Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2021-11-04 CVE-2021-43281 Code Injection vulnerability in Mybb
MyBB before 1.8.29 allows Remote Code Injection by an admin with the "Can manage settings?" permission.
network
low complexity
mybb CWE-94
7.2
2021-11-04 CVE-2021-21686 Link Following vulnerability in Jenkins
File path filters in the agent-to-controller security subsystem of Jenkins 2.318 and earlier, LTS 2.303.2 and earlier do not canonicalize paths, allowing operations to follow symbolic links to outside allowed directories.
network
low complexity
jenkins CWE-59
8.1
2021-11-04 CVE-2021-21688 Missing Authorization vulnerability in Jenkins
The agent-to-controller security check FilePath#reading(FileVisitor) in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not reject any operations, allowing users to have unrestricted read access using certain operations (creating archives, FilePath#copyRecursiveTo).
network
low complexity
jenkins CWE-862
7.5
2021-11-04 CVE-2021-21695 Link Following vulnerability in Jenkins
FilePath#listFiles lists files outside directories that agents are allowed to access when following symbolic links in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
network
low complexity
jenkins CWE-59
8.8
2021-11-04 CVE-2021-21698 Path Traversal vulnerability in Jenkins Subversion
Jenkins Subversion Plugin 2.15.0 and earlier does not restrict the name of a file when looking up a subversion key file on the controller from an agent.
network
low complexity
jenkins CWE-22
7.5
2021-11-04 CVE-2021-34739 Insufficient Session Expiration vulnerability in Cisco products
A vulnerability in the web-based management interface of multiple Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to replay valid user session credentials and gain unauthorized access to the web-based management interface of an affected device.
network
high complexity
cisco CWE-613
8.1
2021-11-04 CVE-2021-34741 Allocation of Resources Without Limits or Throttling vulnerability in Cisco Asyncos
A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack against an affected device.
network
low complexity
cisco CWE-770
7.5
2021-11-04 CVE-2021-40112 Unspecified vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a default credential if the Telnet protocol is enabled Perform command injection Modify the configuration For more information about these vulnerabilities, see the Details section of this advisory.
network
low complexity
cisco
7.5
2021-11-04 CVE-2021-40120 OS Command Injection vulnerability in Cisco Application Extension Platform and IOS XR
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker with administrative privileges to inject arbitrary commands into the underlying operating system and execute them using root-level privileges.
network
low complexity
cisco CWE-78
7.2
2021-11-04 CVE-2021-40124 Improper Privilege Management vulnerability in Cisco Anyconnect Secure Mobility Client
A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to escalate privileges on an affected device.
local
low complexity
cisco CWE-269
7.8