2024

2023

2022

2021

2020

CVE-2020-7111 (v3: 7.2) 16 Apr 2020
A server side injection vulnerability exists which could allow an authenticated administrative user to achieve Remote Code Execution in ClearPass. Resolution: Fixed in 6.7.13, 6.8.4, 6.9.0 and higher.

2019

CVE-2019-5323 (v3: 7.2) 27 Feb 2020
There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an administrative user are not properly sanitized before being parsed by AirWave. If conditions are met, an attacker can obtain command execution on the host.

2018

CVE-2018-16417 (v3: 7.5) 30 Oct 2019
Aruba Instant 4.x prior to 6.4.4.8-4.2.4.12, 6.5.x prior to 6.5.4.11, 8.3.x prior to 8.3.0.6, and 8.4.x prior to 8.4.0.1 allows Command injection.
CVE-2018-20698 (v3: 6.1) 9 Apr 2019
The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page when basePath is set.

2017

2016

2015