Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Portworx MEDIUM 5.5
CVE-2025-9127

A vulnerability exists in PX Enterprise whereby sensitive information may be logged under specific conditions.

Fix: 3.1.9 / 3.2.4+
Fix from $1,600 2025-12-04
Purity\/\/fa HIGH 8.8
CVE-2024-0005

A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotely through a specifically craf…

Fix: after 6.4.10
Fix from $1,950 2024-09-23
Purity\/\/fa CRITICAL 9.8
CVE-2024-0001

A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malici…

Fix: after 6.4.10
Fix from $2,300 2024-09-23
Purity\/\/fa CRITICAL 9.8
CVE-2024-0002

A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.

Fix: after 6.4.10
Fix from $2,300 2024-09-23
Purity\/\/fa HIGH 7.2
CVE-2024-0003

A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing…

Fix: after 6.4.10
Fix from $1,950 2024-09-23
Purity\/\/fa HIGH 7.2
CVE-2024-0004

A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate privilege on the ar…

Fix: after 6.4.10
Fix from $1,950 2024-09-23
Purity\/\/fa HIGH 8.8
CVE-2023-36628

A flaw exists in VASA which allows users with access to a vSphere/ESXi VMware admin on a FlashArray to gain root access through privilege escalation.

Fix: after 6.4.5
Fix from $1,950 2023-10-03
Pure Swagger CRITICAL 9.3
CVE-2022-31524

The PureStorage-OpenConnect/swagger repository through 1.1.5 on GitHub allows absolute path traversal because the Flask send_file function is used un…

Fix: after 1.1.5
Fix from $2,300 2022-07-11
Purity\/\/fa CRITICAL 9.8
CVE-2022-32554

Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases…

Fix: 3.1.13 / 3.2.5+
Fix from $2,300 2022-06-23
Purity\/\/fa HIGH 8.8
CVE-2022-32552

Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases…

Fix: 3.1.13 / 3.2.5+
Fix from $1,950 2022-06-23
Purity\/\/fa HIGH 8.8
CVE-2022-32553

Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases…

Fix: 3.1.13 / 3.2.5+
Fix from $1,950 2022-06-23
Purity MEDIUM 5.4
CVE-2017-7352

Stored Cross-site scripting (XSS) vulnerability in Pure Storage Purity 4.7.5 allows remote authenticated users to inject arbitrary web script or HTML…

No fix yet
Fix from $1,600 2017-10-11