NetApp records
2,519 published records for vendor netapp.
Researcher profile
- Entered KEV
- 40 · 1.6%
- Weaponized
- 52 · 2.1%
- Pre-auth RCE
- 72
- With a fix record
- 67.6%
- Median publish → KEV
- 651 days
Recurring classes
- CWE-416 Use After Free111
- CWE-125 Out-of-bounds Read93
- CWE-787 Out-of-bounds Write90
- CWE-476 NULL Pointer Dereference78
- CWE-400 Uncontrolled Resource Consumption72
- CWE-20 Improper Input Validation68
The weakness classes this vendor ships most often: where to look.
CWEAll records
2,519 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2021-44228Weaponized | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Critical10.0 | KEV | 100.0% | Dec 10, 2021 |
99Now | CVE-2017-5638Weaponized | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mesapache · struts · CWE-755 | Critical9.8 | KEV | 100.0% | Mar 10, 2017 |
99Now | CVE-2021-41773Weaponized | Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49apache · http server · CWE-22 | Critical9.8 | KEV | 100.0% | Oct 5, 2021 |
99Now | CVE-2021-42013Weaponized | Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)apache · http server · CWE-22 | Critical9.8 | KEV | 100.0% | Oct 7, 2021 |
99Now | CVE-2025-24813Weaponized | Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUTapache · tomcat · CWE-44 | Critical9.8 | KEV | 99.9% | Mar 10, 2025 |
99Now | CVE-2023-46604Weaponized | Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attackapache · activemq · CWE-502 | Critical9.8 | KEV | 99.9% | Oct 27, 2023 |
99Now | CVE-2020-1938Weaponized | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.apache · geode | Critical9.8 | KEV | 99.3% | Feb 24, 2020 |
97Now | CVE-2016-3427Weaponized | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to afforacle · jdk · CWE-284 | Critical9.8 | KEV | 92.3% | Apr 21, 2016 |
96Now | CVE-2021-40438Weaponized | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.resf · rocky linux · CWE-918 | Critical9.0 | KEV | 100.0% | Sep 16, 2021 |
96Now | CVE-2024-38475Weaponized | Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.apache · http server · CWE-116 | Critical9.1 | KEV | 100.0% | Jul 1, 2024 |
96Now | CVE-2016-8735Weaponized | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x beforeapache · tomcat | Critical9.8 | KEV | 90.3% | Apr 6, 2017 |
95Now | CVE-2023-4863Weaponized | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bogoogle · chrome · CWE-787 | High8.8 | KEV | 100.0% | Sep 12, 2023 |
93Now | CVE-2021-39144Weaponized | XStream is vulnerable to a Remote Command Execution attackxstream · xstream · CWE-94 | High8.5 | KEV | 98.1% | Aug 23, 2021 |
92Now | CVE-2018-11776Weaponized | Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (eiapache · struts | High8.1 | KEV | 100.0% | Aug 22, 2018 |
92Now | CVE-2017-12617Weaponized | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.apache · tomcat · CWE-434 | High8.1 | KEV | 100.0% | Oct 3, 2017 |
92Now | CVE-2017-12615Weaponized | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.apache · tomcat · CWE-434 | High8.1 | KEV | 99.6% | Sep 19, 2017 |
92Now | CVE-2017-9805Weaponized | The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStreaapache · struts · CWE-502 | High8.1 | KEV | 99.4% | Sep 15, 2017 |
91Now | CVE-2021-3156Weaponized | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root sudo project · sudo · CWE-193 | High7.8 | KEV | 100.0% | Jan 26, 2021 |
90Now | CVE-2023-44487Weaponized | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | High7.5 | KEV | 100.0% | Oct 10, 2023 |
90Now | CVE-2010-1871Weaponized | JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for redhat · jboss enterprise application platform · CWE-917 | High8.8 | KEV | 83.4% | Aug 5, 2010 |
89Now | CVE-2022-0847Weaponized | A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe linux · linux kernel · CWE-665 | High7.8 | KEV | 92.8% | Mar 10, 2022 |
88Now | CVE-2024-54085Weaponized | Redfish Authentication Bypassami · megarac sp-x · CWE-290 | Critical10.0 | KEV | 60.7% | Mar 11, 2025 |
85Now | CVE-2023-4911Weaponized | Glibc: buffer overflow in ld.so leading to privilege escalationgnu · glibc · CWE-122 | High7.8 | KEV | 81.4% | Oct 3, 2023 |
85Now | CVE-2021-22555Weaponized | Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACElinux · linux kernel · CWE-787 | High7.8 | KEV | 78.7% | Jul 7, 2021 |
83Now | CVE-2016-5195Weaponized | Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect halinux · linux kernel · CWE-362 | High7.0 | KEV | 83.5% | Nov 10, 2016 |
- CVE-2021-44228100Now
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
CriticalCVSS 10.0KEVWeaponizedEPSS 100%apache · log4jDec 10, 2021
- CVE-2017-563899Now
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · strutsMar 10, 2017
- CVE-2021-4177399Now
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · http serverOct 5, 2021
- CVE-2021-4201399Now
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · http serverOct 7, 2021
- CVE-2025-2481399Now
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · tomcatMar 10, 2025
- CVE-2023-4660499Now
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · activemqOct 27, 2023
- CVE-2020-193899Now
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.
CriticalCVSS 9.8KEVWeaponizedEPSS 99%apache · geodeFeb 24, 2020
- CVE-2016-342797Now
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff
CriticalCVSS 9.8KEVWeaponizedEPSS 92%oracle · jdkApr 21, 2016
- CVE-2021-4043896Now
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
CriticalCVSS 9.0KEVWeaponizedEPSS 100%resf · rocky linuxSep 16, 2021
- CVE-2024-3847596Now
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
CriticalCVSS 9.1KEVWeaponizedEPSS 100%apache · http serverJul 1, 2024
- CVE-2016-873596Now
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before
CriticalCVSS 9.8KEVWeaponizedEPSS 90%apache · tomcatApr 6, 2017
- CVE-2023-486395Now
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo
HighCVSS 8.8KEVWeaponizedEPSS 100%google · chromeSep 12, 2023
- CVE-2021-3914493Now
XStream is vulnerable to a Remote Command Execution attack
HighCVSS 8.5KEVWeaponizedEPSS 98%xstream · xstreamAug 23, 2021
- CVE-2018-1177692Now
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (ei
HighCVSS 8.1KEVWeaponizedEPSS 100%apache · strutsAug 22, 2018
- CVE-2017-1261792Now
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.
HighCVSS 8.1KEVWeaponizedEPSS 100%apache · tomcatOct 3, 2017
- CVE-2017-1261592Now
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.
HighCVSS 8.1KEVWeaponizedEPSS 100%apache · tomcatSep 19, 2017
- CVE-2017-980592Now
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStrea
HighCVSS 8.1KEVWeaponizedEPSS 99%apache · strutsSep 15, 2017
- CVE-2021-315691Now
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root
HighCVSS 7.8KEVWeaponizedEPSS 100%sudo project · sudoJan 26, 2021
- CVE-2023-4448790Now
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
HighCVSS 7.5KEVWeaponizedEPSS 100%siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023
- CVE-2010-187190Now
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for
HighCVSS 8.8KEVWeaponizedEPSS 83%redhat · jboss enterprise application platformAug 5, 2010
- CVE-2022-084789Now
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe
HighCVSS 7.8KEVWeaponizedEPSS 93%linux · linux kernelMar 10, 2022
- CVE-2024-5408588Now
Redfish Authentication Bypass
CriticalCVSS 10.0KEVWeaponizedEPSS 61%ami · megarac sp-xMar 11, 2025
- CVE-2023-491185Now
Glibc: buffer overflow in ld.so leading to privilege escalation
HighCVSS 7.8KEVWeaponizedEPSS 81%gnu · glibcOct 3, 2023
- CVE-2021-2255585Now
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
HighCVSS 7.8KEVWeaponizedEPSS 79%linux · linux kernelJul 7, 2021
- CVE-2016-519583Now
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect ha
HighCVSS 7.0KEVWeaponizedEPSS 84%linux · linux kernelNov 10, 2016