Записи netapp
2 519 опубликованных записей вендора netapp.
Профиль для исследователя
- Попали в KEV
- 40 · 1,6 %
- С эксплойтом
- 52 · 2,1 %
- Pre-auth RCE
- 72
- С записью об исправлении
- 67,6 %
- Медиана: публикация → KEV
- 651 дн.
Повторяющиеся классы
- CWE-416 Use After Free111
- CWE-125 Out-of-bounds Read93
- CWE-787 Out-of-bounds Write90
- CWE-476 NULL Pointer Dereference78
- CWE-400 Uncontrolled Resource Consumption72
- CWE-20 Improper Input Validation68
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
2 519 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2021-44228Готовый эксплойт | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Критическая10,0 | KEV | 100,0 % | 10 дек. 2021 г. |
99Срочно | CVE-2017-5638Готовый эксплойт | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mesapache · struts · CWE-755 | Критическая9,8 | KEV | 100,0 % | 10 мар. 2017 г. |
99Срочно | CVE-2021-41773Готовый эксплойт | Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49apache · http server · CWE-22 | Критическая9,8 | KEV | 100,0 % | 5 окт. 2021 г. |
99Срочно | CVE-2021-42013Готовый эксплойт | Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)apache · http server · CWE-22 | Критическая9,8 | KEV | 100,0 % | 7 окт. 2021 г. |
99Срочно | CVE-2025-24813Готовый эксплойт | Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUTapache · tomcat · CWE-44 | Критическая9,8 | KEV | 99,9 % | 10 мар. 2025 г. |
99Срочно | CVE-2023-46604Готовый эксплойт | Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attackapache · activemq · CWE-502 | Критическая9,8 | KEV | 99,9 % | 27 окт. 2023 г. |
99Срочно | CVE-2020-1938Готовый эксплойт | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.apache · geode | Критическая9,8 | KEV | 99,3 % | 24 февр. 2020 г. |
97Срочно | CVE-2016-3427Готовый эксплойт | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to afforacle · jdk · CWE-284 | Критическая9,8 | KEV | 92,3 % | 21 апр. 2016 г. |
96Срочно | CVE-2021-40438Готовый эксплойт | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.resf · rocky linux · CWE-918 | Критическая9,0 | KEV | 100,0 % | 16 сент. 2021 г. |
96Срочно | CVE-2024-38475Готовый эксплойт | Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.apache · http server · CWE-116 | Критическая9,1 | KEV | 100,0 % | 1 июл. 2024 г. |
96Срочно | CVE-2016-8735Готовый эксплойт | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x beforeapache · tomcat | Критическая9,8 | KEV | 90,3 % | 6 апр. 2017 г. |
95Срочно | CVE-2023-4863Готовый эксплойт | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bogoogle · chrome · CWE-787 | Высокая8,8 | KEV | 100,0 % | 12 сент. 2023 г. |
93Срочно | CVE-2021-39144Готовый эксплойт | XStream is vulnerable to a Remote Command Execution attackxstream · xstream · CWE-94 | Высокая8,5 | KEV | 98,1 % | 23 авг. 2021 г. |
92Срочно | CVE-2018-11776Готовый эксплойт | Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (eiapache · struts | Высокая8,1 | KEV | 100,0 % | 22 авг. 2018 г. |
92Срочно | CVE-2017-12617Готовый эксплойт | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.apache · tomcat · CWE-434 | Высокая8,1 | KEV | 100,0 % | 3 окт. 2017 г. |
92Срочно | CVE-2017-12615Готовый эксплойт | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.apache · tomcat · CWE-434 | Высокая8,1 | KEV | 99,6 % | 19 сент. 2017 г. |
92Срочно | CVE-2017-9805Готовый эксплойт | The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStreaapache · struts · CWE-502 | Высокая8,1 | KEV | 99,4 % | 15 сент. 2017 г. |
91Срочно | CVE-2021-3156Готовый эксплойт | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root sudo project · sudo · CWE-193 | Высокая7,8 | KEV | 100,0 % | 26 янв. 2021 г. |
90Срочно | CVE-2023-44487Готовый эксплойт | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Высокая7,5 | KEV | 100,0 % | 10 окт. 2023 г. |
90Срочно | CVE-2010-1871Готовый эксплойт | JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for redhat · jboss enterprise application platform · CWE-917 | Высокая8,8 | KEV | 83,4 % | 5 авг. 2010 г. |
89Срочно | CVE-2022-0847Готовый эксплойт | A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe linux · linux kernel · CWE-665 | Высокая7,8 | KEV | 92,8 % | 10 мар. 2022 г. |
88Срочно | CVE-2024-54085Готовый эксплойт | Redfish Authentication Bypassami · megarac sp-x · CWE-290 | Критическая10,0 | KEV | 60,7 % | 11 мар. 2025 г. |
85Срочно | CVE-2023-4911Готовый эксплойт | Glibc: buffer overflow in ld.so leading to privilege escalationgnu · glibc · CWE-122 | Высокая7,8 | KEV | 81,4 % | 3 окт. 2023 г. |
85Срочно | CVE-2021-22555Готовый эксплойт | Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACElinux · linux kernel · CWE-787 | Высокая7,8 | KEV | 78,7 % | 7 июл. 2021 г. |
83Срочно | CVE-2016-5195Готовый эксплойт | Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect halinux · linux kernel · CWE-362 | Высокая7,0 | KEV | 83,5 % | 10 нояб. 2016 г. |
- CVE-2021-44228100Срочно
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %apache · log4j10 дек. 2021 г.
- CVE-2017-563899Срочно
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · struts10 мар. 2017 г.
- CVE-2021-4177399Срочно
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · http server5 окт. 2021 г.
- CVE-2021-4201399Срочно
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · http server7 окт. 2021 г.
- CVE-2025-2481399Срочно
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · tomcat10 мар. 2025 г.
- CVE-2023-4660499Срочно
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · activemq27 окт. 2023 г.
- CVE-2020-193899Срочно
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %apache · geode24 февр. 2020 г.
- CVE-2016-342797Срочно
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %oracle · jdk21 апр. 2016 г.
- CVE-2021-4043896Срочно
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %resf · rocky linux16 сент. 2021 г.
- CVE-2024-3847596Срочно
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 100 %apache · http server1 июл. 2024 г.
- CVE-2016-873596Срочно
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 90 %apache · tomcat6 апр. 2017 г.
- CVE-2023-486395Срочно
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 100 %google · chrome12 сент. 2023 г.
- CVE-2021-3914493Срочно
XStream is vulnerable to a Remote Command Execution attack
ВысокаяCVSS 8,5KEVГотовый эксплойтEPSS 98 %xstream · xstream23 авг. 2021 г.
- CVE-2018-1177692Срочно
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (ei
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 100 %apache · struts22 авг. 2018 г.
- CVE-2017-1261792Срочно
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 100 %apache · tomcat3 окт. 2017 г.
- CVE-2017-1261592Срочно
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 100 %apache · tomcat19 сент. 2017 г.
- CVE-2017-980592Срочно
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStrea
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 99 %apache · struts15 сент. 2017 г.
- CVE-2021-315691Срочно
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 100 %sudo project · sudo26 янв. 2021 г.
- CVE-2023-4448790Срочно
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 окт. 2023 г.
- CVE-2010-187190Срочно
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 83 %redhat · jboss enterprise application platform5 авг. 2010 г.
- CVE-2022-084789Срочно
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 93 %linux · linux kernel10 мар. 2022 г.
- CVE-2024-5408588Срочно
Redfish Authentication Bypass
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 61 %ami · megarac sp-x11 мар. 2025 г.
- CVE-2023-491185Срочно
Glibc: buffer overflow in ld.so leading to privilege escalation
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 81 %gnu · glibc3 окт. 2023 г.
- CVE-2021-2255585Срочно
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 79 %linux · linux kernel7 июл. 2021 г.
- CVE-2016-519583Срочно
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect ha
ВысокаяCVSS 7,0KEVГотовый эксплойтEPSS 84 %linux · linux kernel10 нояб. 2016 г.