Cisco vendor intelligence
Cisco Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Cisco products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 109
- Known exploited vulnerabilities affecting Cisco products
- In CISA KEV
- 98
- Records also listed in the official catalog
- Beyond CISA KEV
- 11
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 8
- Cisco KEVs with sensor-observed exploitation activity
The catalog gap matters for Cisco exposure
Eleven of the 109 exploited Cisco vulnerabilities tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 10% of this vendor portfolio.
- 90%
- Covered by CISA
- 10%
- Beyond CISA
- 44
- Product families
Attested Cisco vulnerabilities
109 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2023-20273
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges... |
Cisco IOS XE Software | Confirmed | In CISA | 23 Oct 2023 |
|
CVE-2020-3259
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability |
Cisco Adaptive Security Appliance (ASA) Software | Confirmed | In CISA | 15 Feb 2024 |
|
CVE-2024-20353
A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)... |
Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense Software | Confirmed | In CISA | 24 Apr 2024 |
|
CVE-2024-20359
A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive... |
Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense Software | Confirmed | In CISA | 24 Apr 2024 |
|
CVE-2024-20399
Cisco NX-OS Software CLI Command Injection Vulnerability |
Cisco NX-OS Software | Confirmed | In CISA | 02 Jul 2024 |
|
CVE-2024-20481
A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense... |
Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense Software | Confirmed | In CISA | 24 Oct 2024 |
|
CVE-2014-2120
Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to... |
Adaptive Security Appliance (ASA) Software | Confirmed | In CISA | 12 Nov 2024 |
|
CVE-2023-20118
A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could... |
Cisco Small Business RV Series Router Firmware | Confirmed | In CISA | 03 Mar 2025 |
|
CVE-2024-20439
A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a... |
Cisco Smart License Utility | Confirmed | In CISA | 31 Mar 2025 |
No Cisco vulnerabilities match this search or filter.
Showing 9 of 9 on this page (109 Cisco known exploited vulnerabilities).
Recurring weakness patterns
Input validation, restriction, and resource management errors account for 42 mapped occurrences across this Cisco KEV portfolio.
CWE-20
Improper Input Validation
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
CWE-399
Resource Management Errors
CWE-121
Stack-based Buffer Overflow
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-287
Improper Authentication