Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2018-0488

    ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption) via a crafted application packet within a TLS... Read more

    Affected Products : debian_linux mbed_tls
    • Published: Feb. 13, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-0487

    ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted certificate chain that is mishandled during RSASSA-PSS signature verification within... Read more

    Affected Products : debian_linux mbed_tls
    • Published: Feb. 13, 2018
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2018-0486

    Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct imperso... Read more

    Affected Products : debian_linux xmltooling-c
    • Published: Jan. 13, 2018
    • Modified: Nov. 21, 2024
  • 8.6

    HIGH
    CVE-2018-0485

    A vulnerability in the SM-1T3/E3 firmware on Cisco Second Generation Integrated Services Routers (ISR G2) and the Cisco 4451-X Integrated Services Router (ISR4451-X) could allow an unauthenticated, remote attacker to cause the ISR G2 Router or the SM-1T3/... Read more

    Affected Products : ios_xe ios
    • Published: Oct. 05, 2018
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2018-0484

    A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a virtual routing and forwarding (VRF) instance despite the absence of the vrf-also keyword in the access-clas... Read more

    Affected Products : ios
    • Published: Jan. 10, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-0483

    A vulnerability in Cisco Jabber Client Framework (JCF) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected system. The vulnerability is due to insufficient validation of user-supplied ... Read more

    Affected Products : jabber
    • Published: Jan. 10, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-0482

    A vulnerability in the web-based management interface of Cisco Prime Network Control System could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected system. The... Read more

    Affected Products : prime_infrastructure
    • Published: Jan. 10, 2019
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2018-0481

    A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exist because the affected software imp... Read more

    Affected Products : ios_xe
    • Published: Oct. 05, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2018-0480

    A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause the device to crash, leading to a denial of service (DoS) condition. The vulnerability is due to a race condition that o... Read more

    Affected Products : ios_xe
    • Published: Oct. 05, 2018
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2018-0477

    A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exist because the affected software imp... Read more

    Affected Products : ios_xe
    • Published: Oct. 05, 2018
    • Modified: Nov. 21, 2024
  • 7.1

    HIGH
    CVE-2018-0476

    A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is... Read more

    Affected Products : ios_xe
    • Published: Oct. 05, 2018
    • Modified: Nov. 21, 2024
  • 7.4

    HIGH
    CVE-2018-0475

    A vulnerability in the implementation of the cluster feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due t... Read more

    Affected Products : ios_xe ios
    • Published: Oct. 05, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-0474

    A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view digest credentials in clear text. The vulnerability is due to the incorrect inclusion of saved passwords in... Read more

    Affected Products : unified_communications_manager
    • Published: Jan. 10, 2019
    • Modified: Nov. 21, 2024
  • 8.6

    HIGH
    CVE-2018-0473

    A vulnerability in the Precision Time Protocol (PTP) subsystem of Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition of the Precision Time Protocol. The vulnerability is due to insufficient proc... Read more

    Affected Products : ios
    • Published: Oct. 05, 2018
    • Modified: Nov. 21, 2024
  • 8.6

    HIGH
    CVE-2018-0472

    A vulnerability in the IPsec driver code of multiple Cisco IOS XE Software platforms and the Cisco ASA 5500-X Series Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is due ... Read more

    • Published: Oct. 05, 2018
    • Modified: Nov. 21, 2024
  • 7.4

    HIGH
    CVE-2018-0471

    A vulnerability in the Cisco Discovery Protocol (CDP) module of Cisco IOS XE Software Releases 16.6.1 and 16.6.2 could allow an unauthenticated, adjacent attacker to cause a memory leak that may lead to a denial of service (DoS) condition. The vulnerabili... Read more

    Affected Products : ios_xe
    • Published: Oct. 05, 2018
    • Modified: Nov. 21, 2024
  • 8.6

    HIGH
    CVE-2018-0470

    A vulnerability in the web framework of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a buffer overflow condition on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to the aff... Read more

    Affected Products : ios_xe
    • Published: Oct. 05, 2018
    • Modified: Nov. 21, 2024
  • 7.1

    HIGH
    CVE-2018-0469

    A vulnerability in the web user interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a double-free-in-memory handling by the affected software when specific H... Read more

    Affected Products : ios_xe
    • Published: Oct. 05, 2018
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2018-0468

    A vulnerability in the configuration of a local database installed as part of the Cisco Energy Management Suite (CEMS) could allow an authenticated, local attacker to access and alter confidential data. The vulnerability is due to the installation of the ... Read more

    • Published: Dec. 04, 2018
    • Modified: Nov. 21, 2024
  • 8.6

    HIGH
    CVE-2018-0467

    A vulnerability in the IPv6 processing code of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is due to incorrect handling of specific IPv6 hop-by-hop options. An attacker cou... Read more

    Affected Products : ios_xe ios
    • Published: Oct. 05, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 293562 Results