netapp

2,510 tracked vulnerabilities.

CVE-2025-26465 MEDIUM
OpenSSH 6.9-9.7 - Machine-in-the-Middle Attack via VerifyHostKeyDNS Error Handling
Feb 18, 2025
CVSS 6.8
EPSS 0.65
CVE-2025-26511 HIGH
Instaclustr Cassandra-Lucene-Index Plugin 4.0-rc1-1.0.0-4.0.16-1.0.0 & 4.1.2-1.0.0-4.1.8-1.0.0 Privilege Escalation
Feb 13, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-1215 LOW
vim < 9.1.1097 - Memory Corruption via --log Argument
Feb 12, 2025
CVSS 2.8
EPSS 0.00
CVE-2025-1181 MEDIUM
GNU Binutils 2.43 - Memory Corruption in _bfd_elf_gc_mark_rsec
Feb 11, 2025
CVSS 5.0
EPSS 0.00
CVE-2025-1178 MEDIUM
GNU Binutils 2.43 - Memory Corruption in bfd_putl64 Function
Feb 11, 2025
CVSS 5.6
EPSS 0.00
CVE-2025-24970 HIGH
Netty <4.1.118.Final - Buffer Overflow
Feb 10, 2025
CVSS 7.5
EPSS 0.01
CVE-2025-0725 HIGH
libcurl <1.2.0.3 - Buffer Overflow
Feb 05, 2025
CVSS 7.3
EPSS 0.01
CVE-2025-0665 HIGH
curl - Eventfd File Descriptor Double Close in Connection Channel Teardown
Feb 05, 2025
CVSS 7.0
EPSS 0.05
CVE-2025-0167 LOW
curl 7.76.0-8.11.0 - Credential Leak via .netrc Default Entry
Feb 05, 2025
CVSS 3.4
EPSS 0.00
CVE-2025-0509 HIGH
Sparkle < 2.6.4 - Unauthenticated Update Replacement via Signature Bypass
Feb 04, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-0411 HIGH KEV
7-Zip 24.09 - Mark-of-the-Web Bypass Code Execution
Jan 25, 2025
CVSS 7.0
EPSS 0.47
CVE-2025-21502 MEDIUM
Oracle GraalVM - Incorrect Authorization
Jan 21, 2025
CVSS 4.8
EPSS 0.00
CVE-2025-21492 MEDIUM
MySQL Server 8.0.0-8.0.36 and 8.4.0 - Authenticated Denial of Service in Optimizer
Jan 21, 2025
CVSS 4.9
EPSS 0.00
CVE-2025-24014 MEDIUM
Vim < 9.1.1043 - Out-of-bounds Write via Silent Ex Mode Binary Character Handling
Jan 20, 2025
CVSS 4.2
EPSS 0.00
CVE-2025-22134 MEDIUM
vim < 9.1.1003 - Heap-based Buffer Overflow via :all Command in Visual Mode
Jan 13, 2025
CVSS 4.2
EPSS 0.00
CVE-2024-54085 CRITICAL KEV
AMI MegaRAC SP-X 12-12.7 - Unauthenticated Authentication Bypass via Redfish Host Interface
Mar 11, 2025
CVSS 9.8
EPSS 0.43
CVE-2024-56171 HIGH
libxml2 < 2.12.10 and 2.13.x < 2.13.6 - Use-After-Free in xmlSchemaIDCFillNodeTables
Feb 18, 2025
CVSS 7.8
EPSS 0.00
CVE-2024-40896 CRITICAL
libxml2 2.11.0-2.11.8, 2.12.0-2.12.8, 2.13.0-2.13.2 - XML External Entity Injection via SAX Parser
Dec 23, 2024
CVSS 9.1
EPSS 0.01
CVE-2024-56337 CRITICAL
Apache Tomcat 9.0.0-9.0.97, 10.1.0-M1-10.1.33, 11.0.0-M1-11.0.1 - Time-of-check Time-of-use Race Condition
Dec 20, 2024
CVSS 9.8
EPSS 0.13
CVE-2024-53580 HIGH
iperf3 3.17.1 - NULL Pointer Dereference in iperf_exchange_parameters()
Dec 18, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-54677 MEDIUM
Apache Tomcat 8.5.0-8.5.100, 9.0.0.M1-9.0.97, 10.1.0-M1-10.1.33, 11.0.0-M1-11.0.1 - DoS via Examples Web App
Dec 17, 2024
CVSS 5.3
EPSS 0.01
CVE-2024-50379 CRITICAL
Apache Tomcat 9.0.0-9.0.97, 10.1.0-M1-10.1.33, 11.0.0-M1-11.0.1 - RCE via TOCTOU Race Condition in JSP Compilation
Dec 17, 2024
CVSS 9.8
EPSS 0.85
CVE-2024-11053 LOW
curl 7.76.0-8.11.1 - Credential Leak via .netrc File and HTTP Redirect
Dec 11, 2024
CVSS 3.4
EPSS 0.01
CVE-2024-8932 CRITICAL
PHP 8.1.0-8.1.30, 8.2.0-8.2.25, 8.3.0-8.3.13 - Out-of-bounds Write via ldap_escape() Integer Overflow
Nov 22, 2024
CVSS 9.8
EPSS 0.00
CVE-2024-3447 MEDIUM
QEMU - Heap-based Buffer Overflow in SDHCI Device Emulation
Nov 14, 2024
CVSS 6.0
EPSS 0.00