NetApp kayıtları
netapp üreticisine ait 2.519 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 40 · %1,6
- Silahlaştırılmış
- 52 · %2,1
- Pre-auth RCE
- 72
- Düzeltme kaydı olan
- %67,6
- Yayından KEV’e ortanca
- 651 gün
Tekrar eden sınıflar
- CWE-416 Use After Free111
- CWE-125 Out-of-bounds Read93
- CWE-787 Out-of-bounds Write90
- CWE-476 NULL Pointer Dereference78
- CWE-400 Uncontrolled Resource Consumption72
- CWE-20 Improper Input Validation68
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
2.519 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
100Hemen | CVE-2021-44228Silahlaştırılmış | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Kritik10,0 | KEV | %100,0 | 10 Ara 2021 |
99Hemen | CVE-2017-5638Silahlaştırılmış | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mesapache · struts · CWE-755 | Kritik9,8 | KEV | %100,0 | 10 Mar 2017 |
99Hemen | CVE-2021-41773Silahlaştırılmış | Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49apache · http server · CWE-22 | Kritik9,8 | KEV | %100,0 | 5 Eki 2021 |
99Hemen | CVE-2021-42013Silahlaştırılmış | Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)apache · http server · CWE-22 | Kritik9,8 | KEV | %100,0 | 7 Eki 2021 |
99Hemen | CVE-2025-24813Silahlaştırılmış | Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUTapache · tomcat · CWE-44 | Kritik9,8 | KEV | %99,9 | 10 Mar 2025 |
99Hemen | CVE-2023-46604Silahlaştırılmış | Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attackapache · activemq · CWE-502 | Kritik9,8 | KEV | %99,9 | 27 Eki 2023 |
99Hemen | CVE-2020-1938Silahlaştırılmış | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.apache · geode | Kritik9,8 | KEV | %99,3 | 24 Şub 2020 |
97Hemen | CVE-2016-3427Silahlaştırılmış | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to afforacle · jdk · CWE-284 | Kritik9,8 | KEV | %92,3 | 21 Nis 2016 |
96Hemen | CVE-2021-40438Silahlaştırılmış | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.resf · rocky linux · CWE-918 | Kritik9,0 | KEV | %100,0 | 16 Eyl 2021 |
96Hemen | CVE-2024-38475Silahlaştırılmış | Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.apache · http server · CWE-116 | Kritik9,1 | KEV | %100,0 | 1 Tem 2024 |
96Hemen | CVE-2016-8735Silahlaştırılmış | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x beforeapache · tomcat | Kritik9,8 | KEV | %90,3 | 6 Nis 2017 |
95Hemen | CVE-2023-4863Silahlaştırılmış | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bogoogle · chrome · CWE-787 | Yüksek8,8 | KEV | %100,0 | 12 Eyl 2023 |
93Hemen | CVE-2021-39144Silahlaştırılmış | XStream is vulnerable to a Remote Command Execution attackxstream · xstream · CWE-94 | Yüksek8,5 | KEV | %98,1 | 23 Ağu 2021 |
92Hemen | CVE-2018-11776Silahlaştırılmış | Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (eiapache · struts | Yüksek8,1 | KEV | %100,0 | 22 Ağu 2018 |
92Hemen | CVE-2017-12617Silahlaştırılmış | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.apache · tomcat · CWE-434 | Yüksek8,1 | KEV | %100,0 | 3 Eki 2017 |
92Hemen | CVE-2017-12615Silahlaştırılmış | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.apache · tomcat · CWE-434 | Yüksek8,1 | KEV | %99,6 | 19 Eyl 2017 |
92Hemen | CVE-2017-9805Silahlaştırılmış | The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStreaapache · struts · CWE-502 | Yüksek8,1 | KEV | %99,4 | 15 Eyl 2017 |
91Hemen | CVE-2021-3156Silahlaştırılmış | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root sudo project · sudo · CWE-193 | Yüksek7,8 | KEV | %100,0 | 26 Oca 2021 |
90Hemen | CVE-2023-44487Silahlaştırılmış | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Yüksek7,5 | KEV | %100,0 | 10 Eki 2023 |
90Hemen | CVE-2010-1871Silahlaştırılmış | JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for redhat · jboss enterprise application platform · CWE-917 | Yüksek8,8 | KEV | %83,4 | 5 Ağu 2010 |
89Hemen | CVE-2022-0847Silahlaştırılmış | A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe linux · linux kernel · CWE-665 | Yüksek7,8 | KEV | %92,8 | 10 Mar 2022 |
88Hemen | CVE-2024-54085Silahlaştırılmış | Redfish Authentication Bypassami · megarac sp-x · CWE-290 | Kritik10,0 | KEV | %60,7 | 11 Mar 2025 |
85Hemen | CVE-2023-4911Silahlaştırılmış | Glibc: buffer overflow in ld.so leading to privilege escalationgnu · glibc · CWE-122 | Yüksek7,8 | KEV | %81,4 | 3 Eki 2023 |
85Hemen | CVE-2021-22555Silahlaştırılmış | Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACElinux · linux kernel · CWE-787 | Yüksek7,8 | KEV | %78,7 | 7 Tem 2021 |
83Hemen | CVE-2016-5195Silahlaştırılmış | Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect halinux · linux kernel · CWE-362 | Yüksek7,0 | KEV | %83,5 | 10 Kas 2016 |
- CVE-2021-44228100Hemen
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100apache · log4j10 Ara 2021
- CVE-2017-563899Hemen
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100apache · struts10 Mar 2017
- CVE-2021-4177399Hemen
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100apache · http server5 Eki 2021
- CVE-2021-4201399Hemen
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100apache · http server7 Eki 2021
- CVE-2025-2481399Hemen
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100apache · tomcat10 Mar 2025
- CVE-2023-4660499Hemen
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100apache · activemq27 Eki 2023
- CVE-2020-193899Hemen
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99apache · geode24 Şub 2020
- CVE-2016-342797Hemen
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %92oracle · jdk21 Nis 2016
- CVE-2021-4043896Hemen
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100resf · rocky linux16 Eyl 2021
- CVE-2024-3847596Hemen
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
KritikCVSS 9,1KEVSilahlaştırılmışEPSS %100apache · http server1 Tem 2024
- CVE-2016-873596Hemen
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %90apache · tomcat6 Nis 2017
- CVE-2023-486395Hemen
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %100google · chrome12 Eyl 2023
- CVE-2021-3914493Hemen
XStream is vulnerable to a Remote Command Execution attack
YüksekCVSS 8,5KEVSilahlaştırılmışEPSS %98xstream · xstream23 Ağu 2021
- CVE-2018-1177692Hemen
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (ei
YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %100apache · struts22 Ağu 2018
- CVE-2017-1261792Hemen
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.
YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %100apache · tomcat3 Eki 2017
- CVE-2017-1261592Hemen
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.
YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %100apache · tomcat19 Eyl 2017
- CVE-2017-980592Hemen
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStrea
YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %99apache · struts15 Eyl 2017
- CVE-2021-315691Hemen
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %100sudo project · sudo26 Oca 2021
- CVE-2023-4448790Hemen
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 Eki 2023
- CVE-2010-187190Hemen
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %83redhat · jboss enterprise application platform5 Ağu 2010
- CVE-2022-084789Hemen
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %93linux · linux kernel10 Mar 2022
- CVE-2024-5408588Hemen
Redfish Authentication Bypass
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %61ami · megarac sp-x11 Mar 2025
- CVE-2023-491185Hemen
Glibc: buffer overflow in ld.so leading to privilege escalation
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %81gnu · glibc3 Eki 2023
- CVE-2021-2255585Hemen
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %79linux · linux kernel7 Tem 2021
- CVE-2016-519583Hemen
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect ha
YüksekCVSS 7,0KEVSilahlaştırılmışEPSS %84linux · linux kernel10 Kas 2016