Skip to main content

Vendor/product archive

netapp / active_iq_unified_manager CVEs

Beta · best-effort

838 CVEs tagged to netapp / active_iq_unified_manager48 Critical, 171 High, 536 Medium, 83 Low, 0 Unrated.

CVE-2025-24928

Published Feb 18, 2025

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted do…

CVSS 7.8 · High

CVE-2024-56171

Published Feb 18, 2025

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML…

CVSS 7.8 · High

CVE-2025-0411

Published Jan 25, 2025

7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User…

CVSS 7.0 · High
evidence mentions
11
Buzz score
69.8
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-21502

Published Jan 21, 2025

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affecte…

CVSS 4.8 · Medium
evidence mentions
5
Buzz score
30.9

CVE-2024-47554

Published Oct 3, 2024

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing…

CVSS 4.3 · Medium

CVE-2024-7254

Published Sep 19, 2024

Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. Sta…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2024-8096

Published Sep 11, 2024

When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect…

CVSS 6.5 · Medium

CVE-2024-21147

Published Jul 16, 2024

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affecte…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2024-21140

Published Jul 16, 2024

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affecte…

CVSS 4.8 · Medium

CVE-2024-21138

Published Jul 16, 2024

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affecte…

CVSS 3.7 · Low
Showing 1-25 of 838 CVEsPage 1 of 34