Latest CVE Feed
-
7.5
HIGHCVE-2021-26992
Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability which could allow a remote attacker to cause a Denial of Service (DoS).... Read more
Affected Products : cloud_manager- EPSS Score: %0.70
- Published: Mar. 19, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-26991
Cloud Manager versions prior to 3.9.4 contain an insecure Cross-Origin Resource Sharing (CORS) policy which could allow a remote attacker to interact with Cloud Manager.... Read more
Affected Products : cloud_manager- EPSS Score: %0.21
- Published: Mar. 19, 2021
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2021-26990
Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability that could allow a remote attacker to overwrite arbitrary system files.... Read more
Affected Products : cloud_manager- EPSS Score: %0.81
- Published: Mar. 19, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-26989
Clustered Data ONTAP versions prior to 9.3P21, 9.5P16, 9.6P12, 9.7P9 and 9.8 are susceptible to a vulnerability which could allow a remote authenticated attacker to cause a Denial of Service (DoS) on clustered Data ONTAP configured for SMB access.... Read more
- EPSS Score: %0.80
- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-26988
Clustered Data ONTAP versions prior to 9.3P21, 9.5P16, 9.6P12, 9.7P8 and 9.8 are susceptible to a vulnerability which could allow unauthorized tenant users to discover information related to converting a 7-Mode directory to Cluster-mode such as Storage Vi... Read more
- EPSS Score: %0.14
- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26987
Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploited could lead to Remote Code Execution. All versions of Element Plug-in fo... Read more
- EPSS Score: %1.87
- Published: Mar. 15, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-26971
A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave web-base management interface could allow remote authenticated users to run ... Read more
Affected Products : airwave- EPSS Score: %1.10
- Published: Mar. 05, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-26970
A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave web-base management interface could allow remote authenticated users to run ... Read more
Affected Products : airwave- EPSS Score: %1.10
- Published: Mar. 05, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-26969
A remote authenticated authenticated xml external entity (xxe) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Due to improper restrictions on XML entities a vulnerability exists in the web-based management... Read more
Affected Products : airwave- EPSS Score: %0.86
- Published: Mar. 05, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-26968
A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the web-based management interface of AirWave could allow an authenticated remote ... Read more
Affected Products : airwave- EPSS Score: %0.21
- Published: Mar. 05, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26967
A remote reflected cross-site scripting (xss) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the web-based management interface of AirWave could allow a remote attacker to conduct a refl... Read more
Affected Products : airwave- EPSS Score: %0.30
- Published: Mar. 05, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-26966
A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Multiple vulnerabilities in the API of AirWave could allow an authenticated remote attacker to conduct SQL injection atta... Read more
Affected Products : airwave- EPSS Score: %0.26
- Published: Mar. 05, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-26965
A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Multiple vulnerabilities in the API of AirWave could allow an authenticated remote attacker to conduct SQL injection atta... Read more
Affected Products : airwave- EPSS Score: %0.23
- Published: Mar. 05, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-26964
A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an authenticated remote attacker to impro... Read more
Affected Products : airwave- EPSS Score: %0.09
- Published: Mar. 05, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-26963
A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave CLI could allow remote authenticated users to run arbitrary commands on the ... Read more
Affected Products : airwave- EPSS Score: %3.63
- Published: Mar. 05, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-26962
A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave CLI could allow remote authenticated users to run arbitrary commands on the ... Read more
Affected Products : airwave- EPSS Score: %3.63
- Published: Mar. 05, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-26961
A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an unauthenticated remote... Read more
Affected Products : airwave- EPSS Score: %0.31
- Published: Mar. 05, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-26960
A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an unauthenticated remote... Read more
Affected Products : airwave- EPSS Score: %0.31
- Published: Mar. 05, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-26958
An issue was discovered in the xcb crate through 2021-02-04 for Rust. It has a soundness violation because transmutation to the wrong type can happen after xcb::base::cast_event uses std::mem::transmute to return a reference to an arbitrary type.... Read more
Affected Products : xcb- EPSS Score: %0.57
- Published: Feb. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26957
An issue was discovered in the xcb crate through 2021-02-04 for Rust. It has a soundness violation because there is an out-of-bounds read in xcb::xproto::change_property(), as demonstrated by a format=32 T=u8 situation where out-of-bounds bytes are sent t... Read more
Affected Products : xcb- EPSS Score: %0.50
- Published: Feb. 09, 2021
- Modified: Nov. 21, 2024