Cisco

2 exploits Active since Feb 2011
CVE-2017-16007 WRITEUP MEDIUM WORKING POC
Cisco Node-jose < 0.9.3 - Information Disclosure
node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and node.js-based servers. node-jose earlier than version 0.9.3 is vulnerable to an invalid curve attack. This allows an attacker to recover the private secret key when JWE with Key Agreement with Elliptic Curve Diffie-Hellman Ephemeral Static (ECDH-ES) is used.
CVSS 5.9
CVE-2011-0354 EXPLOITDB text WRITEUP
Cisco Tandberg Endpoint < tc3.1.3 - Credentials Management
The default configuration of Cisco Tandberg C Series Endpoints, and Tandberg E and EX Personal Video units, with software before TC4.0.0 has a blank password for the root account, which makes it easier for remote attackers to obtain access via an unspecified login method.