VulnSea

netapp has 27 CVEs on record between 2021 and 2026. The median CVSS is 7.8 (high). 4% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-416 (6) and CWE-502 (4). Most affected products: cloud_backup (11), active_iq_unified_manager (4), ontap_tools (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
4% vs 1% corpus
Median CVSS
7.8
Publish → KEV
(1)
Last 90 days
0 prev 3

Products

  • cloud_backup 11
  • active_iq_unified_manager 4
  • ontap_tools 2
  • solidfire_baseboard_management_controller 2
  • active_iq_config_advisor 1
  • active_iq_onecollect 1
27
Total CVEs
0
Critical
1
CISA KEV
1
Exploited

netapp vulnerabilities

CVEs affecting netapp, newest first. Open any entry for full detail, references, and exploit status.

27 CVEsRSS

CVE-2026-22055High· 8.8
3mo ago

Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.

Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.

Twilightnetapp · active_iq_onecollectEPSS 0.24%via NVD
CVE-2026-22054High· 8.8
3mo ago

Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.

Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.

Twilightnetapp · active_iq_config_advisorEPSS 0.24%via NVD
CVE-2026-22051Medium· 4.3
5mo ago

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful exploit could allow an authenticated attacker with low privileges to run arbitrary…

Sunlitnetapp · storagegridEPSS 0.18%via NVD
CVE-2024-21262Medium· 6.5PoC
1y ago

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC)

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 9.0.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access vi…

Twilightnetapp · oncommand_insightEPSS 0.57%via NVD
CVE-2024-26641High· 8.6
2y ago

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv() syzbot found __ip6_tnl_rcv() could access unitiliazed data [1]. Call pskb_inet_may_pull() to fix this, a…

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv() syzbot found __ip6_tnl_rcv() could access unitiliazed data [1]. Call pskb_inet_may_pull() to fix this, a…

Twilightnetapp · active_iq_unified_managerEPSS 0.57%via NVD
CVE-2023-52433High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction New elements in this transaction might expired before such transaction ends

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction New elements in this transaction might expired before such transaction ends. Skip sync GC …

Twilightnetapp · ontap_toolsEPSS 0.25%via NVD
CVE-2024-1635High· 7.5
2y ago

A vulnerability was found in Undertow

A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then closes the conne…

Twilightnetapp · active_iq_unified_managerEPSS 4.6%via NVD
CVE-2024-1086High· 7.8CISA KEVPoC
2y ago

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, …

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, …

Abyssalnetapp · h300s_firmwareEPSS 28%via NVD
CVE-2024-0565Medium· 6.8
2y ago

An out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-component in the Linux Kernel

An out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-component in the Linux Kernel. This issue occurs due to integer underflow on the memcpy length, leading to a denia…

Sunlitnetapp · ontap_toolsEPSS 2.0%via NVD
CVE-2022-4696High· 7.8
3y ago

There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation

There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If IORING_OP_SPLICE is missing the IO_WQ_WORK_FILES flag, which signals that the operation won't use current->nsproxy, s…

Twilightnetapp · h410s_firmwareEPSS 0.43%via NVD
CVE-2022-1199High· 7.5
4y ago

A flaw was found in the Linux kernel

A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio from the user space, resulting in a null-ptr-deref vulnerability and a use-after-free vulnerability.

Twilightnetapp · active_iq_unified_managerEPSS 2.0%via NVD
CVE-2021-20322High· 7.4
4y ago

A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports

A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effect…

Twilightnetapp · active_iq_unified_managerEPSS 6.8%via NVD
CVE-2021-45485High· 7.5PoC
4y ago

In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically ch…

In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically ch…

Midnightnetapp · e-series_santricity_os_controllerEPSS 3.6%via NVD
CVE-2021-42252High· 7.8
4y ago

An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6

An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local attackers able to access the Aspeed LPC control interface could overwrite memory in the kernel and potential…

Twilightnetapp · cloud_backupEPSS 0.37%via NVD
CVE-2021-41864High· 7.8
4y ago

prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write.

prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write.

Twilightnetapp · cloud_backupEPSS 0.41%via NVD
CVE-2021-40490High· 7.0
5y ago

A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13.

A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13.

Twilightnetapp · solidfire_baseboard_management_controllerEPSS 0.30%via NVD
CVE-2021-28691High· 7.8
5y ago

Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the receive kernel thread associated with queue 0 in response to the frontend sen…

Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the receive kernel thread associated with queue 0 in response to the frontend sen…

Twilightnetapp · solidfire_baseboard_management_controllerEPSS 0.36%via NVD
CVE-2021-3483High· 7.8
5y ago

A flaw was found in the Nosy driver in the Linux kernel

A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list, leading to a use-after-free when one of these devices is removed. The highest threat from this vulnerabil…

Twilightnetapp · cloud_backupEPSS 0.36%via NVD
CVE-2021-23134High· 7.8
5y ago

Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges

Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW …

Twilightnetapp · cloud_backupEPSS 0.37%via NVD
CVE-2021-23133Medium· 6.7
5y ago

A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process

A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(s…

Sunlitnetapp · cloud_backupEPSS 0.47%via NVD
CVE-2021-3506High· 7.1
5y ago

An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4

An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to …

Twilightnetapp · cloud_backupEPSS 0.37%via NVD
CVE-2021-27365High· 7.8PoC
5y ago

An issue was discovered in the Linux kernel through 5.11.3

An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is a…

Midnightnetapp · cloud_backupEPSS 2.1%via NVD
CVE-2021-27364High· 7.1
5y ago

An issue was discovered in the Linux kernel through 5.11.3

An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.

Twilightnetapp · cloud_backupEPSS 0.96%via NVD
CVE-2020-36180High· 8.1PoC
5y ago

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.

Midnightnetapp · cloud_backupEPSS 5.0%via NVD
CVE-2020-36179High· 8.1PoC
5y ago

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.

Midnightnetapp · cloud_backupEPSS 21%via NVD
CVE-2020-36184High· 8.1PoC
5y ago

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.

Midnightnetapp · cloud_backupEPSS 10%via NVD
CVE-2020-36181High· 8.1
5y ago

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.

Twilightnetapp · service_level_managerEPSS 5.0%via NVD
netapp vulnerabilities (CVEs) · VulnSea