CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Arubanetworks
1Airwave Glass
Jun 17, 2026
Nov 4, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
1Arubanetworks
1Airwave Glass
Jun 17, 2026
Oct 26, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
1Arubanetworks
1Airwave Glass
Jun 17, 2026
Oct 26, 2020
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
A remote server-side request forgery (ssrf) vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
1Arubanetworks
1Airwave Glass
Jun 17, 2026
Oct 26, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A remote escalation of privilege vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
1Arubanetworks
1Airwave Glass
Jun 17, 2026
Oct 26, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A remote unauthorized access vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
1Arubanetworks
6Cx 6200f Firmware
Cx 6300 FirmwareCx 6400 Firmware+3 more
Jun 17, 2026
Sep 23, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been found. Successful exploitation of these vulnerabilities could result in Local Denial of Service of t...Show more
Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been found. Successful exploitation of these vulnerabilities could result in Local Denial of Service of the CDP (Cisco Discovery Protocol) process in the switch. This applies to firmware versions prior to 10.04.1000.Show less
1Arubanetworks
6Cx 6200f Firmware
Cx 6300 FirmwareCx 6400 Firmware+3 more
Jun 17, 2026
Sep 23, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been found. Successful exploitation of these vulnerabilities could result in Local Denial of Service of t...Show more
Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been found. Successful exploitation of these vulnerabilities could result in Local Denial of Service of the LLDP (Link Layer Discovery Protocol) process in the switch. This applies to firmware versions prior to 10.04.3021.Show less
1Arubanetworks
1Analytics And Location Engine
Jun 17, 2026
Sep 4, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability exists in the Aruba Analytics and Location Engine (ALE) web management interface 2.1.0.2 and earlier firmware that allows an already authenticated administrative user to arbitrarily modify files as an und...Show more
A vulnerability exists in the Aruba Analytics and Location Engine (ALE) web management interface 2.1.0.2 and earlier firmware that allows an already authenticated administrative user to arbitrarily modify files as an underlying privileged operating system user.Show less
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Jun 3, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the attacker is already authenticated to the administrative interface, they could then exploit the system, l...Show more
The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the attacker is already authenticated to the administrative interface, they could then exploit the system, leading to remote command execution in the underlying operating system. Resolution: Fixed in 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 and higher.Show less
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Jun 3, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the attacker is already authenticated to the administrative interface, they could then exploit the system, l...Show more
The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the attacker is already authenticated to the administrative interface, they could then exploit the system, leading to remote command execution in the underlying operating system. Resolution: Fixed in 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 and higher.Show less
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Jun 3, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker could then execute an exploit that would allow to remote command execution...Show more
The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker could then execute an exploit that would allow to remote command execution in the underlying operating system. Resolution: Fixed in 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 and higher.Show less
1Arubanetworks
1Clearpass
Jun 17, 2026
Apr 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability exists allowing attackers, when present in the same network segment as ClearPass' management interface, to make changes to certain databases in ClearPass by crafting HTTP packets. As a result of this atta...Show more
A vulnerability exists allowing attackers, when present in the same network segment as ClearPass' management interface, to make changes to certain databases in ClearPass by crafting HTTP packets. As a result of this attack, a possible complete cluster compromise might occur. Resolution: Fixed in 6.7.13, 6.8.4, 6.9.0 and higher.Show less
1Arubanetworks
1Clearpass
Jun 17, 2026
Apr 16, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found when an attacker, while communicating with the ClearPass management interface, is able to intercept and change parameters in the HTTP packets resulting in the compromise of some of ClearPass' se...Show more
A vulnerability was found when an attacker, while communicating with the ClearPass management interface, is able to intercept and change parameters in the HTTP packets resulting in the compromise of some of ClearPass' service accounts. Resolution: Fixed in 6.7.10, 6.8.1, 6.9.0 and higher.Show less
1Arubanetworks
1Clearpass
Jun 17, 2026
Apr 16, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A server side injection vulnerability exists which could allow an authenticated administrative user to achieve Remote Code Execution in ClearPass. Resolution: Fixed in 6.7.13, 6.8.4, 6.9.0 and higher.
1Arubanetworks
1Clearpass
Jun 17, 2026
Apr 16, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
ClearPass is vulnerable to Stored Cross Site Scripting by allowing a malicious administrator, or a compromised administrator account, to save malicious scripts within ClearPass that could be executed resulting in a privi...Show more
ClearPass is vulnerable to Stored Cross Site Scripting by allowing a malicious administrator, or a compromised administrator account, to save malicious scripts within ClearPass that could be executed resulting in a privilege escalation attack. Resolution: Fixed in 6.7.13, 6.8.4, 6.9.0 and higher.Show less
1Elementor
1Website Builder
Jun 17, 2026
Jan 22, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.
1Learndash
1Learndash
Jun 17, 2026
Jan 16, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field.
1Etoilewebdesign
1Ultimate Faq
Jun 17, 2026
Jan 16, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.
5Cacti
DebianFedoraproject+2 more
7Backports Sle
CactiDebian Linux+4 more
Jun 17, 2026
Jan 16, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in dat...Show more
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS).Show less
3Debian
FedoraprojectRedislabs
3Debian Linux
FedoraHiredis
Jun 17, 2026
Jan 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked.
1Kibokolabs
1Chained Quiz
Jun 17, 2026
Jan 17, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The chained-quiz plugin 1.1.8.1 for WordPress has reflected XSS via the wp-admin/admin-ajax.php total_questions parameter.
1Autodesk
1Fbx Software Development Kit
Jun 17, 2026
Apr 17, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A heap overflow vulnerability in the Autodesk FBX-SDK versions 2019.2 and earlier may lead to arbitrary code execution on a system running it.
1Autodesk
1Fbx Software Development Kit
Jun 17, 2026
Apr 17, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A NULL pointer dereference vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to denial of service of the application.
1Autodesk
1Fbx Software Development Kit
Jun 17, 2026
Apr 17, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An intager overflow vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to denial of service of the application.
1Autodesk
1Fbx Software Development Kit
Jun 17, 2026
Apr 17, 2020
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
A use-after-free vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to code execution on a system running it.