Vulnerabilities > Cisco > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-03-03 CVE-2023-20078 Out-of-bounds Write vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-787
critical
9.8
2023-03-01 CVE-2023-20032 Out-of-bounds Write vulnerability in multiple products
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code.
network
low complexity
cisco clamav CWE-787
critical
9.8
2023-01-20 CVE-2023-20025 Improper Input Validation vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco Small Business RV042 Series Routers could allow an unauthenticated, remote attacker to bypass authentication on the affected device.
network
low complexity
cisco CWE-20
critical
9.8
2023-01-02 CVE-2015-10011 Improper Encoding or Escaping of Output vulnerability in Cisco Openresolve
A vulnerability classified as problematic has been found in OpenDNS OpenResolve.
network
low complexity
cisco CWE-116
critical
9.8
2022-07-06 CVE-2022-20859 Incorrect Authorization vulnerability in Cisco products
A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an authenticated, remote attacker to perform certain administrative actions they should not be able to.
network
low complexity
cisco CWE-863
critical
9.0
2022-06-15 CVE-2022-20825 Improper Input Validation vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
critical
10.0
2022-05-27 CVE-2022-20797 OS Command Injection vulnerability in Cisco Secure Network Analytics 2.1.1
A vulnerability in the web-based management interface of Cisco Secure Network Analytics, formerly Cisco Stealthwatch Enterprise, could allow an authenticated, remote attacker to execute arbitrary commands as an administrator on the underlying operating system.
network
low complexity
cisco CWE-78
critical
9.0
2022-05-04 CVE-2022-20801 Command Injection vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device.
network
low complexity
cisco CWE-77
critical
9.0
2022-05-04 CVE-2022-20799 Command Injection vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device.
network
low complexity
cisco CWE-77
critical
9.0
2022-05-04 CVE-2022-20779 Improper Input Validation vulnerability in Cisco Enterprise NFV Infrastructure Software
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM.
network
cisco CWE-20
critical
9.3