Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2017-12421
NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to execute arbitrary code on the storage controller via unspecifi…
Clustered Data Ontap
Mitigation only
HIGH 7.7
CVE-2017-12423
NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to read data on other Storage Virtual Machines (SVMs) via unspeci…
Clustered Data Ontap
Mitigation only
HIGH 7.5
CVE-2017-14053
NetApp OnCommand Unified Manager for Clustered Data ONTAP before 7.2P1 does not set the secure flag for an unspecified cookie in an HTTPS session, wh…
Oncommand Unified Manager For Clustered Data Ontap
after 7.2
MEDIUM 6.5
CVE-2016-1895
NetApp Data ONTAP before 8.2.5 and 8.3.x before 8.3.2P12 allow remote authenticated users to cause a denial of service via vectors related to unsafe …
Data Ontap
after 8.2.4
CRITICAL 9.8
CVE-2015-7746
NetApp Data ONTAP before 8.2.4, when operating in 7-Mode, allows remote attackers to bypass authentication and (1) obtain sensitive information from …
Data Ontap
after 8.2.3
MEDIUM 6.5
CVE-2017-12422
NetApp StorageGRID Webscale 10.2.x before 10.2.2.3, 10.3.x before 10.3.0.4, and 10.4.x before 10.4.0.2 allow remote authenticated users to delete arb…
Storagegrid Webscale
Mitigation only
HIGH 8.8
CVE-2017-12420
Heap-based buffer overflow in the SMB implementation in NetApp Clustered Data ONTAP before 8.3.2P8 and 9.0 before P2 allows remote authenticated user…
Clustered Data Ontap
after 9.0
MEDIUM 5.9
CVE-2017-12859
NetApp Data ONTAP before 8.2.5, when operating in 7-Mode in NFS environments, allows remote attackers to cause a denial of service via unspecified ve…
Data Ontap
after 8.2.4
HIGH 8.1
CVE-2015-7887
NetApp SnapCenter Server 1.0 allows remote authenticated users to list and delete backups.
Snapcenter Server
Patch available
MEDIUM 6.5
CVE-2017-8919
NetApp OnCommand API Services before 1.2P3 logs the LDAP BIND password when a user attempts to log in using the REST API, which allows remote authent…
Oncommand Api Services
after 1.2
MEDIUM 6.5
CVE-2017-7947
NetApp Clustered Data ONTAP before 8.3.2P11, 9.0 before P4, and 9.1 before P5 allow attackers to obtain sensitive password information by leveraging …
Clustered Data Ontap
Mitigation only
HIGH 8.1
CVE-2016-3998
NetApp AltaVault 4.1 and earlier allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service vi…
Altavault
after 4.1
HIGH 8.1
CVE-2016-5045
NetApp OnCommand System Manager before 9.0 allows remote attackers to obtain sensitive credentials via vectors related to cluster peering setup.
Oncommand System Manager
Mitigation only
HIGH 7.5
CVE-2016-3400
NetApp Data ONTAP 8.1 and 8.2, when operating in 7-Mode, allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or caus…
Data Ontap
No fix yet
HIGH 7.5
CVE-2016-3997
NetApp Clustered Data ONTAP allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service by leve…
Clustered Data Ontap
Mitigation only
HIGH 7.5
CVE-2017-7236
SQL injection vulnerability in NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 allows remote attackers to execute arbitrary SQL comm…
Oncommand Unified Manager Core Package
Patch available
HIGH 7.5
CVE-2017-7439
NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 might allow remote attackers to obtain sensitive information via vectors involving e…
Oncommand Unified Manager Core Package
Patch available
HIGH 7.5
CVE-2017-5988
NetApp Clustered Data ONTAP 8.1 through 9.1P1, when NFS or SMB is enabled, allows remote attackers to cause a denial of service via unspecified vecto…
Clustered Data Ontap
No fix yet
MEDIUM 5.3
CVE-2017-7345
NetApp OnCommand Performance Manager and OnCommand Unified Manager for Clustered Data ONTAP before 7.1P1 improperly bind the Java Management Extensio…
Clustered Data Ontap
after 7.1
HIGH 8.8
CVE-2016-5374
NetApp Data ONTAP 9.0 and 9.1 before 9.1P1 allows remote authenticated users that own SMB-hosted data to bypass intended sharing restrictions by leve…
Data Ontap
Patch available
HIGH 7.5
CVE-2017-5995
The NetApp ONTAP Select Deploy administration utility 2.0 through 2.2.1 might allow remote attackers to obtain sensitive information via unspecified …
Ontap Select Deploy Administration Utility
Mitigation only
CRITICAL 9.8
CVE-2016-5711
NetApp Virtual Storage Console for VMware vSphere before 6.2.1 uses a non-unique certificate, which allows remote attackers to conduct man-in-the-mid…
Virtual Storage Console For Vmware Vsphere
after 6.2
CRITICAL 9.8
CVE-2016-6667
NetApp OnCommand Unified Manager for Clustered Data ONTAP 6.3 through 6.4P1 contain a default privileged account, which allows remote attackers to ex…
Oncommand Unified Manager For Clustered Data Ontap
Patch available
HIGH 8.8
CVE-2015-8322
NetApp OnCommand System Manager 8.3.x before 8.3.2 allows remote authenticated users to execute arbitrary code via unspecified vectors.
Data Ontap
Patch available
HIGH 8.1
CVE-2016-1894
NetApp OnCommand Workflow Automation before 3.1P2 allows remote attackers to bypass authentication via unspecified vectors.
Oncommand Workflow Automation
after 3.1
HIGH 7.5
CVE-2015-8544
NetApp SnapDrive for Windows before 7.0.2P4, 7.0.3, and 7.1 before 7.1.3P1 allows remote attackers to obtain sensitive information via unspecified ve…
Snapdrive
after 7.1.3
HIGH 7.5
CVE-2016-3063
Multiple functions in NetApp OnCommand System Manager before 8.3.2 do not properly escape special characters, which allows remote authenticated users…
Oncommand System Manager
after 8.3.1
HIGH 7.5
CVE-2016-4341
NetApp Clustered Data ONTAP before 8.3.2P7 allows remote attackers to obtain SMB share information via unspecified vectors.
Clustered Data Ontap
after 8.3.2
HIGH 7.3
CVE-2016-1502
NetApp SnapCenter Server 1.0 and 1.0P1 allows remote attackers to partially bypass authentication and then list and delete backups via unspecified ve…
Snapcenter Server
Patch available
MEDIUM 6.3
CVE-2016-5372
Cross-site request forgery (CSRF) vulnerability in NetApp Snap Creator Framework before 4.3.0P1 allows remote attackers to hijack the authentication …
Snap Creator Framework
after 4.3.0