|
194301
|
6.3 |
MEDIUM
Network
|
arubanetworks
|
airwave
|
A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave web-base management …
|
CWE-78
OS Command
|
CVE-2021-26970
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194302
|
6.8 |
MEDIUM
Network
|
cncf
|
spire
|
In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided through the agent ID templating feature, which may allow the issu…
|
CWE-863
Incorrect Authorization
|
CVE-2021-27099
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194303
|
8.1 |
HIGH
Network
|
cncf
|
spire
|
In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the FetchX509SVID RPC of SPIRE Server’s Legacy Node API can result in the possible iss…
|
CWE-295
Improper Certificate Validation
|
CVE-2021-27098
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194304
|
6.3 |
MEDIUM
Network
|
arubanetworks
|
airwave
|
A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave web-base management …
|
NVD-CWE-noinfo
|
CVE-2021-26971
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194305
|
6.5 |
MEDIUM
Network
|
arubanetworks
|
airwave
|
A remote authenticated authenticated xml external entity (xxe) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Due to improper restrictions on XML ent…
|
CWE-611
XXE
|
CVE-2021-26969
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194306
|
4.8 |
MEDIUM
Network
|
arubanetworks
|
airwave
|
A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the web-based management i…
|
CWE-79
Cross-site Scripting
|
CVE-2021-26968
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194307
|
6.5 |
MEDIUM
Network
|
arubanetworks
|
airwave
|
A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Multiple vulnerabilities in the API of AirWave could allow an aut…
|
CWE-89
SQL Injection
|
CVE-2021-26966
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194308
|
6.5 |
MEDIUM
Network
|
arubanetworks
|
airwave
|
A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Multiple vulnerabilities in the API of AirWave could allow an aut…
|
CWE-89
SQL Injection
|
CVE-2021-26965
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194309
|
7.2 |
HIGH
Network
|
arubanetworks
|
airwave
|
A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave CLI could allow remo…
|
NVD-CWE-noinfo
|
CVE-2021-26963
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194310
|
6.1 |
MEDIUM
Network
|
arubanetworks
|
airwave
|
A remote reflected cross-site scripting (xss) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the web-based management interface of…
|
CWE-79
Cross-site Scripting
|
CVE-2021-26967
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|