Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.2

    HIGH
    CVE-2018-0183

    A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device. The vulnerability... Read more

    Affected Products : ios_xe
    • Published: Mar. 28, 2018
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2018-0182

    Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into the CLI of the affected software, which could allow the attacker to gain access to the underlying Linux shel... Read more

    Affected Products : ios_xe
    • Published: Mar. 28, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-0181

    A vulnerability in the Redis implementation used by the Cisco Policy Suite for Mobile and Cisco Policy Suite Diameter Routing Agent software could allow an unauthenticated, remote attacker to modify key-value pairs for short-lived events stored by the Red... Read more

    • Published: Jan. 10, 2019
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2018-0177

    A vulnerability in the IP Version 4 (IPv4) processing code of Cisco IOS XE Software running on Cisco Catalyst 3850 and Cisco Catalyst 3650 Series Switches could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, o... Read more

    • Published: Mar. 28, 2018
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2018-0176

    Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device. The vuln... Read more

    Affected Products : ios_xe
    • Published: Mar. 28, 2018
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2018-0170

    A vulnerability in the Cisco Umbrella Integration feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition, related to the OpenDNS software. The vulnerability is due to a logic error tha... Read more

    Affected Products : ios_xe
    • Published: Mar. 28, 2018
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2018-0169

    Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device. The vuln... Read more

    Affected Products : ios_xe ios
    • Published: Mar. 28, 2018
    • Modified: Nov. 21, 2024
  • 7.4

    HIGH
    CVE-2018-0165

    A vulnerability in the Internet Group Management Protocol (IGMP) packet-processing functionality of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust buffers on an affected device, resulting in a denial of service (DoS) co... Read more

    • Published: Mar. 28, 2018
    • Modified: Nov. 21, 2024
  • 8.6

    HIGH
    CVE-2018-0164

    A vulnerability in the Switch Integrated Security Features of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an interface queue wedge. The vulnerability is due to incorrect handling of crafted IPv6 packets. An attacker coul... Read more

    Affected Products : ios_xe
    • Published: Mar. 28, 2018
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2018-0163

    A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass the authentication phase on an 802.1x multi-auth port. The vulnerability is due to a logic change ... Read more

    • Published: Mar. 28, 2018
    • Modified: Nov. 21, 2024
  • 6.3

    MEDIUM
    CVE-2018-0160

    A vulnerability in Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper management of memory resources... Read more

    • Published: Mar. 28, 2018
    • Modified: Nov. 21, 2024
  • 8.6

    HIGH
    CVE-2018-0157

    A vulnerability in the Zone-Based Firewall code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a device to reload. The vulnerability is due to the way fragmented packets are handled in the firewall code. An attacker coul... Read more

    Affected Products : ios_xe
    • Published: Mar. 28, 2018
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2018-0152

    A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to gain elevated privileges on an affected device. The vulnerability exists because the affected software does not reset the pr... Read more

    Affected Products : ios_xe
    • Published: Mar. 28, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2018-0150

    A vulnerability in Cisco IOS XE Software could allow an unauthenticated, remote attacker to log in to a device running an affected release of Cisco IOS XE Software with the default username and password that are used at initial boot, aka a Static Credenti... Read more

    • Published: Mar. 28, 2018
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2018-0149

    A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software could allow an authenticated, remote attacker to conduct a Document Object Model-based (DOM-based), stored ... Read more

    • Published: Jun. 07, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-0148

    A vulnerability in the web-based management interface of Cisco UCS Director Software and Cisco Integrated Management Controller (IMC) Supervisor Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack... Read more

    Affected Products : ucs_director
    • Published: Feb. 22, 2018
    • Modified: Nov. 21, 2024
  • 5.8

    MEDIUM
    CVE-2018-0146

    A vulnerability in the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to improper CSRF protection by t... Read more

    Affected Products : data_center_analytics_framework
    • Published: Feb. 22, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2018-0145

    A vulnerability in the web-based management interface of the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface of an a... Read more

    Affected Products : data_center_analytics_framework
    • Published: Feb. 22, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2018-0144

    A vulnerability in the web-based management interface of Cisco Prime Data Center Network Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affe... Read more

    Affected Products : prime_data_center_network_manager
    • Published: Mar. 08, 2018
    • Modified: Nov. 21, 2024
  • 8.4

    HIGH
    CVE-2018-0141

    A vulnerability in Cisco Prime Collaboration Provisioning (PCP) Software 11.6 could allow an unauthenticated, local attacker to log in to the underlying Linux operating system. The vulnerability is due to a hard-coded account password on the system. An at... Read more

    • Published: Mar. 08, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 293577 Results