Cisco Systems, Inc.

First CVE: Nov 8, 2007Active for: 19 years
6,269
CVEs Published
More CVEs Published than 97% of tracked CNAs
313.4
Avg CVEs / Year
More Avg CVEs / Year than 96% of tracked CNAs
6.8
Avg CVSS Score
Higher Avg CVSS Score than 33% of tracked CNAs
1.5%
In CISA KEV
Higher KEV Rate than 90% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Cisco Systems, Inc. as a CNA, 95.1% affect products that Cisco Systems, Inc. develops as a vendor.

95.1%
Self-reported: 5,960Third-party: 309

Of all the CVEs published that affect products developed by Cisco Systems, Inc., 89.8% are self-published by Cisco Systems, Inc. as a CNA.

89.8%
10.2%
Self-published: 5,960Published by other CNAs: 676

Trends Over Time

The number and severity of CVEs published by Cisco Systems, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 8, 2007
18 years ago
Most Recent CVE
Jul 15, 2026
9 days ago

Top CVEs

All CVEs published by Cisco Systems, Inc. as a CNA, regardless of affected vendor or product.

6,269 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service
Jun 10, 20269.899YESYES
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advi
May 14, 202610.099YESYES
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and
Oct 16, 202310.099YESYES
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a rel
Mar 17, 20179.899YESYES
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as roo
Jun 25, 202510.098YESYES
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an
May 6, 20219.898YESYES
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an
May 6, 20219.898YESYES
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated,
Jul 22, 20207.598YESYES
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrie
Jan 24, 20197.598YESYES
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpected
Jun 7, 20187.598YESYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA6,269 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCriticalNone
Attack Vector
Local722 (11.5%)
Network3,395 (54.2%)
Unknown1,835 (29.3%)
Physical39 (0.6%)
Adjacent Network278 (4.4%)
Attack Complexity
Low4,242 (67.7%)
High192 (3.1%)
Unknown1,835 (29.3%)
User Interaction
None3,481 (55.5%)
Unknown1,835 (29.3%)
Required953 (15.2%)
Privileges Required
Low1,225 (19.5%)
High847 (13.5%)
None2,362 (37.7%)
Unknown1,835 (29.3%)

Exploit Exposure

Signals from CVEs in this cna scope (6269 CVEs).

CISA KEV
93 CVEs
1.5% of CVEs· 90th percentile
Metasploit
49 CVEs
0.8% of CVEs· 85th percentile
Nuclei
30 CVEs
0.5% of CVEs· 75th percentile
ExploitDB
99 CVEs
1.6% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Cisco Systems, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Cisco Systems, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs