VulnSea

cisco has 397 CVEs on record between 2017 and 2026. Disclosure cadence is accelerating: 122 in the last 90 days against 33 in the 90 before. The busiest recent month was September 2026 with 95. The median CVSS is 7.2 (high), with 50 rated critical. 4% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 189 days (13 cases). The dominant weakness classes are CWE-20 (34) and CWE-400 (30). Most affected products: secure_firewall_threat_defense (75), Cisco Identity Services Engine Software (41), enterprise_nfv_infrastructure_software (21).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
4% vs 1% corpus
Median CVSS
7.2
Publish → KEV
189 d median(13)
Last 90 days
122 prev 33

Products

  • secure_firewall_threat_defense 75
  • Cisco Identity Services Engine Software 41
  • enterprise_nfv_infrastructure_software 21
  • adaptive_security_appliance 18
  • Cisco TelePresence Endpoint Software (TC/CE) 17
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 16
397
Total CVEs
50
Critical
13
CISA KEV
15
Exploited

cisco vulnerabilities

CVEs affecting cisco, newest first. Open any entry for full detail, references, and exploit status.

397 CVEsRSS

CVE-2026-20111Medium· 4.8
7mo ago

A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system.…

A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system.…

▾ Sunlitcisco · prime_infrastructureEPSS 0.19%via NVD
CVE-2025-20359Medium· 6.5
11mo ago

Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the disclosure of possible sensitive data or cause the Snort 3 Detection Engine to crash. …

Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the disclosure of possible sensitive data or cause the Snort 3 Detection Engine to crash. …

▾ Sunlitcisco · snortEPSS 0.48%via NVD
CVE-2025-20338Medium· 6.0
1y ago

A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands as root on the underlying operating system of an affected device. This vulne…

A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands as root on the underlying operating system of an affected device. This vulne…

▾ Sunlitcisco · ios_xeEPSS 0.16%via NVD
CVE-2025-20352High· 7.7CISA KEVPoC
1y ago

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of serv…

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of serv…

▾ Abyssalcisco · ios_xe_sd-wanEPSS 39%via NVD
CVE-2025-20160High· 8.1
1y ago

A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to view sensitive data or bypass authentication

A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to view sensitive data or bypass authentication. This vulnerability exists …

▾ Twilightcisco · iosEPSS 0.43%via NVD
CVE-2025-20149Medium· 6.5
1y ago

A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnera…

A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnera…

▾ Sunlitcisco · iosEPSS 0.12%via NVD
CVE-2025-20312High· 7.7
1y ago

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability i…

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability i…

▾ Twilightcisco · ios_xeEPSS 0.39%via NVD
CVE-2025-20311High· 7.4
1y ago

A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches could allow an unauthenticated, adjacent attacker to cause an egress port to become blocked and drop all outbound traff…

A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches could allow an unauthenticated, adjacent attacker to cause an egress port to become blocked and drop all outbound traff…

▾ Twilightcisco · ios_xeEPSS 0.20%via NVD
CVE-2025-20327High· 7.7
1y ago

A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input vali…

A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input vali…

▾ Twilightcisco · iosEPSS 0.39%via NVD
CVE-2025-20313Medium· 6.7
1y ago

Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and brea…

Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and brea…

▾ Sunlitcisco · ios_xeEPSS 0.18%via NVD
CVE-2025-20365Medium· 4.3
1y ago

A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an unauthenticated, adjacent attacker to modify the IPv6 gateway on an affected device. This vulnerability is due to a …

A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an unauthenticated, adjacent attacker to modify the IPv6 gateway on an affected device. This vulnerability is due to a …

▾ SunlitCisco · Cisco Aironet Access Point Software (IOS XE Controller)EPSS 0.17%via NVD
CVE-2025-20364Medium· 4.3
1y ago

A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow an unauthenticated, adjacent attacker to inject wireless 802.11 action frames with arbitrary information. This vu…

A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow an unauthenticated, adjacent attacker to inject wireless 802.11 action frames with arbitrary information. This vu…

▾ SunlitCisco · Cisco Aironet Access Point Software (IOS XE Controller)EPSS 0.12%via NVD
CVE-2025-20248Medium· 6.0
1y ago

A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR Software image signature verification and load unsigned software on an affected device

A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR Software image signature verification and load unsigned software on an affected device. To exploit t…

▾ Sunlitcisco · ios_xrEPSS 0.10%via NVD
CVE-2025-20296Medium· 5.4
1y ago

A vulnerability in the web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerabilit…

A vulnerability in the web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerabilit…

▾ Sunlitcisco · ucs_managerEPSS 0.23%via NVD
CVE-2025-20317High· 7.1
1y ago

Cisco UCS Virtual Keyboard Video Monitor (vKVM) Open Redirect Vulnerability

A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to redirect a user to a malicious website. This vulnerabili…

▾ TwilightCisco · Cisco Unified Computing System (Managed)EPSS 0.43%via CSAF
CVE-2025-20131Medium· 4.9
1y ago

A vulnerability in the GUI of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability is due to improper validation of…

A vulnerability in the GUI of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability is due to improper validation of…

▾ Sunlitcisco · identity_services_engineEPSS 0.30%via NVD
CVE-2025-20224Medium· 5.8
1y ago

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker t…

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker t…

▾ Sunlitcisco · secure_firewall_threat_defenseEPSS 0.71%via NVD
CVE-2025-20272Medium· 4.3
1y ago

A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack. This v…

A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack. This v…

▾ Sunlitcisco · prime_infrastructureEPSS 0.32%via NVD
CVE-2025-20278Medium· 6.0
1y ago

Cisco Unified Communications Products Command Injection Vulnerability (CVE-2025-20278)

A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. This vuln…

▾ SunlitCisco · Cisco Unified Communications ManagerEPSS 0.18%via CSAF
CVE-2025-20129Medium· 4.3
1y ago

Cisco Customer Collaboration Platform Information Disclosure Vulnerability (CVE-2025-20129)

A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data. This vulnerability…

▾ SunlitCisco · Cisco SocialMinerEPSS 0.34%via CSAF
CVE-2025-20112Medium· 5.1
1y ago

Cisco Unified Communications Products Privilege Escalation Vulnerability (CVE-2025-20112)

A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to excessive perm…

▾ SunlitCisco · Cisco Unified Communications ManagerEPSS 0.14%via CSAF
CVE-2025-20151Medium· 4.3
1y ago

Cisco IOS and IOS XE Software SNMPv3 Configuration Restriction Vulnerability (CVE-2025-20151)

A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to poll an affected device using SNMP,…

▾ SunlitCisco · IOSEPSS 0.39%via CSAF
CVE-2025-20205Medium· 4.8
1y ago

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interf…

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interf…

▾ Sunlitcisco · identity_services_engineEPSS 0.33%via NVD
CVE-2025-20204Medium· 4.8
1y ago

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interf…

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interf…

▾ Sunlitcisco · identity_services_engineEPSS 0.33%via NVD
CVE-2024-20260High· 8.6
1y ago

Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models

Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found tha…

▾ TwilightCisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareEPSS 0.59%via NVD
CVE-2024-20343Medium· 5.5
2y ago

Cisco IOS XR Software CLI Arbitrary File Read Vulnerability (CVE-2024-20343)

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to read any file in the file system of the underlying Linux operating system. The attacker must have valid credentials on the affected device.…

▾ SunlitCisco · Cisco IOS XR SoftwareEPSS 0.14%via CSAF
CVE-2024-20317High· 7.4
2y ago

Cisco IOS XR Software Layer 2 Services Denial of Service Vulnerability

A vulnerability in the handling of specific Ethernet frames by Cisco IOS XR Software for various Cisco Network Convergence System (NCS) platforms could allow an unauthenticated, adjacent attacker to cause critical priority packets to be dr…

▾ TwilightCisco · Cisco IOS XR SoftwareEPSS 0.24%via CSAF
CVE-2024-20479Medium· 4.8
2y ago

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user-su…

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user-su…

▾ Sunlitcisco · identity_services_engineEPSS 0.29%via NVD
CVE-2024-20373Medium· 5.3
2y ago

Cisco IOS and Cisco IOS XE SNMP Extended ACL Bypass Vulnerability

A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) IPv4 access control list (ACL) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform SNMP p…

▾ SunlitCisco · IOSEPSS 0.50%via CSAF
CVE-2024-20271High· 8.6
2y ago

Cisco Access Point Software Denial of Service Vulnerability (CVE-2024-20271)

A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficien…

▾ TwilightCisco · Cisco Aironet Access Point SoftwareEPSS 0.63%via CSAF
cisco vulnerabilities (CVEs) — page 7 · VulnSea