iAutomate is affected by a session fixation vulnerability.  An attacker could hijack a victim's session ID from their authenticated session.

📅 Published: Feb. 5, 2025, 3:11 p.m. 🔄 Last Modified: Oct. 10, 2025, 4:27 p.m.
Total resulsts: 343825
Page 6305 of 34,383
« previous page » next page
Filters