Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2019-5501
Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 may disclose sensitive LDAP account information to unauthenticated remote attackers.
Data Ontap
8.2.5+
CRITICAL 9.1
CVE-2019-10744EPSS 5%
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying prop…
Active Iq Unified Manager
12.1.5.2 / 13.1.3.4+
CRITICAL 9.8
CVE-2019-5497
NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were shipped with a default account enabled that could allow…
Aff A700s Firmware
Mitigation only
HIGH 7.5
CVE-2019-5495
OnCommand Unified Manager for VMware vSphere, Linux and Windows prior to 9.5 shipped without certain HTTP Security headers configured which could all…
Oncommand Unified Manager
9.5+
HIGH 7.5
CVE-2019-5496
Oncommand Insight versions prior to 7.3.5 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive …
Oncommand Insight
7.3.5+
HIGH 7.5
CVE-2019-5494
OnCommand Unified Manager 7-Mode prior to version 5.2.4 shipped without certain HTTP Security headers configured which could allow an attacker to obt…
Oncommand Unified Manager
5.2.4+
HIGH 7.5
CVE-2019-5492
Element Plug-in for vCenter Server versions prior to 4.2.3 may disclose sensitive account information to an unauthenticated attacker. NetApp HCI Comp…
Hyper Converged Infrastructure Compute Node
4.2.3+
CRITICAL 9.8
CVE-2019-5490
Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled that cou…
Service Processor
Mitigation only
MEDIUM 5.3
CVE-2018-5482
NetApp SnapCenter Server prior to 4.1 does not set the secure flag for a sensitive cookie in an HTTPS session which can allow the transmission of the…
Snapcenter Server
4.1+
HIGH 7.5
CVE-2019-5491
Clustered Data ONTAP versions prior to 9.1P15 and 9.3 prior to 9.3P7 are susceptible to a vulnerability which discloses sensitive information to an u…
Clustered Data Ontap
9.1+
HIGH 7.4
CVE-2018-5481
OnCommand Unified Manager for 7-Mode (core package) prior to 5.2.4 uses cookies that lack the secure attribute in certain circumstances making it vul…
Oncommand Unified Manager
5.2.4+
MEDIUM 6.5
CVE-2018-1000873
Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes …
Active Iq Unified Manager
2.9.8 / 11.2.0.3.23+
CRITICAL 9.8
CVE-2018-5495
All StorageGRID Webscale versions are susceptible to a vulnerability which could permit an unauthenticated attacker to communicate with systems on th…
Storagegrid Webscale
Mitigation only
CRITICAL 9.8
CVE-2018-5492
NetApp E-Series SANtricity OS Controller Software 11.30 and later version 11.30.5 is susceptible to unauthenticated remote code execution.
E Series Santricity Os Controller
after 11.40
HIGH 8.8
CVE-2018-5490
Read-Only export policy rules are not correctly enforced in Clustered Data ONTAP 8.3 Release Candidate versions and therefore may allow more than "re…
Clustered Data Ontap
8.3+
MEDIUM 6.5
CVE-2018-5489
NetApp 7-Mode Transition Tool allows users with valid credentials to access functions and information which may have been intended to be restricted t…
7 Mode Transition Tool
2.0+
MEDIUM 6.5
CVE-2017-13652
NetApp OnCommand Insight version 7.3.0 and versions prior to 7.2.0 are susceptible to clickjacking attacks which could cause a user to perform an uni…
Oncommand Insight
7.2.0+
MEDIUM 5.3
CVE-2017-7568
NetApp OnCommand Unified Manager for 7-Mode (core package) versions prior to 5.2.3 may disclose sensitive LDAP account information to authenticated u…
Oncommand Unified Manager
5.2.3+
CRITICAL 9.8
CVE-2018-5488
NetApp SANtricity Web Services Proxy versions 1.10.x000.0002 through 2.12.X000.0002 and SANtricity Storage Manager 11.30.0X00.0004 through 11.42.0X00…
Santricity Storage Manager
after 11.42.0x00.0001
MEDIUM 6.5
CVE-2018-3721
lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith fu…
Active Iq Unified Manager
4.17.5+
CRITICAL 9.8
CVE-2018-5487
NetApp OnCommand Unified Manager for Linux versions 7.2 through 7.3 ship with the Java Management Extension Remote Method Invocation (JMX RMI) servic…
Oncommand Unified Manager
after 7.3
HIGH 7.8
CVE-2018-5485
NetApp OnCommand Unified Manager for Windows versions 7.2 through 7.3 are susceptible to a vulnerability which could lead to a privilege escalation a…
Oncommand Unified Manager
after 7.3
HIGH 7.8
CVE-2018-5486
NetApp OnCommand Unified Manager for Linux versions 7.2 though 7.3 ship with the Java Debug Wire Protocol (JDWP) enabled which allows unauthorized lo…
Oncommand Unified Manager
after 7.3
HIGH 7.2
CVE-2017-15519
Versions of SnapCenter 2.0 through 3.0.1 allow unauthenticated remote attackers to view and modify backup related data via the Plug-in for NAS File S…
Snapcenter Server
after 3.0.1
HIGH 7.8
CVE-2017-15518
All versions of OnCommand API Services prior to 2.1 and NetApp Service Level Manager prior to 1.0RC4 log a privileged database user account password.…
Oncommand Api Services
after 2.0
MEDIUM 6.5
CVE-2017-14583
NetApp Clustered Data ONTAP versions 9.x prior to 9.1P10 and 9.2P2 are susceptible to a vulnerability which allows an attacker to cause a Denial of S…
Clustered Data Ontap
after 9.1
HIGH 8.1
CVE-2016-6904
Versions of VASA Provider for Clustered Data ONTAP prior to 7.0P1 contain a web server that accepts plain text authentication. This could allow an un…
Vasa Provider
after 7.0
MEDIUM 5.5
CVE-2017-15517
AltaVault OST Plug-in versions prior to 1.2.2 may allow attackers to obtain sensitive information via unspecified vectors. All users are urged to mov…
Altavault Ost Plug In
1.2.2+
HIGH 8.8
CVE-2017-15516
NetApp SnapCenter Server versions 1.1 through 2.x are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability which could be used to cause a…
Snapcenter Server
Patch available
MEDIUM 5.7
CVE-2017-5201
NetApp Clustered Data ONTAP before 8.3.2P8 and 9.0 before P2 allow remote authenticated users to obtain sensitive cluster and tenant information via …
Clustered Data Ontap
8.3.2+