7.7

CVSS3.1

CVE-2025-20172 -

A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP requests. An attackerโ€ฆ

๐Ÿ“… Published: Feb. 5, 2025, 4:37 p.m. ๐Ÿ”„ Last Modified: July 3, 2025, 3:48 p.m.

7.7

CVSS3.1

CVE-2025-20173 -

A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnโ€ฆ

๐Ÿ“… Published: Feb. 5, 2025, 4:35 p.m. ๐Ÿ”„ Last Modified: July 3, 2025, 3:48 p.m.

4.3

CVSS3.1

CVE-2025-20207 - Cisco Secure Email Gateway, Cisco Secure Email and Web Appliance and Cisco Secure Web Appliance SNMโ€ฆ

A vulnerability in Simple Network Management Protocol (SNMP) polling for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, remote attacker to obtain confidential information about the underlying operating system. This vulโ€ฆ

๐Ÿ“… Published: Feb. 5, 2025, 4:15 p.m. ๐Ÿ”„ Last Modified: Feb. 5, 2025, 5:15 p.m.

4.8

CVSS3.1

CVE-2025-20205 - Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.  This vulnerability is due to insufficient validation of user-supplied iโ€ฆ

๐Ÿ“… Published: Feb. 5, 2025, 4:14 p.m. ๐Ÿ”„ Last Modified: March 28, 2025, 1:46 p.m.

4.8

CVSS3.1

CVE-2025-20204 - Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.  This vulnerability is due to insufficient validation of user-supplied iโ€ฆ

๐Ÿ“… Published: Feb. 5, 2025, 4:14 p.m. ๐Ÿ”„ Last Modified: March 28, 2025, 1:42 p.m.

3.4

CVSS3.1

CVE-2025-20185 - Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Privilege Escalaโ€ฆ

A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, local attacker to elevate privileges to root. The attacker must authentโ€ฆ

๐Ÿ“… Published: Feb. 5, 2025, 4:14 p.m. ๐Ÿ”„ Last Modified: Aug. 6, 2025, 4:53 p.m.

6.5

CVSS3.1

CVE-2025-20184 - Cisco Secure Email and Web Manager and Secure Web Appliance Command Injection Vulnerability

A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Web Appliance could allow an authenticated, remote attacker to perform command injection attacks against an affected device. The attacker must authenticate with valid admiโ€ฆ

๐Ÿ“… Published: Feb. 5, 2025, 4:14 p.m. ๐Ÿ”„ Last Modified: Aug. 8, 2025, 5:11 p.m.

5.8

CVSS3.1

CVE-2025-20183 - Cisco Secure Web Appliance Range Request Bypass Vulnerability

A vulnerability in a policy-based Cisco Application Visibility and Control (AVC) implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to evade the antivirus scanner and download a malicious file onto an endpoint.  The vulnerโ€ฆ

๐Ÿ“… Published: Feb. 5, 2025, 4:14 p.m. ๐Ÿ”„ Last Modified: Aug. 5, 2025, 7:28 p.m.

4.8

CVSS3.1

CVE-2025-20180 - Cisco Secure Email and Web Manager and Secure Email Gateway Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability โ€ฆ

๐Ÿ“… Published: Feb. 5, 2025, 4:14 p.m. ๐Ÿ”„ Last Modified: Aug. 15, 2025, 8:36 p.m.

6.1

CVSS3.1

CVE-2025-20179 - Cisco Expressway Series Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly โ€ฆ

๐Ÿ“… Published: Feb. 5, 2025, 4:14 p.m. ๐Ÿ”„ Last Modified: Feb. 5, 2025, 5:21 p.m.
Total resulsts: 343929
Page 6315 of 34,393
ยซ previous page ยป next page
Filters