Vulnerabilities
Summary — last 7 days
New vulnerabilities3,338▲ 363 vs. last week
Critical / high1,493▲ 135 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 119 vs. last week
853 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (6.8) | 0.50% | — | Oracle Mysql ClusterOracle Mysql ClientNetapp Active IQ Unified ManagerNetapp Snapcenter | 4/15/2025 | 6/17/2026 | Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client.… | |
| Analyzed | Medium (5.3) | 1.3% | — | Apache POINetapp Active IQ Unified Manager | 4/9/2025 | 6/17/2026 | Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to add zip entries with duplicate names (including the path) in the zip. In this case, products reading… | |
| Modified | High (7.7) | 0.39% | — | Netapp Active IQ Unified ManagerNetapp Manageability Software Development KITNetapp OntapNetapp Solidfire & HCI Management Node+7 | 2/18/2025 | 6/17/2026 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047. | |
| Modified | Critical (9.8) | 1.2% | — | Xmlsoft Libxml2Netapp HCI Compute NodeNetapp H410c FirmwareNetapp H300s Firmware+7 | 2/18/2025 | 6/17/2026 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used. | |
| Modified | Medium (6.8) | 7.7% | — | Openbsd OpensshNetapp Active IQ Unified ManagerNetapp OntapRedhat Openshift Container Platform+2 | 2/18/2025 | 9/2/2026 | A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be… | |
| Analyzed | Low (2.3) | 0.72% | — | GNU BinutilsNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility | 2/11/2025 | 6/17/2026 | A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The… | |
| Analyzed | Medium (6.3) | 0.80% | — | GNU BinutilsNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility | 2/11/2025 | 6/17/2026 | A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The… | |
| Analyzed | High (7.5) | 2.2% | — | NettyNetapp Active IQ Unified ManagerNetapp Oncommand Insight | 2/10/2025 | 6/17/2026 | Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash.… | |
| Analyzed | High (7) | 67% | ⚠ Active exploitation | Netapp Active IQ Unified Manager7-zip | 1/25/2025 | 6/17/2026 | 7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific… | |
| Analyzed | Medium (4.8) | 1.0% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+7 | 1/21/2025 | 6/17/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf, 11.0.25, 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM for JDK: 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM… | |
| Analyzed | Medium (4.9) | 0.96% | — | Oracle Mysql ServerNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation | 1/21/2025 | 6/17/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 and prior and 8.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of… | |
| Analyzed | Critical (9.8) | 1.3% | — | Gnome GlibDebian LinuxNetapp Active IQ Unified ManagerNetapp Ontap Tools | 11/11/2024 | 6/17/2026 | gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character. | |
| Analyzed | Medium (5.9) | 1.0% | — | Netapp Active IQ Unified ManagerNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage NodeNetapp Windows Host Utilities+8 | 10/27/2024 | 6/17/2026 | An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser. | |
| Modified | High (7.5) | 0.94% | — | Eclipse JettyNetapp Bootstrap OSNetapp Active IQ Unified Manager | 10/14/2024 | 6/17/2026 | There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory finally. | |
| Analyzed | Medium (4.3) | 1.3% | — | Apache Commons IONetapp Active IQ Unified ManagerNetapp BluexpNetapp E-series Santricity Unified Manager+4 | 10/3/2024 | 6/17/2026 | Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0… | |
| Analyzed | Critical (9.2) | 3.3% | — | Apache AvroNetapp Active IQ Unified ManagerNetapp Brocade SAN Navigator | 10/3/2024 | 6/17/2026 | Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgrade to version 1.11.4 or 1.12.0, which fix this issue. | |
| Analyzed | High (8.7) | 2.8% | — | Google ProtobufGoogle Protobuf-javaGoogle Protobuf-javaliteGoogle Protobuf-kotlin+4 | 9/19/2024 | 6/17/2026 | Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map… | |
| Analyzed | Medium (6.5) | 0.73% | — | Haxx CurlDebian LinuxNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+6 | 9/11/2024 | 6/17/2026 | When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for… | |
| Modified | Medium (4.3) | 0.64% | — | AngularjsNetapp Active IQ Unified Manager | 9/9/2024 | 6/17/2026 | Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects all versions of AngularJS.… | |
| Modified | Medium (4.3) | 0.61% | — | AngularjsNetapp Active IQ Unified Manager | 9/9/2024 | 6/17/2026 | Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and greater. Note: The… | |
| Modified | High (7.5) | 67% | — | OpensslNetapp Active IQ Unified ManagerManagement Services FOR Element Software AND Netapp HCINetapp Ontap 9+15 | 9/3/2024 | 6/17/2026 | Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service.… | |
| Analyzed | Medium (4.3) | 0.57% | — | Vmware Spring FrameworkNetapp Active IQ Unified ManagerNetapp Oncommand Insight | 8/20/2024 | 6/17/2026 | In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true: | |
| Analyzed | High (7.4) | 1.1% | — | Netapp Active IQ Unified ManagerNetapp BluexpNetapp Data Infrastructure Insights Storage Workload Security AgentNetapp Oncommand Insight+6 | 7/16/2024 | 6/17/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM… | |
| Analyzed | Medium (4.8) | 0.94% | — | Netapp Active IQ Unified ManagerNetapp BluexpNetapp Data Infrastructure Insights Storage Workload Security AgentNetapp Oncommand Insight+6 | 7/16/2024 | 6/17/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM… | |
| Analyzed | Low (3.7) | 1.3% | — | Netapp Active IQ Unified ManagerNetapp BluexpNetapp Data Infrastructure Insights Storage Workload Security AgentNetapp Oncommand Insight+5 | 7/16/2024 | 6/17/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM… |