Cisco Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Cisco products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

103

In CISA KEV

94

Beyond CISA KEV

9

Sensor Observed

3

Virtual Patch Available

1

Cisco KEVs Added by Year

Loading...

103 Cisco KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2014-2120

Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to...

Confirmed In CISA 12 Nov 2024
CVE-2023-20118

A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could...

Confirmed In CISA 03 Mar 2025
CVE-2024-20439

A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a...

Confirmed In CISA 31 Mar 2025

Common Vulnerability Classes (CWE)

  • CWE-20 — Improper Input Validation 21
  • CWE-399 — Resource Management Errors 10
  • CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 10
  • CWE-121 — Stack-based Buffer Overflow 6
  • CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor 5
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 4
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 4
  • CWE-287 — Improper Authentication 3

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology