Vulnerabilities > Cisco > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-07-06 CVE-2022-20859 Incorrect Authorization vulnerability in Cisco products
A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an authenticated, remote attacker to perform certain administrative actions they should not be able to.
network
low complexity
cisco CWE-863
critical
9.0
2022-06-15 CVE-2022-20825 Improper Input Validation vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
critical
10.0
2022-05-27 CVE-2022-20797 OS Command Injection vulnerability in Cisco Secure Network Analytics 2.1.1
A vulnerability in the web-based management interface of Cisco Secure Network Analytics, formerly Cisco Stealthwatch Enterprise, could allow an authenticated, remote attacker to execute arbitrary commands as an administrator on the underlying operating system.
network
low complexity
cisco CWE-78
critical
9.0
2022-05-04 CVE-2022-20801 Command Injection vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device.
network
low complexity
cisco CWE-77
critical
9.0
2022-05-04 CVE-2022-20799 Command Injection vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device.
network
low complexity
cisco CWE-77
critical
9.0
2022-05-04 CVE-2022-20779 Improper Input Validation vulnerability in Cisco Enterprise NFV Infrastructure Software
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM.
network
cisco CWE-20
critical
9.3
2022-05-04 CVE-2022-20777 Incorrect Authorization vulnerability in Cisco Enterprise NFV Infrastructure Software
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM.
network
low complexity
cisco CWE-863
critical
9.0
2022-05-04 CVE-2022-20753 Out-of-bounds Write vulnerability in Cisco products
A vulnerability in web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device.
network
low complexity
cisco CWE-787
critical
9.0
2022-05-03 CVE-2022-20743 Unrestricted Upload of File with Dangerous Type vulnerability in Cisco Firepower Management Center
A vulnerability in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to bypass security protections and upload malicious files to the affected system.
network
low complexity
cisco CWE-434
critical
9.0
2022-04-15 CVE-2022-20723 Unspecified vulnerability in Cisco IOS XE and Ir510 Operating System
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software.
network
low complexity
cisco
critical
9.0