NetApp / Ontap
25 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-22049 | ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID… | HIGH | 8.7 | Jul 22, 2026 |
| CVE-2026-22052 | ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticate… | MEDIUM | 5.3 | Mar 4, 2026 |
| CVE-2026-22050 | ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a vulnerability which could allow a privi… | MEDIUM | 6.9 | Jan 12, 2026 |
| CVE-2025-1861 | Stream HTTP wrapper truncates redirect location to 1024 bytes | MEDIUM | 6.3 | Mar 30, 2025 |
| CVE-2025-1736 | Stream HTTP wrapper header check might omit basic auth header | MEDIUM | 6.3 | Mar 30, 2025 |
| CVE-2025-1734 | Streams HTTP wrapper does not fail for headers with invalid name and no colon | MEDIUM | 6.3 | Mar 30, 2025 |
| CVE-2025-26465 | Openssh: machine-in-the-middle attack if verifyhostkeydns is enabled | MEDIUM | 6.8 | Feb 18, 2025 |
| CVE-2025-24928 | libxml2: Stack-based buffer overflow in xmlSnprintfElements of libxml2 | HIGH | 7.8 | Feb 18, 2025 |
| CVE-2024-56171 | libxml2: Use-After-Free in libxml2 | CRITICAL | 9.8 | Feb 18, 2025 |
| CVE-2025-0167 | netrc and default credential leak | LOW | 3.4 | Feb 5, 2025 |
| CVE-2024-11053 | netrc and redirect credential leak | MEDIUM | 5.9 | Dec 11, 2024 |
| CVE-2024-8932 | OOB access in ldap_escape | CRITICAL | 9.8 | Nov 22, 2024 |
| CVE-2024-39573 | Apache HTTP Server: mod_rewrite proxy handler substitution | HIGH | 7.5 | Jul 1, 2024 |
| CVE-2024-38473 | Apache HTTP Server proxy encoding problem | HIGH | 8.1 | Jul 1, 2024 |
| CVE-2024-38472 | Apache HTTP Server on WIndows UNC SSRF | HIGH | 7.5 | Jul 1, 2024 |
| CVE-2024-36387 | Apache HTTP Server: DoS by Null pointer in websocket over HTTP/2 | MEDIUM | 5.4 | Jul 1, 2024 |
| CVE-2024-6387 | Openssh: regresshion - race condition in ssh allows rce/dos | HIGH | 8.1 | Jul 1, 2024 |
| CVE-2024-27316 | Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames | HIGH | 7.5 | Apr 4, 2024 |
| CVE-2024-24795 | Apache HTTP Server: HTTP Response Splitting in multiple modules | MEDIUM | 6.3 | Apr 4, 2024 |
| CVE-2023-38709 | Apache HTTP Server: HTTP response splitting | HIGH | 7.3 | Apr 4, 2024 |
| CVE-2024-2004 | Usage of disabled protocol | MEDIUM | 5.3 | Mar 27, 2024 |
| CVE-2024-28757 | expat: XML Entity Expansion | HIGH | 7.5 | Mar 10, 2024 |
| CVE-2023-4408 | Parsing large DNS messages may cause excessive CPU load | HIGH | 7.5 | Feb 13, 2024 |
| CVE-2023-27317 | Information Disclosure Vulnerability in ONTAP 9 | MEDIUM | 4.6 | Dec 15, 2023 |
| CVE-2023-27536 | curl: GSS delegation too eager connection re-use | MEDIUM | 5.9 | Mar 30, 2023 |
Showing 1 to 25 of 25 CVEs