Skip to content
Noroxi

NetApp records

2,519 published records for vendor netapp.

Researcher profile

Entered KEV
40 · 1.6%
Weaponized
52 · 2.1%
Pre-auth RCE
72
With a fix record
67.6%
Median publish → KEV
651 days

All records

2,519 records
  • Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    apache · log4jDec 10, 2021

  • The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · strutsMar 10, 2017

  • Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · http serverOct 5, 2021

  • Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · http serverOct 7, 2021

  • Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · tomcatMar 10, 2025

  • Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · activemqOct 27, 2023

  • When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    apache · geodeFeb 24, 2020

  • Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff

    CriticalCVSS 9.8KEVWeaponizedEPSS 92%

    oracle · jdkApr 21, 2016

  • A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.

    CriticalCVSS 9.0KEVWeaponizedEPSS 100%

    resf · rocky linuxSep 16, 2021

  • Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.

    CriticalCVSS 9.1KEVWeaponizedEPSS 100%

    apache · http serverJul 1, 2024

  • Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before

    CriticalCVSS 9.8KEVWeaponizedEPSS 90%

    apache · tomcatApr 6, 2017

  • Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo

    HighCVSS 8.8KEVWeaponizedEPSS 100%

    google · chromeSep 12, 2023

  • XStream is vulnerable to a Remote Command Execution attack

    HighCVSS 8.5KEVWeaponizedEPSS 98%

    xstream · xstreamAug 23, 2021

  • Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (ei

    HighCVSS 8.1KEVWeaponizedEPSS 100%

    apache · strutsAug 22, 2018

  • When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.

    HighCVSS 8.1KEVWeaponizedEPSS 100%

    apache · tomcatOct 3, 2017

  • When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.

    HighCVSS 8.1KEVWeaponizedEPSS 100%

    apache · tomcatSep 19, 2017

  • The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStrea

    HighCVSS 8.1KEVWeaponizedEPSS 99%

    apache · strutsSep 15, 2017

  • Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root

    HighCVSS 7.8KEVWeaponizedEPSS 100%

    sudo project · sudoJan 26, 2021

  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023

  • JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for

    HighCVSS 8.8KEVWeaponizedEPSS 83%

    redhat · jboss enterprise application platformAug 5, 2010

  • A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe

    HighCVSS 7.8KEVWeaponizedEPSS 93%

    linux · linux kernelMar 10, 2022

  • Redfish Authentication Bypass

    CriticalCVSS 10.0KEVWeaponizedEPSS 61%

    ami · megarac sp-xMar 11, 2025

  • Glibc: buffer overflow in ld.so leading to privilege escalation

    HighCVSS 7.8KEVWeaponizedEPSS 81%

    gnu · glibcOct 3, 2023

  • Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE

    HighCVSS 7.8KEVWeaponizedEPSS 79%

    linux · linux kernelJul 7, 2021

  • Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect ha

    HighCVSS 7.0KEVWeaponizedEPSS 84%

    linux · linux kernelNov 10, 2016