ISC vendor intelligence

ISC Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting ISC products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse ISC KEVs Full KEV feed
Total KEVs
108
Known exploited vulnerabilities affecting ISC products
In CISA KEV
96
Records also listed in the official catalog
Beyond CISA KEV
12
Additional exploited CVEs absent from CISA KEV
Sensor Observed
7
ISC KEVs with sensor-observed exploitation activity

The catalog gap matters for ISC exposure

Twelve of the 108 exploited ISC CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 11% of this vendor portfolio.

89%
Covered by CISA
11%
Beyond CISA
45
Product families

Attested ISC CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2026-20349

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability

Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software Confirmed In CISA 11 Aug 2026
CVE-2025-20282

Cisco ISE API Unauthenticated Remote Code Execution Vulnerability

Cisco Identity Services Engine Software Confirmed Beyond CISA 07 Aug 2026
CVE-2021-1472

Cisco Small Business RV Series Routers Vulnerabilities

Cisco Small Business RV Series Router Firmware Confirmed Beyond CISA 30 Jul 2026
CVE-2026-20316

Cisco Secure Firewall Management Center Software Static Credential Vulnerability

Cisco Secure Firewall Management Center (FMC) Confirmed In CISA 29 Jul 2026
CVE-2008-4128

Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services...

IOS Confirmed In CISA 13 Jul 2026
CVE-2026-20230

Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability

Cisco Unified Communications Manager Confirmed In CISA 23 Jun 2026
CVE-2026-20262

Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability

Cisco Catalyst SD-WAN Manager Confirmed In CISA 15 Jun 2026
CVE-2026-20245

Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability

Cisco Catalyst SD-WAN Controller, Cisco Catalyst SD-WAN Manager Confirmed In CISA 05 Jun 2026
CVE-2024-20404

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on...

Cisco Unified Contact Center Enterprise, Cisco Unified Contact Center Express, Cisco Finesse, Cisco Packaged Contact Center Enterprise High Beyond CISA 01 Apr 2026
CVE-2020-16139

A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the device remotely through...

Unified IP Conference Station 7937G High Beyond CISA 10 Feb 2026
CVE-2024-20440

A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This...

Cisco Smart License Utility High Beyond CISA 25 Jan 2026
CVE-2013-2678

Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive...

Linksys E4200 High Beyond CISA 23 Nov 2025
CVE-2023-20073

Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers Arbitrary File Upload Vulnerability

Cisco Small Business RV Series Router Firmware High Beyond CISA 09 Nov 2025
CVE-2020-26073

Cisco SD-WAN vManage Directory Traversal Vulnerability

Cisco Catalyst SD-WAN Manager High Beyond CISA 24 Jul 2025
CVE-2018-0127

A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an...

RV132W ADSL2+ Wireless-N VPN Router, RV134W VDSL2 Wireless-AC VPN Router High Beyond CISA 21 Jun 2025
CVE-2001-0537

HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being...

IOS Confirmed Beyond CISA 21 Jun 2025
CVE-2019-1821

Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities

Cisco Prime Infrastructure High Beyond CISA 08 Jun 2025
CVE-2026-20133

A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected...

Cisco Catalyst SD-WAN Manager Confirmed In CISA 01 Jun 2026
CVE-2026-20128

Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability

Cisco Catalyst SD-WAN Manager Confirmed In CISA 01 Jun 2026
CVE-2026-20122

Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability

Cisco Catalyst SD-WAN Manager Confirmed In CISA 01 Jun 2026
CVE-2026-20131

Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability

Cisco Secure Firewall Management Center (FMC) Confirmed In CISA 01 Jun 2026
CVE-2026-20127

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Cisco Catalyst SD-WAN Manager Confirmed In CISA 01 Jun 2026
CVE-2022-20775

Cisco SD-WAN Software Privilege Escalation Vulnerability

Cisco Catalyst SD-WAN, Cisco Catalyst SD-WAN Manager, Cisco SD-WAN vContainer, Cisco SD-WAN vEdge Cloud, Cisco SD-WAN vEdge Router Confirmed In CISA 01 Jun 2026
CVE-2026-20045

Cisco Unified Communications Products Remote Code Execution Vulnerability

Cisco Unified Communications Manager, Cisco Unified Communications Manager IM and Presence Service, Cisco Unity Connection Confirmed In CISA 01 Jun 2026
CVE-2025-20393

Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability

Cisco Secure Email, Cisco Secure Email and Web Manager Confirmed In CISA 01 Jun 2026
CVE-2025-20352

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the...

IOS, Cisco IOS XE Software, Cisco IOS XE Catalyst SD-WAN Confirmed In CISA 01 Jun 2026
CVE-2025-20362

Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD...

Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software Confirmed In CISA 01 Jun 2026
CVE-2025-20333

A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense...

Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software Confirmed In CISA 01 Jun 2026
CVE-2025-20337

Cisco ISE API Unauthenticated Remote Code Execution Vulnerability

Cisco Identity Services Engine Software, Cisco ISE Passive Identity Connector Confirmed In CISA 01 Jun 2026
CVE-2025-20281

Cisco ISE API Unauthenticated Remote Code Execution Vulnerability

Cisco Identity Services Engine Software Confirmed In CISA 01 Jun 2026
CVE-2026-20182

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Cisco Catalyst SD-WAN Controller, Cisco Catalyst SD-WAN Manager Confirmed In CISA 01 Jun 2026
CVE-2026-8398

A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434),...

DAEMON Tools Lite Confirmed In CISA 27 May 2026
CVE-2013-4854

The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND...

BIND High Beyond CISA 26 Jul 2013
CVE-2018-0296

A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an...

Cisco Adaptive Security Appliance unknown Confirmed In CISA 03 Nov 2021
CVE-2019-1653

Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability

Cisco Small Business RV Series Router Firmware Confirmed In CISA 03 Nov 2021
CVE-2020-3161

Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability

Cisco IP phone Confirmed In CISA 03 Nov 2021
CVE-2020-3569

Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerabilities

Cisco IOS XR Software Confirmed In CISA 03 Nov 2021
CVE-2020-3566

Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

Cisco IOS XR Software Confirmed In CISA 03 Nov 2021
CVE-2020-3118

Cisco IOS XR Software Cisco Discovery Protocol Format String Vulnerability

Cisco IOS XR Software Confirmed In CISA 03 Nov 2021
CVE-2018-0171

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to...

Cisco IOS and IOS XE Confirmed In CISA 03 Nov 2021
CVE-2021-1498

Cisco HyperFlex HX Command Injection Vulnerabilities

Cisco HyperFlex HX Data Platform Confirmed In CISA 03 Nov 2021
CVE-2021-1497

Cisco HyperFlex HX Command Injection Vulnerabilities

Cisco HyperFlex HX Data Platform Confirmed In CISA 03 Nov 2021
CVE-2020-3580

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities

Cisco Adaptive Security Appliance (ASA) Software Confirmed In CISA 03 Nov 2021
CVE-2020-3452

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability

Cisco Adaptive Security Appliance (ASA) Software Confirmed In CISA 03 Nov 2021
CVE-2017-12231

A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an...

Cisco IOS Confirmed In CISA 03 Mar 2022
CVE-2017-12232

A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0...

Cisco IOS Confirmed In CISA 03 Mar 2022
CVE-2017-12233

Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an...

Cisco IOS Confirmed In CISA 03 Mar 2022
CVE-2017-12234

Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an...

Cisco IOS Confirmed In CISA 03 Mar 2022
CVE-2017-12235

A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an...

Cisco IOS Confirmed In CISA 03 Mar 2022
CVE-2017-12237

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow...

Cisco IOS and IOS XE Confirmed In CISA 03 Mar 2022
CVE-2017-12238

A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow...

Cisco IOS Confirmed In CISA 03 Mar 2022
CVE-2017-12240

The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated,...

Cisco IOS and IOS XE Confirmed In CISA 03 Mar 2022
CVE-2017-12319

A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an...

Cisco IOS XE Confirmed In CISA 03 Mar 2022
CVE-2017-6627

A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote...

Cisco IOS and Cisco IOS XE Confirmed In CISA 03 Mar 2022
CVE-2017-6663

A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent...

Cisco IOS and IOS XE Confirmed In CISA 03 Mar 2022
CVE-2017-6736

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an...

IOS, Universal Product Confirmed In CISA 03 Mar 2022
CVE-2017-6737

A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely...

IOS Confirmed In CISA 03 Mar 2022
CVE-2017-6738

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an...

IOS, Cisco IOS XE Software Confirmed In CISA 03 Mar 2022
CVE-2017-6740

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an...

IOS, Universal Product Confirmed In CISA 03 Mar 2022
CVE-2017-6743

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an...

IOS, Universal Product Confirmed In CISA 03 Mar 2022
CVE-2017-6744

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an...

IOS, Universal Product Confirmed In CISA 03 Mar 2022
CVE-2018-0151

A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote...

Cisco IOS and IOS XE Confirmed In CISA 03 Mar 2022
CVE-2018-0154

A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an...

Cisco IOS Confirmed In CISA 03 Mar 2022
CVE-2018-0155

A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst...

Cisco IOS and IOS XE Confirmed In CISA 03 Mar 2022
CVE-2018-0156

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to...

Cisco IOS and IOS XE Confirmed In CISA 03 Mar 2022
CVE-2018-0158

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an...

Cisco IOS and IOS XE Confirmed In CISA 03 Mar 2022
CVE-2018-0159

A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software...

Cisco IOS and IOS XE Confirmed In CISA 03 Mar 2022
CVE-2018-0161

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst...

Cisco IOS Confirmed In CISA 03 Mar 2022
CVE-2018-0167

Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and...

Cisco IOS, IOS XE, and IOS XR Confirmed In CISA 03 Mar 2022
CVE-2018-0172

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated,...

Cisco IOS and IOS XE Confirmed In CISA 03 Mar 2022
CVE-2018-0173

A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4...

Cisco IOS and IOS XE Confirmed In CISA 03 Mar 2022
CVE-2018-0174

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated,...

Cisco IOS and IOS XE Confirmed In CISA 03 Mar 2022
CVE-2018-0175

Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR...

Cisco IOS, IOS XE, and IOS XR Confirmed In CISA 03 Mar 2022
CVE-2018-0179

Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to...

Cisco IOS Confirmed In CISA 03 Mar 2022
CVE-2018-0180

Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to...

Cisco IOS Confirmed In CISA 03 Mar 2022
CVE-2019-1652

Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability

Cisco Small Business RV Series Router Firmware Confirmed In CISA 03 Mar 2022
CVE-2022-20699

Cisco Small Business RV Series Routers Vulnerabilities

Cisco Small Business RV Series Router Firmware Confirmed In CISA 03 Mar 2022
CVE-2022-20700

Cisco Small Business RV Series Routers Vulnerabilities

Cisco Small Business RV Series Router Firmware Confirmed In CISA 03 Mar 2022
CVE-2022-20701

Cisco Small Business RV Series Routers Vulnerabilities

Cisco Small Business RV Series Router Firmware Confirmed In CISA 03 Mar 2022
CVE-2022-20703

Cisco Small Business RV Series Routers Vulnerabilities

Cisco Small Business RV Series Router Firmware Confirmed In CISA 03 Mar 2022
CVE-2022-20708

Cisco Small Business RV Series Routers Vulnerabilities

Cisco Small Business RV Series Router Firmware Confirmed In CISA 03 Mar 2022
CVE-2009-2055

Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid...

IOS XR Confirmed In CISA 25 Mar 2022
CVE-2010-3035

Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers...

IOS XR Confirmed In CISA 25 Mar 2022
CVE-2015-0666

Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers...

Prime Data Center Network Manager Confirmed In CISA 25 Mar 2022
CVE-2017-3881

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an...

Cisco IOS and IOS XE Software Confirmed In CISA 25 Mar 2022
CVE-2018-0125

A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers could allow an...

Cisco RV132W and RV134W Confirmed In CISA 25 Mar 2022
CVE-2018-0147

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an...

Cisco Secure Access Control System Confirmed In CISA 25 Mar 2022
CVE-2022-20821

Cisco IOS XR Software Health Check Open Port Vulnerability

Cisco IOS XR Software Confirmed In CISA 23 May 2022
CVE-2016-6367

Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges...

Adaptive Security Appliance (ASA) Software Confirmed In CISA 24 May 2022
CVE-2016-6366

Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv,...

Adaptive Security Appliance (ASA) Software Confirmed In CISA 24 May 2022
CVE-2019-15271

Cisco Small Business RV016, RV042, RV042G, and RV082 Routers Arbitrary Command Execution Vulnerability

Cisco Small Business RV Series Router Firmware Confirmed In CISA 08 Jun 2022
CVE-2020-3153

Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability

Cisco AnyConnect Secure Mobility Client Confirmed In CISA 24 Oct 2022
CVE-2020-3433

Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability

Cisco AnyConnect Secure Mobility Client Confirmed In CISA 24 Oct 2022
CVE-2017-6742

A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely...

Cisco IOS XE Software, Universal Product Confirmed In CISA 19 Apr 2023
CVE-2016-6415

The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x,...

IOS, IOS XE, IOS XR, PIX Confirmed In CISA 19 May 2023
CVE-2004-1464

Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP...

IOS Confirmed In CISA 19 May 2023
CVE-2023-20269

A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)...

Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense Software Confirmed In CISA 13 Sep 2023
CVE-2023-20109

A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an...

IOS, Cisco IOS XE Software Confirmed In CISA 10 Oct 2023
CVE-2023-20198

Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are...

Cisco IOS XE Software Confirmed In CISA 16 Oct 2023
CVE-2023-20273

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges...

Cisco IOS XE Software Confirmed In CISA 23 Oct 2023
CVE-2020-3259

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability

Cisco Adaptive Security Appliance (ASA) Software Confirmed In CISA 15 Feb 2024
CVE-2024-20353

A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)...

Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense Software Confirmed In CISA 24 Apr 2024
CVE-2024-20359

A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive...

Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense Software Confirmed In CISA 24 Apr 2024
CVE-2024-20399

Cisco NX-OS Software CLI Command Injection Vulnerability

Cisco NX-OS Software Confirmed In CISA 02 Jul 2024
CVE-2024-20481

A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense...

Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense Software Confirmed In CISA 24 Oct 2024
CVE-2014-2120

Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to...

Adaptive Security Appliance (ASA) Software Confirmed In CISA 12 Nov 2024
CVE-2023-20118

A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could...

Cisco Small Business RV Series Router Firmware Confirmed In CISA 03 Mar 2025
CVE-2024-20439

A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a...

Cisco Smart License Utility Confirmed In CISA 31 Mar 2025

Showing 108 of 108 ISC known exploited vulnerabilities.

Recurring weakness patterns

Input validation, restriction, and resource management errors account for 42 mapped occurrences across this ISC KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.