Netapp
Netapp Active IQ Unified Manager: vulnerabilidades y CVE
Netapp Active IQ Unified Manager tiene 848 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 55 son críticas y 9 figuran en el catálogo de explotación activa de CISA.
CVE848
Últimos 12 meses0
Críticas55
Explotadas activamente9
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-0411 | Alta (7) | 67% | ⚠ Explotación activa | 25 ene 2025 | 7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this… |
| CVE-2020-11023 | Media (6.1) | 85% | ⚠ Explotación activa | 29 abr 2020 | In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e.… |
| CVE-2023-41993 | Alta (8.8) | 24% | ⚠ Explotación activa | 21 sept 2023 | The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively… |
| CVE-2023-4863 | Alta (8.8) | 100% | ⚠ Explotación activa | 12 sept 2023 | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity:… |
| CVE-2021-3156 | Alta (7.8) | 100% | ⚠ Explotación activa | 26 ene 2021 | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash… |
| CVE-2017-12617 | Alta (8.1) | 100% | ⚠ Explotación activa | 4 oct 2017 | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to… |
| CVE-2019-13272 | Alta (7.8) | 52% | ⚠ Explotación activa | 17 jul 2019 | In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by… |
| CVE-2021-44228 | Crítica (10) | 100% | ⚠ Explotación activa | 10 dic 2021 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other… |
| CVE-2018-11776 | Alta (8.1) | 100% | ⚠ Explotación activa | 22 ago 2018 | Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-30722 | Media (6.8) | 0.50% | — | 15 abr 2025 | Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Difficult to exploit vulnerability allows low… |
| CVE-2025-31672 | Media (5.3) | 1.3% | — | 9 abr 2025 | Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to… |
| CVE-2025-24928 | Alta (7.7) | 0.39% | — | 18 feb 2025 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is… |
| CVE-2024-56171 | Crítica (9.8) | 1.2% | — | 18 feb 2025 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an… |
| CVE-2025-26465 | Media (6.8) | 7.7% | — | 18 feb 2025 | A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH… |
| CVE-2025-1181 | Baja (2.3) | 0.72% | — | 11 feb 2025 | A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory… |
| CVE-2025-1178 | Media (6.3) | 0.80% | — | 11 feb 2025 | A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory… |
| CVE-2025-24970 | Alta (7.5) | 2.2% | — | 10 feb 2025 | Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it… |
| CVE-2025-0411 | Alta (7) | 67% | ⚠ Explotación activa | 25 ene 2025 | 7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this… |
| CVE-2025-21502 | Media (4.8) | 1.0% | — | 21 ene 2025 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf,… |
| CVE-2025-21492 | Media (4.9) | 0.96% | — | 21 ene 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 and prior and 8.4.0. Easily exploitable vulnerability allows high privileged… |
| CVE-2024-52533 | Crítica (9.8) | 1.3% | — | 11 nov 2024 | gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character. |
| CVE-2024-50602 | Media (5.9) | 1.0% | — | 27 oct 2024 | An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser. |
| CVE-2024-9823 | Alta (7.5) | 0.94% | — | 14 oct 2024 | There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted… |
| CVE-2024-47554 | Media (4.3) | 1.3% | — | 3 oct 2024 | Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue… |
| CVE-2024-47561 | Crítica (9.2) | 3.3% | — | 3 oct 2024 | Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgrade to version 1.11.4 or 1.12.0, which fix this issue. |
| CVE-2024-7254 | Alta (8.7) | 2.8% | — | 19 sept 2024 | Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as… |
| CVE-2024-8096 | Media (6.5) | 0.73% | — | 11 sept 2024 | When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly… |
| CVE-2024-8373 | Media (4.3) | 0.64% | — | 9 sept 2024 | Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing… |
| CVE-2024-8372 | Media (4.3) | 0.61% | — | 9 sept 2024 | Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing… |
| CVE-2024-6119 | Alta (7.5) | 67% | — | 3 sept 2024 | Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process.… |
| CVE-2024-38808 | Media (4.3) | 0.57% | — | 20 ago 2024 | In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS)… |
| CVE-2024-21147 | Alta (7.4) | 1.1% | — | 16 jul 2024 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf,… |
| CVE-2024-21140 | Media (4.8) | 0.94% | — | 16 jul 2024 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf,… |
| CVE-2024-21138 | Baja (3.7) | 1.3% | — | 16 jul 2024 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf,… |
| CVE-2024-21131 | Baja (3.7) | 1.0% | — | 16 jul 2024 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf,… |
| CVE-2024-6387 | Alta (8.1) | 100% | — | 1 jul 2024 | A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able… |
| CVE-2024-37891 | Media (6.5) | 1.1% | — | 17 jun 2024 | urllib3 is a user-friendly HTTP client library for Python. When using urllib3's proxy support with `ProxyManager`, the `Proxy-Authorization` header is only sent to the configured proxy, as expected. However, when… |
| CVE-2024-33600 | Media (5.9) | 1.2% | — | 6 may 2024 | nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache fails to add a not-found netgroup response to the cache, the client request can result in a null pointer dereference.… |
| CVE-2024-2961 | Alta (7.3) | 88% | — | 17 abr 2024 | The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.