Cisco Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Cisco products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
103
In CISA KEV
94
Beyond CISA KEV
9
Sensor Observed
3
Virtual Patch Available
1
Cisco KEVs Added by Year
103 Cisco KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-20337
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability |
Cisco Identity Services Engine Software, Cisco ISE Passive Identity Connector | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-20281
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability |
Cisco Identity Services Engine Software | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2026-20182
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability |
Cisco Catalyst SD-WAN Controller, Cisco Catalyst SD-WAN Manager | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2018-0296
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an... |
Cisco Adaptive Security Appliance unknown | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-1653
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability |
Cisco Small Business RV Series Router Firmware | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-3161
Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability |
Cisco IP phone | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-3569
Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerabilities |
Cisco IOS XR Software | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-3566
Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability |
Cisco IOS XR Software | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-3118
Cisco IOS XR Software Cisco Discovery Protocol Format String Vulnerability |
Cisco IOS XR Software | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2018-0171
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-1498
Cisco HyperFlex HX Command Injection Vulnerabilities |
Cisco HyperFlex HX Data Platform | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-1497
Cisco HyperFlex HX Command Injection Vulnerabilities |
Cisco HyperFlex HX Data Platform | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-3580
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities |
Cisco Adaptive Security Appliance (ASA) Software | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-3452
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability |
Cisco Adaptive Security Appliance (ASA) Software | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2017-12231
A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an... |
Cisco IOS | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-12232
A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0... |
Cisco IOS | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-12233
Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an... |
Cisco IOS | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-12234
Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an... |
Cisco IOS | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-12235
A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an... |
Cisco IOS | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-12237
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-12238
A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow... |
Cisco IOS | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-12240
The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated,... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-12319
A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an... |
Cisco IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-6627
A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote... |
Cisco IOS and Cisco IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-6663
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Mar 2022 |
Common Vulnerability Classes (CWE)
- CWE-20 — Improper Input Validation 21
- CWE-399 — Resource Management Errors 10
- CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 10
- CWE-121 — Stack-based Buffer Overflow 6
- CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor 5
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 4
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 4
- CWE-287 — Improper Authentication 3
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology