Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2020-8573
The NetApp HCI H610C, H615C and H610S Baseboard Management Controllers (BMC) are shipped with a documented default account and password that should b…
Hci H610s Firmware
Mitigation only
HIGH 8.1
CVE-2020-14195
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jn…
Active Iq Unified Manager
2.9.10.5+
HIGH 8.1
CVE-2020-14060EPSS 9%
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.…
Active Iq Unified Manager
2.9.10.5+
HIGH 8.1
CVE-2020-14061
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueC…
Active Iq Unified Manager
2.9.10.5+
HIGH 8.1
CVE-2020-14062EPSS 8%
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xal…
Active Iq Unified Manager
2.9.10.5+
HIGH 7.5
CVE-2020-8572
Element OS prior to version 12.0 and Element HealthTools prior to version 2020.04.01.04 are susceptible to a vulnerability which when successfully ex…
Element Healthtools
12.0 / 2020.04.01.04+
HIGH 7.5
CVE-2019-5500
Certain versions of the NetApp Service Processor and Baseboard Management Controller firmware allow a remote unauthenticated attacker to cause a Deni…
Fas26x0 Firmware
No fix yet
MEDIUM 5.4
CVE-2019-17276
OnCommand System Manager versions 9.3 prior to 9.3P18 and 9.4 prior to 9.4P2 are susceptible to a cross site scripting vulnerability that could allow…
Oncommand System Manager
Mitigation only
HIGH 7.5
CVE-2020-8571
StorageGRID (formerly StorageGRID Webscale) versions 10.0.0 through 11.3 prior to 11.2.0.8 and 11.3.0.4 are susceptible to a vulnerability which allo…
Storagegrid
11.2.0.8 / 11.3.0.4+
CRITICAL 9.8
CVE-2020-9547EPSS 18%
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engi…
Active Iq Unified Manager
2.7.9.7 / 2.8.11.6+
CRITICAL 9.8
CVE-2020-9548EPSS 18%
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.An…
Active Iq Unified Manager
2.7.9.7 / 2.8.11.6+
CRITICAL 9.8
CVE-2020-9546
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shad…
Active Iq Unified Manager
2.7.9.7 / 2.8.11.6+
CRITICAL 9.8
CVE-2019-17275
OnCommand Cloud Manager versions prior to 3.8.0 are susceptible to arbitrary code execution by remote attackers.
Oncommand Cloud Manager
3.8.0+
HIGH 7.8
CVE-2019-17274
NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 were shipped with a default account en…
Fabric Attached Storage 8700 Firmware
after 13.1
HIGH 7.2
CVE-2013-3322
NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to inject arbitrary commands in the Halt/Reboot interface.
Oncommand System Manager
after 2.1
MEDIUM 6.5
CVE-2019-17273
E-Series SANtricity OS Controller Software version 11.60.0 is susceptible to a vulnerability which allows an attacker to cause a Denial of Service (D…
E Series Santricity Os Controller
after 11.60.0
HIGH 7.5
CVE-2013-3321
NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to include arbitrary files through specially crafted requests to the "diagnos…
Oncommand System Manager
after 2.1
MEDIUM 6.1
CVE-2013-3320
Cross-site Scripting (XSS) vulnerability in NetApp OnCommand System Manager before 2.2 allows remote attackers to inject arbitrary web script or HTML…
Oncommand System Manager
2.2+
CRITICAL 9.8
CVE-2019-5509
ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerability which when successfully e…
Ontap Select Deploy Administration Utility
after 2.12.2
HIGH 7.2
CVE-2019-17272
All versions of ONTAP Select Deploy administration utility are susceptible to a vulnerability which when successfully exploited could allow an admini…
Ontap Select Deploy Administration Utility
Mitigation only
HIGH 7.5
CVE-2019-5508
Clustered Data ONTAP versions 9.2 through 9.4 are susceptible to a vulnerability which allows an attacker to use l2ping to cause a Denial of Service …
Clustered Data Ontap
after 9.4
MEDIUM 5.9
CVE-2019-5506
Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circumstances making them susceptible to impersonatio…
Clustered Data Ontap
after 9.6
MEDIUM 5.5
CVE-2019-5507
SnapManager for Oracle prior to version 3.4.2P1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sens…
Snapmanager
3.4.2+
CRITICAL 9.8
CVE-2019-17267
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactio…
Active Iq Unified Manager
2.8.11.5 / 2.9.10+
CRITICAL 9.8
CVE-2019-5504
ONTAP Select Deploy administration utility versions 2.12 & 2.12.1 ship with an HTTP service bound to the network allowing unauthenticated remote atta…
Ontap Select Deploy Administration Utility
Patch available
CRITICAL 9.8
CVE-2019-5505
ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext.
Ontap Select Deploy Administration Utility
after 2.12.1
MEDIUM 5.3
CVE-2019-5503
OnCommand Workflow Automation versions prior to 5.0 shipped without certain HTTP Security headers configured which could allow an attacker to obtain …
Oncommand Workflow Automation
Mitigation only
MEDIUM 6.5
CVE-2019-5498
OnCommand Insight versions through 7.3.6 may disclose sensitive account information to an authenticated user.
Oncommand Insight
after 7.3.6
CRITICAL 9.1
CVE-2019-5502
SMB in Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 has weak cryptography which when exploited could lead to information disclosure or ad…
Data Ontap
8.2.5+
HIGH 7.5
CVE-2019-5493
Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 are susceptible to a vulnerability which discloses information to an unauthenticated attacke…
Data Ontap
8.2.5+