Vulnerabilities

Summary — last 7 days

New vulnerabilities3,332▲ 359 vs. last week
Critical / high1,490▲ 132 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 120 vs. last week
–

106 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedHigh (7.1)22%—VIMNetapp HCI Compute Node3/3/20256/17/2026
Vim is an open source, command line text editor. Vim is distributed with the tar.vim plugin, that allows easy editing and viewing of (compressed or uncompressed) tar files. Starting with 9.1.0858, the tar.vim plugin uses the ":read" ex command line to append below the cursor position, however the is not sanitized and…
ModifiedHigh (7.7)0.39%—Netapp Active IQ Unified ManagerNetapp Manageability Software Development KITNetapp OntapNetapp Solidfire & HCI Management Node+72/18/20256/17/2026
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.
ModifiedCritical (9.8)1.2%—Xmlsoft Libxml2Netapp HCI Compute NodeNetapp H410c FirmwareNetapp H300s Firmware+72/18/20256/17/2026
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.
AnalyzedMedium (4.2)0.24%—VIMNetapp HCI Compute Node2/18/20256/17/2026
Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages using the `:redir` ex command to register, variables and files. It also allows to show the contents of registers using the `:registers` or `:display` ex command. When redirecting the output of `:display` to a…
AnalyzedMedium (6.8)0.90%—Sparkle-project SparkleNetapp HCI Compute NodeNetapp Oncommand Workflow Automation2/4/20256/17/2026
A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.
AnalyzedMedium (5.5)0.28%—VIMNetapp HCI Compute Node Firmware1/20/20256/17/2026
Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mode (-s -e), Vim typically doesn't show a screen and just operates silently in batch mode. However, it is still possible to trigger the function that handles the scrolling of a gui version of Vim by…
AnalyzedCritical (9.1)1.2%—Xmlsoft Libxml2Netapp HCI Compute NodeNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage Node+512/23/20246/17/2026
In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.
ModifiedHigh (7.5)0.92%—ES Iperf3Netapp Ontap 9Netapp HCI Compute Node12/18/20246/17/2026
iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
ModifiedMedium (6)0.55%—QemuNetapp HCI Compute Node11/14/20246/17/2026
A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_count` and the size of `s->fifo_buffer` are set to 0x200, leading to an out-of-bound access. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of…
AnalyzedMedium (5.9)1.0%—Netapp Active IQ Unified ManagerNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage NodeNetapp Windows Host Utilities+810/27/20246/17/2026
An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.
AnalyzedMedium (4.2)0.33%—Netapp HCI Compute NodeNeovimVIM8/1/20249/17/2026
Vim is an open source command line text editor. double-free in dialog_changed() in Vim < v9.1.0648. When abandoning a buffer, Vim may ask the user what to do with the modified buffer. If the user wants the changed buffer to be saved, Vim may create a new Untitled file, if the buffer did not have a name yet. However,…
ModifiedMedium (5.5)0.50%—Linux KernelNetapp Converged Systems Advisor AgentNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage Node+65/30/20248/4/2026
In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix nfsd4_encode_fattr4() crasher Ensure that args.acl is initialized early. It is used in an unconditional call to kfree() on the way out of nfsd4_encode_fattr4().
AnalyzedMedium (6.7)0.37%—Intel TDX ModuleNetapp HCI Compute Node Bios5/16/20248/31/2026
Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.
AnalyzedHigh (8.2)0.38%—Intel TDX ModuleNetapp HCI Compute Node Bios5/16/20248/31/2026
Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.
Undergoing AnalysisHigh (7.3)88%—GNU GlibcNetapp Active IQ Unified ManagerDebian LinuxNetapp HCI H300s Firmware+94/17/20246/17/2026
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
AnalyzedMedium (4.9)0.69%—Intel Server Platform ServicesNetapp HCI Bootstrap OSNetapp HCI Compute Node Bios2/14/20246/17/2026
Uncontrolled resource consumption for some Intel(R) SPS firmware before version SPS_E5_06.01.04.002.0 may allow a privileged user to potentially enable denial of service via network access.
AnalyzedMedium (4.7)0.54%—Fedoraproject FedoraNetapp HCI Compute NodeNeovimVIM11/22/20239/17/2026
Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a `:s` command for the very first time and using a sub-replace-special atom inside the substitution part, it is possible that the recursive `:s` call causes free-ing of memory which may later then be accessed…
AnalyzedHigh (7.8)0.57%—Apple MacosNetapp HCI Compute NodeNeovimVIM+11/4/20239/24/2026
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.
ModifiedHigh (7.5)2.5%—Libexpat Project LibexpatDebian LinuxFedoraproject FedoraNetapp H300s Firmware+810/24/20226/17/2026
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
ModifiedCritical (9.8)19%—ZlibFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+148/5/20227/14/2026
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the…
ModifiedHigh (7.5)7.6%—Linux KernelDebian LinuxNetapp Active IQ Unified ManagerNetapp Solidfire & HCI Management Node+37/27/20226/17/2026
nfqnl_mangle in net/netfilter/nfnetlink_queue.c in the Linux kernel through 5.18.14 allows remote attackers to cause a denial of service (panic) because, in the case of an nf_queue verdict with a one-byte nfta_payload attribute, an skb_pull can encounter a negative skb->len.
ModifiedMedium (5.3)2.4%—Oracle GraalvmOracle JDKOracle JREAzul Zulu+107/19/20226/17/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17.0.3.1; Oracle GraalVM Enterprise Edition: 21.3.2 and 22.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network…
ModifiedMedium (5.9)2.7%—Oracle GraalvmOracle JDKOracle JREOracle Openjdk+117/19/20226/17/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1, 18.0.1.1; Oracle GraalVM Enterprise Edition: 20.3.6, 21.3.2 and 22.1.0. Difficult to exploit vulnerability…
ModifiedMedium (5.3)3.9%—Oracle GraalvmOracle JDKOracle JREOracle Openjdk+117/19/20226/17/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1, 18.0.1.1; Oracle GraalVM Enterprise Edition: 20.3.6, 21.3.2 and 22.1.0. Easily exploitable vulnerability…
ModifiedHigh (7.5)81%—Apache Xalan-javaDebian LinuxOracle GraalvmOracle JDK+127/19/20226/17/2026
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java…