|
195981
|
6.5 |
MEDIUM
Adjacent
|
netgear
|
br200_firmware br500_firmware d7800_firmware ex6100v2_firmware ex6150v2_firmware ex6250_firmware ex6400_firmware ex6400v2_firmware ex6410_firmware ex6420_firmware ex7300…
|
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Authentication is not …
|
-
|
CVE-2021-27257
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195982
|
8.8 |
HIGH
Adjacent
|
netgear
|
br200_firmware br500_firmware d7800_firmware ex6100v2_firmware ex6150v2_firmware ex6250_firmware ex6400_firmware ex6400v2_firmware ex6410_firmware ex6420_firmware ex7300…
|
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Although authentication is required to exploit thi…
|
-
|
CVE-2021-27256
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195983
|
8.8 |
HIGH
Adjacent
|
netgear
|
br200_firmware br500_firmware d7800_firmware ex6100v2_firmware ex6150v2_firmware ex6250_firmware ex6400_firmware ex6400v2_firmware ex6410_firmware ex6420_firmware ex7300…
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Authentication is not required to exploit this vulnerability…
|
-
|
CVE-2021-27255
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195984
|
8.8 |
HIGH
Adjacent
|
netgear
|
br200_firmware br500_firmware d7800_firmware ex6100v2_firmware ex6150v2_firmware ex6250_firmware ex6400_firmware ex6400v2_firmware ex6410_firmware ex6420_firmware ex7300…
|
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7800. Authentication is not required to exploit this vulnerability. The specific fl…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2021-27254
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195985
|
6.3 |
MEDIUM
Network
|
arubanetworks
|
airwave
|
A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave web-base management …
|
CWE-78
OS Command
|
CVE-2021-26970
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195986
|
6.8 |
MEDIUM
Network
|
cncf
|
spire
|
In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided through the agent ID templating feature, which may allow the issu…
|
CWE-863
Incorrect Authorization
|
CVE-2021-27099
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195987
|
8.1 |
HIGH
Network
|
cncf
|
spire
|
In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the FetchX509SVID RPC of SPIRE Server’s Legacy Node API can result in the possible iss…
|
CWE-295
Improper Certificate Validation
|
CVE-2021-27098
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195988
|
6.3 |
MEDIUM
Network
|
arubanetworks
|
airwave
|
A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave web-base management …
|
NVD-CWE-noinfo
|
CVE-2021-26971
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195989
|
6.5 |
MEDIUM
Network
|
arubanetworks
|
airwave
|
A remote authenticated authenticated xml external entity (xxe) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Due to improper restrictions on XML ent…
|
CWE-611
XXE
|
CVE-2021-26969
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195990
|
4.8 |
MEDIUM
Network
|
arubanetworks
|
airwave
|
A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the web-based management i…
|
CWE-79
Cross-site Scripting
|
CVE-2021-26968
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|