CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
CVE-2026-22056 Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale)
ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID…
Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoS…
Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized A…
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful expl…
ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticate…
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (form…
ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a vulnerability which could allow a privi…
CVE-2025-26517 Privilege Escalation Vulnerability in StorageGRID (formerly StorageGRID Webscale)
CVE-2025-26516 Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale)
CVE-2025-26515 Server-Side Request Forgery Vulnerability in StorageGRID (formerly StorageGRID Webscale)
CVE-2025-26514 Reflected Cross-Site Scripting Vulnerability in StorageGRID (formerly StorageGRID Webscale)
The installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when successfully exploited could allow a local…
Apache HttpComponents: PSL (Public Suffix List) validation bypass
mysql: mariadb: mysqldump unspecified vulnerability (CPU Apr 2025)
openjdk: Improve compiler transformations (Oracle CPU 2025-04)
mysql: MySQL Server: High privileged attacker can cause Denial of Service (DoS)
Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names
Stream HTTP wrapper truncates redirect location to 1024 bytes
Stream HTTP wrapper header check might omit basic auth header
Streams HTTP wrapper does not fail for headers with invalid name and no colon
CVE-2025-26512 Privilege Escalation Vulnerability in SnapCenter
Vim vulnerable to potential data loss with zip.vim and special crafted zip files
Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)
ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)
Showing 1 to 25 CVEs · page 1 (more available)