Cisco Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Cisco products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
103
In CISA KEV
94
Beyond CISA KEV
9
Sensor Observed
3
Virtual Patch Available
1
Cisco KEVs Added by Year
103 Cisco KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2014-2120
Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to... |
Adaptive Security Appliance (ASA) Software | Confirmed | In CISA | 12 Nov 2024 |
|
CVE-2023-20118
A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could... |
Cisco Small Business RV Series Router Firmware | Confirmed | In CISA | 03 Mar 2025 |
|
CVE-2024-20439
A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a... |
Cisco Smart License Utility | Confirmed | In CISA | 31 Mar 2025 |
Common Vulnerability Classes (CWE)
- CWE-20 — Improper Input Validation 21
- CWE-399 — Resource Management Errors 10
- CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 10
- CWE-121 — Stack-based Buffer Overflow 6
- CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor 5
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 4
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 4
- CWE-287 — Improper Authentication 3
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology