Cisco

Operational audit scripts and mitigation intelligence for 216 known Cisco vulnerabilities.

CVSS 10

CVE-2025-20265

Target: Cisco Secure Firewall Management Center - RADIUS Subsystem

CVSS 10

CVE-2025-20393

Actively Exploited

Target: Cisco Secure Email Gateway - Spam Quarantine

CVSS 10

CVE-2026-20079

Target: Secure Firewall Management Center (FMC) Software

CVSS 10

CVE-2023-20238

Target: Cisco BroadWorks Application Delivery Platform - SSO Implementation

CVSS 10

CVE-2025-20337

Actively Exploited

Target: Cisco ISE - API

CVSS 10

CVE-2024-20418

Target: Cisco Unified Industrial Wireless Software - Web-based Management Interface

CVSS 10

CVE-2025-20309

Target: Cisco Unified Communications Manager - Session Management Edition

CVSS 10

CVE-2026-20127

Actively Exploited

Target: Catalyst SD-WAN Controller - Peering Authentication

CVSS 10

CVE-2026-20131

Actively Exploited

Target: Cisco Secure Firewall Management Center (FMC) Software

CVSS 10

CVE-2025-20188

Target: Cisco IOS XE - Wireless LAN Controllers

CVSS 10

CVE-2024-20419

Target: Cisco Smart Software Manager On-Prem - Authentication System

CVSS 10

CVE-2023-20198

Actively Exploited

Target: Cisco IOS XE - Web UI

CVSS 10

CVE-2025-20282

Target: Cisco ISE - Internal API

CVSS 10

CVE-2025-20281

Actively Exploited

Target: Cisco ISE - API

CVSS 9.9

CVE-2025-20124

Target: Cisco ISE - API

CVSS 9.9

CVE-2023-20048

Target: Cisco Firepower Management Center - Web Services Interface

CVSS 9.9

CVE-2025-20333

Actively Exploited

Target: Cisco Secure Firewall - Adaptive Security Appliance (ASA) Software

CVSS 9.9

CVE-2025-20156

Target: Cisco Meeting Management - REST API

CVSS 9.9

CVE-2023-20036

Target: Cisco IND - Web UI

CVSS 9.9

CVE-2024-20253

Target: Cisco Unified Communications Manager - Web Services

CVSS 9.9

CVE-2024-20424

Target: Cisco FMC - Web Management Interface

CVSS 9.9

CVE-2024-20329

Target: Cisco Adaptive Security Appliance (ASA) Software - SSH Subsystem

CVSS 9.9

CVE-2024-20432

Target: Cisco Nexus Dashboard Fabric Controller - REST API

CVSS 9.9

CVE-2025-20286

Target: Cisco Identity Services Engine (ISE)

CVSS 9.8

CVE-2024-20401

Target: Cisco Secure Email Gateway - Content Scanning and Message Filtering

CVSS 9.8

CVE-2023-20079

Target: Cisco IP Phone - Web-based Management Interface

CVSS 9.8

CVE-2024-20439

Actively Exploited

Target: Cisco Smart Licensing Utility - API

CVSS 9.8

CVE-2023-20078

Target: Cisco IP Phone - Web-based Management Interface

CVSS 9.8

CVE-2026-20093

Target: Cisco Integrated Management Controller - IMC

CVSS 9.8

CVE-2026-20160

Target: Cisco Smart Software Manager On-Prem - SSM On-Prem

CVSS 9.8

CVE-2023-31488

Target: Cisco Secure Email Gateway - Hyland Perceptive Filters

CVSS 9.8

CVE-2023-20252

Target: Cisco Catalyst SD-WAN Manager Software - SAML APIs

CVSS 9.8

CVE-2026-20129

Target: Catalyst SD-WAN Manager - API

CVSS 9.8

CVE-2025-20354

Target: Cisco Unified CCX - Java RMI

CVSS 9.8

CVE-2024-20454

Target: Cisco SPA300/500 Series IP Phones - Web Management Interface

CVSS 9.8

CVE-2023-20101

Target: Cisco Emergency Responder - Root Account

CVSS 9.8

CVE-2023-20126

Target: Cisco SPA112 - Web-based management interface

CVSS 9.8

CVE-2024-20450

Target: Cisco SPA300/500 Series IP Phones - Web UI

CVSS 9.6

CVE-2024-20252

Target: Cisco Expressway Series - Web UI

CVSS 9.6

CVE-2023-20192

Target: Cisco Expressway Series - Cisco TelePresence Video Communication Server (VCS)

CVSS 9.6

CVE-2024-20254

Target: Cisco Expressway Series - Web Interface

CVSS 9.6

CVE-2023-20105

Target: Cisco Expressway Series - Web-based Management Interface

CVSS 9.4

CVE-2025-20358

Target: Cisco Unified CCX - CCX Editor

CVSS 9.3

CVE-2024-20412

Target: Cisco Firepower Threat Defense - Software

CVSS 9.1

CVE-2025-20125

Target: Cisco ISE - API

CVSS 9.1

CVE-2023-20214

Target: Cisco SD-WAN vManage - REST API

CVSS 9.1

CVE-2023-20154

Target: Cisco Modeling Labs - Web Interface

CVSS 9

CVE-2025-20363

Target: Cisco IOS XE - Web UI

CVSS 9

CVE-2023-20025

Target: Cisco Small Business Routers - Web Management Interface

CVSS 8.8

CVE-2024-20360

Target: Cisco Firepower Management Center - Web-based Management Interface

CVSS 8.8

CVE-2026-20094

Target: Cisco IMC - Web-Based Management Interface

CVSS 8.8

CVE-2025-20341

Target: Cisco Catalyst Center - Virtual Appliance

CVSS 8.8

CVE-2025-20334

Target: Cisco IOS XE - HTTP API

CVSS 8.8

CVE-2026-20040

Target: IOS XR Software - CLI

CVSS 8.8

CVE-2026-20046

Target: IOS XR Software

CVSS 8.8

CVE-2026-20098

Target: Cisco Meeting Management - Certificate Management

CVSS 8.8

CVE-2024-20536

Target: Nexus Dashboard Fabric Controller - REST API

CVSS 8.8

CVE-2024-20449

Target: Nexus Dashboard Fabric Controller - NDFC

CVSS 8.8

CVE-2024-20393

Target: Cisco RV340 Series - Web UI

CVSS 8.8

CVE-2025-20138

Target: Cisco IOS XR Software - CLI

CVSS 8.8

CVE-2024-20398

Target: Cisco IOS XR Software - CLI

CVSS 8.8

CVE-2024-20381

Target: Cisco Crosswork Network Services Orchestrator - JSON-RPC API

CVSS 8.8

CVE-2025-20236

Target: Webex App - Client

CVSS 8.8

CVE-2026-20126

Target: Catalyst SD-WAN Manager

CVSS 8.8

CVE-2024-20435

Target: Secure Web Appliance - CLI

CVSS 8.8

CVE-2025-20186

Target: Cisco IOS XE - Web UI

CVSS 8.8

CVE-2024-20295

Target: Cisco Integrated Management Controller - CLI

CVSS 8.8

CVE-2025-20261

Target: Cisco IMC - SSH Connection Handling

CVSS 8.7

CVE-2025-20163

Target: Cisco Nexus Dashboard Fabric Controller - SSH

CVSS 8.7

CVE-2024-20356

Target: Cisco IMC - Web Management Interface

CVSS 8.6

CVE-2024-20455

Target: Cisco IOS XE - Unified Threat Defense

CVSS 8.6

CVE-2026-20101

Target: Secure Firewall ASA Software - SAML 2.0 SSO

CVSS 8.6

CVE-2026-20039

Target: Cisco Secure Firewall - Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software

CVSS 8.6

CVE-2026-20082

Target: Secure Firewall Adaptive Security Appliance (ASA) Software

CVSS 8.6

CVE-2026-20103

Target: Secure Firewall - Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software

CVSS 8.6

CVE-2025-20115

Target: Cisco IOS XR - BGP

CVSS 8.6

CVE-2025-20142

Target: Cisco IOS XR - IPv4 ACL/QoS

CVSS 8.6

CVE-2025-20146

Target: Cisco IOS XR - Layer 3 Multicast

CVSS 8.6

CVE-2025-20154

Target: Cisco IOS - TWAMP Server

CVSS 8.6

CVE-2025-20162

Target: Cisco IOS XE - DHCP Snooping

CVSS 8.6

CVE-2025-20182

Target: Cisco ASA - IKEv2

CVSS 8.6

CVE-2025-20152

Target: Cisco Identity Services Engine - RADIUS

CVSS 8.6

CVE-2025-20271

Target: Meraki MX and Z Series - Cisco AnyConnect VPN server

CVSS 8.6

CVE-2025-20133

Target: Cisco Secure Firewall ASA Software - Remote Access SSL VPN

CVSS 8.6

CVE-2025-20134

Target: Cisco Secure Firewall - Adaptive Security Appliance (ASA) Software

CVSS 8.6

CVE-2025-20136

Target: Cisco Secure Firewall - Adaptive Security Appliance (ASA) Software

CVSS 8.6

CVE-2025-20217

Target: Cisco Secure Firewall Threat Defense - Snort 3 Detection Engine

CVSS 8.6

CVE-2025-20315

Target: Cisco IOS XE - NBAR

CVSS 8.6

CVE-2025-20222

Target: Cisco Secure Firewall - Adaptive Security Appliance (ASA) Software

CVSS 8.6

CVE-2025-20239

Target: Cisco IOS - IKEv2

CVSS 8.6

CVE-2025-20243

Target: Cisco Secure Firewall ASA Software - Management and VPN Web Server

CVSS 8.6

CVE-2025-20253

Target: Cisco IOS Software - IKEv2

CVSS 8.6

CVE-2025-20263

Target: Cisco Secure Firewall - Adaptive Security Appliance (ASA) Software

CVSS 8.6

CVE-2025-20343

Target: Cisco Identity Services Engine - RADIUS

CVSS 8.6

CVE-2024-20267

Target: Cisco NX-OS Software - Netstack

CVSS 8.6

CVE-2024-20321

Target: Cisco NX-OS Software - eBGP

CVSS 8.6

CVE-2024-20259

Target: Cisco IOS XE - DHCP Snooping

CVSS 8.6

CVE-2024-20271

Target: Cisco Access Point Software - IP Packet Processing

CVSS 8.6

CVE-2024-20311

Target: Cisco IOS XE - LISP

CVSS 8.6

CVE-2024-20314

Target: Cisco IOS XE - SD-Access

CVSS 8.6

CVE-2024-20308

Target: Cisco IOS XE - IKEv1

CVSS 8.6

CVE-2024-20353

Actively Exploited

Target: Cisco ASA - Web Server

CVSS 8.6

CVE-2024-20375

Target: Cisco Unified Communications Manager - SIP Call Processing

CVSS 8.6

CVE-2024-20446

Target: Cisco NX-OS Software - DHCPv6 Relay Agent

CVSS 8.6

CVE-2024-20304

Target: Cisco IOS XR - Mtrace2

CVSS 8.6

CVE-2024-20433

Target: Cisco IOS XE - RSVP

CVSS 8.6

CVE-2024-20436

Target: Cisco IOS XE - HTTP Server

CVSS 8.6

CVE-2024-20464

Target: Cisco IOS XE - PIM

CVSS 8.6

CVE-2024-20467

Target: Cisco IOS XE - IPv4 Fragmentation Reassembly

CVSS 8.6

CVE-2024-20480

Target: Cisco IOS XE - DHCP Snooping

CVSS 8.6

CVE-2024-20498

Target: Meraki MX - Cisco AnyConnect VPN server

CVSS 8.6

CVE-2024-20499

Target: Meraki MX - Cisco AnyConnect VPN server

CVSS 8.6

CVE-2024-20501

Target: Cisco Meraki MX - Cisco AnyConnect VPN server

CVSS 8.6

CVE-2024-20260

Target: Cisco Adaptive Security Virtual Appliance - VPN and Management Web Server

CVSS 8.6

CVE-2024-20330

Target: Cisco Firepower Threat Defense - Snort Detection Engine

CVSS 8.6

CVE-2024-20339

Target: Cisco Firepower Threat Defense - TLS Processing

CVSS 8.6

CVE-2024-20351

Target: Cisco Firepower Threat Defense - Snort Detection Engine

CVSS 8.6

CVE-2024-20402

Target: Cisco Adaptive Security Appliance (ASA) Software - SSL VPN

CVSS 8.6

CVE-2024-20426

Target: Cisco ASA - IKEv2

CVSS 8.6

CVE-2024-20494

Target: Cisco ASA Software - TLS Cryptography

CVSS 8.6

CVE-2024-20495

Target: Cisco Adaptive Security Appliance (ASA) Software - Remote Access VPN

CVSS 8.6

CVE-2026-20012

Target: Cisco IOS Software - Internet Key Exchange version 2 (IKEv2)

CVSS 8.6

CVE-2026-20084

Target: Cisco IOS XE Software - Cisco Catalyst 9000 Series Switches

CVSS 8.6

CVE-2026-20086

Target: Cisco IOS XE Wireless Controller Software - Catalyst CW9800 Family

CVSS 8.5

CVE-2025-20148

Target: Cisco Secure Firewall Management Center (FMC) Software - Web-based management interface

CVSS 8.5

CVE-2025-20251

Target: Cisco Secure Firewall - Adaptive Security Appliance (ASA) Software

CVSS 8.4

CVE-2024-20489

Target: Cisco IOS XR - PON Controller

CVSS 8.4

CVE-2025-60692

Target: Linksys E1200 - Firmware

CVSS 8.3

CVE-2025-20164

Target: Cisco IOS - Device Manager

CVSS 8.2

CVE-2024-20255

Target: Cisco Expressway Series - SOAP API

CVSS 8.2

CVE-2024-20337

Target: Cisco Secure Client - SAML Authentication

CVSS 8.2

CVE-2026-20045

Actively Exploited

Target: Cisco Unified Communications Manager - Web UI

CVSS 8.2

CVE-2024-20458

Target: Cisco ATA 190 Series - Web-based Management Interface

CVSS 8.1

CVE-2025-20160

Target: Cisco IOS XE - TACACS+ Protocol

CVSS 8.1

CVE-2026-20002

Target: Secure FMC Software - Web-based Management Interface

CVSS 8.1

CVE-2024-20437

Target: Cisco IOS XE - Web UI

CVSS 8

CVE-2026-20155

Target: Cisco Evolved Programmable Network Manager - Web-based Management Interface

CVSS 7.8

CVE-2025-20122

Target: Cisco SD-WAN Manager - CLI

CVSS 7.8

CVE-2024-20366

Target: Cisco Crosswork Network Services Orchestrator - Tail-f High Availability Cluster Communications

CVSS 7.8

CVE-2024-20326

Target: Cisco Crosswork Network Services Orchestrator - CLI

CVSS 7.8

CVE-2024-20389

Target: ConfD - CLI

CVSS 7.8

CVE-2024-20320

Target: Cisco IOS XR Software - SSH Client

CVSS 7.7

CVE-2025-20169

Target: Cisco IOS XE - SNMP Subsystem

CVSS 7.7

CVE-2025-20192

Target: Cisco IOS XE - IKEv1

CVSS 7.7

CVE-2026-20105

Target: Secure Firewall - Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software

CVSS 7.7

CVE-2025-20212

Target: Cisco Meraki MX - Cisco AnyConnect VPN server

CVSS 7.7

CVE-2026-20049

Target: Secure Firewall - Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software

CVSS 7.7

CVE-2026-20100

Target: Secure Firewall Adaptive Security Appliance (ASA) Software - Remote Access SSL VPN

CVSS 7.7

CVE-2026-20014

Target: Secure Firewall ASA Software - IKEv2

CVSS 7.7

CVE-2025-20176

Target: Cisco IOS XE - SNMP Subsystem

CVSS 7.7

CVE-2026-20048

Target: Nexus 9000 Series Fabric Switches - SNMP Subsystem

CVSS 7.7

CVE-2024-20268

Target: Cisco ASA - SNMP

CVSS 7.7

CVE-2025-20175

Target: Cisco IOS XE - SNMP Subsystem

CVSS 7.7

CVE-2024-20408

Target: Cisco Adaptive Security Appliance - Dynamic Access Policies

CVSS 7.7

CVE-2025-20174

Target: Cisco IOS XE - SNMP Subsystem

CVSS 7.7

CVE-2025-20173

Target: Cisco IOS XE - SNMP Subsystem

CVSS 7.7

CVE-2026-20125

Target: Cisco IOS Software - HTTP Server

CVSS 7.7

CVE-2025-20312

Target: Cisco IOS XE - SNMP Subsystem

CVSS 7.7

CVE-2025-20352

Actively Exploited

Target: Cisco IOS XE - SNMP Subsystem

CVSS 7.7

CVE-2025-20327

Target: Cisco IOS - Web UI

CVSS 7.7

CVE-2025-20244

Target: Cisco Secure Firewall - Adaptive Security Appliance (ASA) Software

CVSS 7.7

CVE-2025-20127

Target: Cisco Secure Firewall - Adaptive Security Appliance (ASA) Software

CVSS 7.7

CVE-2025-20172

Target: Cisco IOS - SNMP Subsystem

CVSS 7.7

CVE-2025-20171

Target: Cisco IOS XE - SNMP Subsystem

CVSS 7.7

CVE-2025-20170

Target: Cisco IOS XE - SNMP Subsystem

CVSS 7.5

CVE-2026-20128

Target: Catalyst SD-WAN Manager - Data Collection Agent

CVSS 7.5

CVE-2024-20281

Target: Cisco Nexus Dashboard - Web-based Management Interface

CVSS 7.5

CVE-2024-20484

Target: Cisco Enterprise Chat and Email - External Agent Assignment Service

CVSS 7.5

CVE-2026-20119

Target: Cisco TelePresence Collaboration Endpoint - Software

CVSS 7.5

CVE-2024-20376

Target: Cisco IP Phone - Web-based Management Interface

CVSS 7.5

CVE-2024-20350

Target: Cisco Catalyst Center - SSH Server

CVSS 7.5

CVE-2025-20165

Target: Cisco BroadWorks - SIP Processing Subsystem

CVSS 7.5

CVE-2025-27091

Target: OpenH264 - Codec Library

CVSS 7.5

CVE-2024-20348

Target: Nexus Dashboard Fabric Controller - Out-of-Band Plug and Play

CVSS 7.5

CVE-2024-20451

Target: Cisco Small Business SPA Series IP Phones - Web Management Interface

CVSS 7.5

CVE-2025-20350

Target: Cisco SIP Software - Web UI

CVSS 7.5

CVE-2025-20209

Target: Cisco IOS XR - Internet Key Exchange version 2 (IKEv2)

CVSS 7.5

CVE-2024-20323

Target: Cisco Intelligent Node Software - iNode Manager

CVSS 7.5

CVE-2025-20139

Target: Cisco Enterprise Chat and Email - Chat Messaging

CVSS 7.5

CVE-2024-20378

Target: Cisco IP Phone - Web-based Management Interface

CVSS 7.5

CVE-2024-20440

Target: Cisco Smart Licensing Utility - Web UI

CVSS 7.4

CVE-2024-20318

Target: Cisco IOS XR Software - Layer 2 Ethernet services

CVSS 7.4

CVE-2024-20276

Target: Cisco IOS - Catalyst 6000 Series Switches

CVSS 7.4

CVE-2026-20051

Target: Nexus 3600 Platform Switches - EVPN

CVSS 7.4

CVE-2026-20033

Target: Nexus 9000 Series Fabric Switches - ACI mode

CVSS 7.4

CVE-2026-20010

Target: NX-OS Software - Link Layer Discovery Protocol (LLDP)

CVSS 7.4

CVE-2026-20004

Target: Cisco IOS XE Software - TLS Library

CVSS 7.4

CVE-2024-20303

Target: Cisco IOS XE - Wireless LAN Controllers

CVSS 7.4

CVE-2025-20111

Target: Cisco NX-OS - Health Monitoring Diagnostics

CVSS 7.4

CVE-2025-20311

Target: Cisco IOS XE - Catalyst 9000 Series Switches

CVSS 7.4

CVE-2024-20327

Target: Cisco IOS XR - PPPoE Termination

CVSS 7.4

CVE-2025-20340

Target: Cisco IOS XR - Address Resolution Protocol

CVSS 7.4

CVE-2024-20313

Target: Cisco IOS XE - OSPFv2

CVSS 7.4

CVE-2025-20241

Target: Cisco NX-OS Software - IS-IS

CVSS 7.4

CVE-2025-20202

Target: Cisco IOS XE - Wireless Controller Software

CVSS 7.4

CVE-2025-20140

Target: Cisco IOS XE - Wireless Network Control

CVSS 7.4

CVE-2026-20074

Target: IOS XR Software - IS-IS

CVSS 7.4

CVE-2024-20317

Target: Cisco IOS XR Software - Network Convergence System

CVSS 7.4

CVE-2024-20406

Target: Cisco IOS XR - IS-IS Protocol

CVSS 7.4

CVE-2025-20189

Target: Cisco IOS XE - Cisco ASR 903 Aggregation Services Routers

CVSS 7.4

CVE-2024-20312

Target: Cisco IOS XE - IS-IS Protocol

CVSS 7.4

CVE-2025-20191

Target: Cisco IOS - Switch Integrated Security Features

CVSS 7.4

CVE-2025-20141

Target: Cisco IOS XR - Route Processor

CVSS 7.3

CVE-2026-20151

Target: Cisco Smart Software Manager On-Prem - Web Interface

CVSS 7.3

CVE-2024-20430

Target: Meraki Systems Manager (SM) Agent for Windows

CVSS 7.3

CVE-2024-20338

Target: Cisco Secure Client - ISE Posture

CVSS 7.3

CVE-2025-20210

Target: Cisco Catalyst Center - Management API

CVSS 7.3

CVE-2024-20272

Target: Cisco Unity Connection - Web-based Management Interface

CVSS 7.2

CVE-2024-20470

Target: Cisco RV340 - Web UI

CVSS 7.2

CVE-2024-20404

Target: Cisco Finesse - Web-based Management Interface

CVSS 7.2

CVE-2026-20062

Target: Secure Firewall Adaptive Security Appliance (ASA) Software

CVSS 7.2

CVE-2024-20483

Target: Cisco IOS XR - Routed PON Controller Software

CVSS 7.1

CVE-2025-20317

Target: Cisco Integrated Management Controller - Virtual Keyboard Video Monitor

CVSS 7.1

CVE-2025-20113

Target: Cisco Unified Intelligence Center - API

CVSS 7.1

CVE-2024-20421

Target: Cisco ATA 190 Series - Web-based Management Interface

CVSS 7.1

CVE-2025-20206

Target: Cisco Secure Client - Secure Firewall Posture Engine