Перейти к содержимому
Noroxi

Записи netapp

2 519 опубликованных записей вендора netapp.

Профиль для исследователя

Попали в KEV
40 · 1,6 %
С эксплойтом
52 · 2,1 %
Pre-auth RCE
72
С записью об исправлении
67,6 %
Медиана: публикация → KEV
651 дн.

Записи по годам

  1. 16
  2. 17
  3. 18
  4. 19
  5. 20
  6. 21
  7. 22
  8. 23
  9. 24
  10. 25
  11. 26

Столбик: всего · тёмная часть: CISA KEV.

Повторяющиеся классы

Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

CWE

Все записи

2 519 записей
  • CVE-2021-44228
    100Срочно

    Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %

    apache · log4j10 дек. 2021 г.

  • CVE-2017-5638
    99Срочно

    The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    apache · struts10 мар. 2017 г.

  • CVE-2021-41773
    99Срочно

    Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    apache · http server5 окт. 2021 г.

  • CVE-2021-42013
    99Срочно

    Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    apache · http server7 окт. 2021 г.

  • CVE-2025-24813
    99Срочно

    Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    apache · tomcat10 мар. 2025 г.

  • CVE-2023-46604
    99Срочно

    Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    apache · activemq27 окт. 2023 г.

  • CVE-2020-1938
    99Срочно

    When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    apache · geode24 февр. 2020 г.

  • CVE-2016-3427
    97Срочно

    Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %

    oracle · jdk21 апр. 2016 г.

  • CVE-2021-40438
    96Срочно

    A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.

    КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %

    resf · rocky linux16 сент. 2021 г.

  • CVE-2024-38475
    96Срочно

    Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.

    КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 100 %

    apache · http server1 июл. 2024 г.

  • CVE-2016-8735
    96Срочно

    Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 90 %

    apache · tomcat6 апр. 2017 г.

  • CVE-2023-4863
    95Срочно

    Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 100 %

    google · chrome12 сент. 2023 г.

  • CVE-2021-39144
    93Срочно

    XStream is vulnerable to a Remote Command Execution attack

    ВысокаяCVSS 8,5KEVГотовый эксплойтEPSS 98 %

    xstream · xstream23 авг. 2021 г.

  • CVE-2018-11776
    92Срочно

    Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (ei

    ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 100 %

    apache · struts22 авг. 2018 г.

  • CVE-2017-12617
    92Срочно

    When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.

    ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 100 %

    apache · tomcat3 окт. 2017 г.

  • CVE-2017-12615
    92Срочно

    When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.

    ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 100 %

    apache · tomcat19 сент. 2017 г.

  • CVE-2017-9805
    92Срочно

    The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStrea

    ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 99 %

    apache · struts15 сент. 2017 г.

  • CVE-2021-3156
    91Срочно

    Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 100 %

    sudo project · sudo26 янв. 2021 г.

  • CVE-2023-44487
    90Срочно

    The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 окт. 2023 г.

  • CVE-2010-1871
    90Срочно

    JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 83 %

    redhat · jboss enterprise application platform5 авг. 2010 г.

  • CVE-2022-0847
    89Срочно

    A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 93 %

    linux · linux kernel10 мар. 2022 г.

  • CVE-2024-54085
    88Срочно

    Redfish Authentication Bypass

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 61 %

    ami · megarac sp-x11 мар. 2025 г.

  • CVE-2023-4911
    85Срочно

    Glibc: buffer overflow in ld.so leading to privilege escalation

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 81 %

    gnu · glibc3 окт. 2023 г.

  • CVE-2021-22555
    85Срочно

    Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 79 %

    linux · linux kernel7 июл. 2021 г.

  • CVE-2016-5195
    83Срочно

    Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect ha

    ВысокаяCVSS 7,0KEVГотовый эксплойтEPSS 84 %

    linux · linux kernel10 нояб. 2016 г.