Latest CVE Feed
-
6.5
MEDIUMCVE-2021-34712
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct cypher query language injection attacks on an affected system. This vulnerability is due to insufficient input ... Read more
- EPSS Score: %0.07
- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-34711
A vulnerability in the debug shell of Cisco IP Phone software could allow an authenticated, local attacker to read any file on the device file system. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability... Read more
- EPSS Score: %0.07
- Published: Oct. 06, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-34710
Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command injection attack resulting in remote code execution or cause a denial of service (DoS) condition on an affected device. For... Read more
- EPSS Score: %5.69
- Published: Oct. 06, 2021
- Modified: Nov. 21, 2024
-
6.9
MEDIUMCVE-2021-34709
Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow an authenticate... Read more
Affected Products : ios_xr 8201 8202 8101-32fh 8101-32h 8102-64h 8201-32fh 8800_12-slot 8800_18-slot 8800_4-slot +13 more products- EPSS Score: %0.02
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-34708
Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow an authenticate... Read more
Affected Products : ios_xr 8201 8202 8101-32fh 8101-32h 8102-64h 8201-32fh 8800_12-slot 8800_18-slot 8800_4-slot +13 more products- EPSS Score: %0.02
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-34707
A vulnerability in the REST API of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to access sensitive data on an affected system. This vulnerability exists because the application does not sufficiently prot... Read more
Affected Products : evolved_programmable_network_manager- EPSS Score: %0.24
- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2021-34706
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information or conduct a server-side request forgery (SSRF) attack through an affected device. ... Read more
Affected Products : identity_services_engine- EPSS Score: %0.21
- Published: Oct. 06, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-34705
A vulnerability in the Voice Telephony Service Provider (VTSP) service of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass configured destination patterns and dial arbitrary numbers. This vulnerability... Read more
- EPSS Score: %0.34
- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-34704
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulner... Read more
- EPSS Score: %0.25
- Published: Jan. 11, 2022
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-34703
A vulnerability in the Link Layer Discovery Protocol (LLDP) message parser of Cisco IOS Software and Cisco IOS XE Software could allow an attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. This vulnerabil... Read more
Affected Products : ios_xe ios catalyst_3650-12x48fd-e catalyst_3650-12x48fd-l catalyst_3650-12x48fd-s catalyst_3650-12x48uq catalyst_3650-12x48uq-e catalyst_3650-12x48uq-l catalyst_3650-12x48uq-s catalyst_3650-12x48ur +193 more products- EPSS Score: %0.27
- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-34702
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information. This vulnerability is due to improper enforcement of administrator privilege level... Read more
Affected Products : identity_services_engine- EPSS Score: %0.16
- Published: Oct. 06, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-34701
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (U... Read more
- EPSS Score: %0.09
- Published: Nov. 04, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-34700
A vulnerability in the CLI interface of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to read arbitrary files on the underlying file system of an affected system. This vulnerability exists because access to sensitive informati... Read more
- EPSS Score: %0.05
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2021-34699
A vulnerability in the TrustSec CLI parser of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to an improper interaction between the web UI and the CLI pars... Read more
- EPSS Score: %0.79
- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-34698
A vulnerability in the proxy service of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to exhaust system memory and cause a denial of service (DoS) condition on an affected device. This vulnerability i... Read more
- EPSS Score: %0.52
- Published: Oct. 06, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-34697
A vulnerability in the Protection Against Distributed Denial of Service Attacks feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct denial of service (DoS) attacks to or through the affected device. This vulnerabili... Read more
Affected Products : ios_xe- EPSS Score: %0.38
- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2021-34696
A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrect programming of... Read more
Affected Products : ios_xe asr_902 asr_903 asr_907 asr_920-10sz-pd asr_920-10sz-pd_r asr_920-12cz-a asr_920-12cz-a_r asr_920-12cz-d asr_920-12cz-d_r +13 more products- EPSS Score: %0.18
- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-34693
net/can/bcm.c in the Linux kernel through 5.12.10 allows local users to obtain sensitive information from kernel stack memory because parts of a data structure are uninitialized.... Read more
- EPSS Score: %0.05
- Published: Jun. 14, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-34692
iDrive RemotePC before 7.6.48 on Windows allows privilege escalation. A local and low-privileged user can force RemotePC to execute an attacker-controlled executable with SYSTEM privileges.... Read more
- EPSS Score: %0.06
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-34691
iDrive RemotePC before 4.0.1 on Linux allows denial of service. A remote and unauthenticated attacker can disconnect a valid user session by connecting to an ephemeral port.... Read more
- EPSS Score: %0.53
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024