netapp
2,510 tracked vulnerabilities.
CVE-2025-26465
MEDIUM
OpenSSH 6.9-9.7 - Machine-in-the-Middle Attack via VerifyHostKeyDNS Error Handling
Feb 18, 2025
CVSS 6.8
EPSS 0.65
CVE-2025-26511
HIGH
Instaclustr Cassandra-Lucene-Index Plugin 4.0-rc1-1.0.0-4.0.16-1.0.0 & 4.1.2-1.0.0-4.1.8-1.0.0 Privilege Escalation
Feb 13, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-1215
LOW
vim < 9.1.1097 - Memory Corruption via --log Argument
Feb 12, 2025
CVSS 2.8
EPSS 0.00
CVE-2025-1181
MEDIUM
GNU Binutils 2.43 - Memory Corruption in _bfd_elf_gc_mark_rsec
Feb 11, 2025
CVSS 5.0
EPSS 0.00
CVE-2025-1178
MEDIUM
GNU Binutils 2.43 - Memory Corruption in bfd_putl64 Function
Feb 11, 2025
CVSS 5.6
EPSS 0.00
CVE-2025-24970
HIGH
Netty <4.1.118.Final - Buffer Overflow
Feb 10, 2025
CVSS 7.5
EPSS 0.01
CVE-2025-0725
HIGH
libcurl <1.2.0.3 - Buffer Overflow
Feb 05, 2025
CVSS 7.3
EPSS 0.01
CVE-2025-0665
HIGH
curl - Eventfd File Descriptor Double Close in Connection Channel Teardown
Feb 05, 2025
CVSS 7.0
EPSS 0.05
CVE-2025-0167
LOW
curl 7.76.0-8.11.0 - Credential Leak via .netrc Default Entry
Feb 05, 2025
CVSS 3.4
EPSS 0.00
CVE-2025-0509
HIGH
Sparkle < 2.6.4 - Unauthenticated Update Replacement via Signature Bypass
Feb 04, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-0411
HIGH
KEV
7-Zip 24.09 - Mark-of-the-Web Bypass Code Execution
Jan 25, 2025
CVSS 7.0
EPSS 0.47
CVE-2025-21502
MEDIUM
Oracle GraalVM - Incorrect Authorization
Jan 21, 2025
CVSS 4.8
EPSS 0.00
CVE-2025-21492
MEDIUM
MySQL Server 8.0.0-8.0.36 and 8.4.0 - Authenticated Denial of Service in Optimizer
Jan 21, 2025
CVSS 4.9
EPSS 0.00
CVE-2025-24014
MEDIUM
Vim < 9.1.1043 - Out-of-bounds Write via Silent Ex Mode Binary Character Handling
Jan 20, 2025
CVSS 4.2
EPSS 0.00
CVE-2025-22134
MEDIUM
vim < 9.1.1003 - Heap-based Buffer Overflow via :all Command in Visual Mode
Jan 13, 2025
CVSS 4.2
EPSS 0.00
CVE-2024-54085
CRITICAL
KEV
AMI MegaRAC SP-X 12-12.7 - Unauthenticated Authentication Bypass via Redfish Host Interface
Mar 11, 2025
CVSS 9.8
EPSS 0.43
CVE-2024-56171
HIGH
libxml2 < 2.12.10 and 2.13.x < 2.13.6 - Use-After-Free in xmlSchemaIDCFillNodeTables
Feb 18, 2025
CVSS 7.8
EPSS 0.00
CVE-2024-40896
CRITICAL
libxml2 2.11.0-2.11.8, 2.12.0-2.12.8, 2.13.0-2.13.2 - XML External Entity Injection via SAX Parser
Dec 23, 2024
CVSS 9.1
EPSS 0.01
CVE-2024-56337
CRITICAL
Apache Tomcat 9.0.0-9.0.97, 10.1.0-M1-10.1.33, 11.0.0-M1-11.0.1 - Time-of-check Time-of-use Race Condition
Dec 20, 2024
CVSS 9.8
EPSS 0.13
CVE-2024-53580
HIGH
iperf3 3.17.1 - NULL Pointer Dereference in iperf_exchange_parameters()
Dec 18, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-54677
MEDIUM
Apache Tomcat 8.5.0-8.5.100, 9.0.0.M1-9.0.97, 10.1.0-M1-10.1.33, 11.0.0-M1-11.0.1 - DoS via Examples Web App
Dec 17, 2024
CVSS 5.3
EPSS 0.01
CVE-2024-50379
CRITICAL
Apache Tomcat 9.0.0-9.0.97, 10.1.0-M1-10.1.33, 11.0.0-M1-11.0.1 - RCE via TOCTOU Race Condition in JSP Compilation
Dec 17, 2024
CVSS 9.8
EPSS 0.85
CVE-2024-11053
LOW
curl 7.76.0-8.11.1 - Credential Leak via .netrc File and HTTP Redirect
Dec 11, 2024
CVSS 3.4
EPSS 0.01
CVE-2024-8932
CRITICAL
PHP 8.1.0-8.1.30, 8.2.0-8.2.25, 8.3.0-8.3.13 - Out-of-bounds Write via ldap_escape() Integer Overflow
Nov 22, 2024
CVSS 9.8
EPSS 0.00
CVE-2024-3447
MEDIUM
QEMU - Heap-based Buffer Overflow in SDHCI Device Emulation
Nov 14, 2024
CVSS 6.0
EPSS 0.00
Products
oncommand_insight 971
active_iq_unified_manager 848
oncommand_workflow_automation 743
snapcenter 575
cloud_backup 345
h700s_firmware 289
h300s_firmware 288
h410s_firmware 288
h500s_firmware 288
e-series_santricity_os_controller 242
h410c_firmware 236
steelstore_cloud_integrated_storage 211
solidfire 192
clustered_data_ontap 187
hci_management_node 182
snapmanager 180
ontap_select_deploy_administration_utility 179
oncommand_unified_manager 169
h700e_firmware 149
h300e_firmware 148
h500e_firmware 148
e-series_santricity_storage_manager 140
storage_automation_store 113
solidfire_\&_hci_management_node 103
element_software 100
e-series_santricity_web_services 99
oncommand_balance 83
santricity_unified_manager 77
7-mode_transition_tool 75
oncommand_performance_manager 73
Quick Filters