Vulnerabilities (CVE)
Yack CVE helps teams search and track vulnerabilities.
TOTAL
358,413 CVE
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Arubanetworks 1Airwave Glass Jun 17, 2026 Nov 4, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. |
1Arubanetworks 1Airwave Glass Jun 17, 2026 Oct 26, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. |
1Arubanetworks 1Airwave Glass Jun 17, 2026 Oct 26, 2020 N/A· v4 5.8 MEDIUM· v3 5.0 MEDIUM· v2 A remote server-side request forgery (ssrf) vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. |
A remote escalation of privilege vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. |
1Arubanetworks 1Airwave Glass Jun 17, 2026 Oct 26, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A remote unauthorized access vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. |
1Arubanetworks 6Cx 6200f Firmware Cx 6300 FirmwareCx 6400 Firmware+3 moreJun 17, 2026 Sep 23, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been found. Successful exploitation of these vulnerabilities could result in Local Denial of Service of t...Show more |
1Arubanetworks 6Cx 6200f Firmware Cx 6300 FirmwareCx 6400 Firmware+3 moreJun 17, 2026 Sep 23, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been found. Successful exploitation of these vulnerabilities could result in Local Denial of Service of t...Show more |
1Arubanetworks 1Analytics And Location Engine Jun 17, 2026 Sep 4, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability exists in the Aruba Analytics and Location Engine (ALE) web management interface 2.1.0.2 and earlier firmware that allows an already authenticated administrative user to arbitrarily modify files as an und...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Jun 3, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the attacker is already authenticated to the administrative interface, they could then exploit the system, l...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Jun 3, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the attacker is already authenticated to the administrative interface, they could then exploit the system, l...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Jun 3, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker could then execute an exploit that would allow to remote command execution...Show more |
A vulnerability exists allowing attackers, when present in the same network segment as ClearPass' management interface, to make changes to certain databases in ClearPass by crafting HTTP packets. As a result of this atta...Show more |
A vulnerability was found when an attacker, while communicating with the ClearPass management interface, is able to intercept and change parameters in the HTTP packets resulting in the compromise of some of ClearPass' se...Show more |
A server side injection vulnerability exists which could allow an authenticated administrative user to achieve Remote Code Execution in ClearPass. Resolution: Fixed in 6.7.13, 6.8.4, 6.9.0 and higher. |
ClearPass is vulnerable to Stored Cross Site Scripting by allowing a malicious administrator, or a compromised administrator account, to save malicious scripts within ClearPass that could be executed resulting in a privi...Show more |
The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template. |
The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field. |
1Etoilewebdesign 1Ultimate Faq Jun 17, 2026 Jan 16, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php. |
5Cacti DebianFedoraproject+2 more7Backports Sle CactiDebian Linux+4 moreJun 17, 2026 Jan 16, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in dat...Show more |
3Debian FedoraprojectRedislabs3Debian Linux FedoraHiredisJun 17, 2026 Jan 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked. |
The chained-quiz plugin 1.1.8.1 for WordPress has reflected XSS via the wp-admin/admin-ajax.php total_questions parameter. |
1Autodesk 1Fbx Software Development Kit Jun 17, 2026 Apr 17, 2020 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 A heap overflow vulnerability in the Autodesk FBX-SDK versions 2019.2 and earlier may lead to arbitrary code execution on a system running it. |
1Autodesk 1Fbx Software Development Kit Jun 17, 2026 Apr 17, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A NULL pointer dereference vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to denial of service of the application. |
1Autodesk 1Fbx Software Development Kit Jun 17, 2026 Apr 17, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An intager overflow vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to denial of service of the application. |
1Autodesk 1Fbx Software Development Kit Jun 17, 2026 Apr 17, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A use-after-free vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to code execution on a system running it. |