Netapp Security Vulnerabilities (CVEs)

Track 350 security vulnerabilities affecting Netapp products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

66 Critical
260 High
22 Medium
2 Low
🔔 Get Alerts for Netapp
CVE-2023-2829 7.5

A vulnerability in BIND 9 DNS servers configured with DNSSEC validation and aggressive cache usage allows remote attackers to cause denial of service ...

Jun 21, 2023
CVE-2023-35826 7.0

A use-after-free vulnerability in the Linux kernel's cedrus video decoder driver allows local attackers to potentially escalate privileges or cause de...

Jun 18, 2023
CVE-2023-35828 7.0

A use-after-free vulnerability in the Renesas USB3 gadget driver in Linux kernel versions before 6.3.2 allows local attackers to potentially execute a...

Jun 18, 2023
CVE-2023-35788 7.8

This vulnerability allows attackers to perform out-of-bounds writes in the Linux kernel's flower classifier code via specially crafted GENEVE packets....

Jun 16, 2023
CVE-2023-3141 7.1

A use-after-free vulnerability in the Linux kernel's r592 memory stick host driver allows local attackers to crash the system during device disconnect...

Jun 9, 2023
CVE-2023-3111 7.8

A use-after-free vulnerability in the Linux kernel's Btrfs filesystem allows local attackers to potentially crash the system or execute arbitrary code...

Jun 5, 2023
CVE-2023-2953 7.5

This vulnerability in OpenLDAP causes a null pointer dereference in the ber_memalloc_x() function, which can lead to denial of service (DoS) by crashi...

May 30, 2023
CVE-2023-28322 3.7

This vulnerability in curl versions before 8.1.0 causes information disclosure when reusing a handle between PUT and POST requests. It affects applica...

May 26, 2023
CVE-2023-28319 7.5

CVE-2023-28319 is a use-after-free vulnerability in curl/libcurl versions before 8.1.0 that occurs during SSH server public key verification. When ver...

May 26, 2023
CVE-2023-28709 7.5

This vulnerability allows attackers to bypass request size limits in Apache Tomcat by submitting exactly maxParameterCount query parameters, potential...

May 22, 2023
CVE-2023-2124 7.8

A local privilege escalation vulnerability exists in the Linux kernel's XFS filesystem when restoring from a dirty log journal after failure. This all...

May 15, 2023
CVE-2023-1096 9.8

CVE-2023-1096 is a critical authentication bypass vulnerability in NetApp SnapCenter that allows remote unauthenticated attackers to gain administrati...

May 12, 2023
CVE-2023-32233 7.8

CVE-2023-32233 is a use-after-free vulnerability in the Linux kernel's Netfilter nf_tables subsystem that allows unprivileged local users to perform a...

May 8, 2023
CVE-2023-28656 8.1

CVE-2023-28656 is an authorization bypass vulnerability in NGINX Management Suite that allows authenticated users to access configuration objects outs...

May 3, 2023
CVE-2023-2006 7.0

This CVE describes a race condition vulnerability in the Linux kernel's RxRPC network protocol, where improper locking during bundle processing could ...

Apr 24, 2023
CVE-2023-21930 7.4

This vulnerability in Oracle Java SE and GraalVM Enterprise Edition's JSSE component allows attackers to compromise confidentiality and integrity of d...

Apr 18, 2023
CVE-2023-1989 7.0

A use-after-free vulnerability in the Linux kernel's Bluetooth subsystem allows local attackers to potentially execute arbitrary code or cause denial ...

Apr 11, 2023
CVE-2023-1838 7.1

A use-after-free vulnerability in the Linux kernel's virtio network driver allows local attackers to crash the system or potentially leak kernel memor...

Apr 5, 2023
CVE-2023-28464 7.8

This vulnerability is a use-after-free and double-free flaw in the Linux kernel's Bluetooth subsystem that can lead to privilege escalation. Attackers...

Mar 31, 2023
CVE-2023-27533 8.8

A vulnerability in curl versions before 8.0 allows attackers to inject malicious content during TELNET protocol negotiation when user input is accepte...

Mar 30, 2023
CVE-2023-27534 8.8

A path traversal vulnerability in curl's SFTP implementation allows attackers to bypass path filtering by using specially crafted paths containing til...

Mar 30, 2023
CVE-2023-1077 7.0

CVE-2023-1077 is a type confusion vulnerability in the Linux kernel's real-time scheduler that can lead to memory corruption. This allows local attack...

Mar 27, 2023
CVE-2023-1380 7.1

This CVE describes an out-of-bounds read vulnerability in the Broadcom brcmfmac WiFi driver in the Linux kernel. When processing association request d...

Mar 27, 2023
CVE-2023-0386 7.8

This Linux kernel vulnerability allows local users to escalate privileges by exploiting a uid mapping bug in OverlayFS when copying capable files betw...

Mar 22, 2023
CVE-2022-38734 7.5

CVE-2022-38734 is a Denial of Service vulnerability in NetApp StorageGRID's Local Distribution Router service. Attackers can crash the LDR service by ...

Mar 2, 2023
CVE-2023-23914 9.1

A vulnerability in curl versions before 7.88.0 causes HSTS (HTTP Strict Transport Security) to fail when processing multiple URLs sequentially on the ...

Feb 23, 2023
CVE-2023-24329 7.5

This vulnerability in Python's urllib.parse component allows attackers to bypass URL blocklisting mechanisms by using URLs that begin with blank chara...

Feb 17, 2023
CVE-2023-0361 7.4

This CVE describes a timing side-channel vulnerability in GnuTLS that allows attackers to perform Bleichenbacher-style attacks against RSA encryption....

Feb 15, 2023
CVE-2022-32221 9.8

This vulnerability in libcurl allows an attacker to cause memory corruption or data leakage when reusing a handle from a PUT to a POST request. Applic...

Dec 5, 2022
CVE-2022-35737 7.5

This SQLite vulnerability allows array-bounds overflow when processing extremely large string arguments (billions of bytes) through certain C API func...

Aug 3, 2022
CVE-2022-31107 7.1

This vulnerability allows an authenticated malicious user to take over another user's Grafana account via OAuth login manipulation. It affects Grafana...

Jul 15, 2022
CVE-2022-31097 7.3

Grafana versions 8.x and 9.x before specific patched releases are vulnerable to stored cross-site scripting (XSS) in the Unified Alerting feature. An ...

Jul 15, 2022
CVE-2022-2048 7.5

This vulnerability in Eclipse Jetty's HTTP/2 server implementation allows attackers to cause denial of service by sending invalid HTTP/2 requests that...

Jul 7, 2022
CVE-2022-32207 9.8

CVE-2022-32207 is a privilege escalation vulnerability in curl versions before 7.84.0 where file permission widening occurs during atomic file operati...

Jul 7, 2022
CVE-2021-38945 9.8

CVE-2021-38945 is a critical vulnerability in IBM Cognos Analytics that allows remote attackers to upload arbitrary files due to improper content vali...

Jun 24, 2022
CVE-2022-29244 7.5

This vulnerability in npm causes workspace operations to ignore .gitignore and .npmignore exclusion rules, potentially exposing sensitive files. Anyon...

Jun 13, 2022
CVE-2022-26377 7.5

This HTTP request smuggling vulnerability in Apache HTTP Server's mod_proxy_ajp module allows attackers to bypass security controls and smuggle malici...

Jun 9, 2022
CVE-2022-28615 9.1

This vulnerability in Apache HTTP Server 2.4.53 and earlier could cause crashes or information disclosure due to a buffer overflow in the ap_strcmp_ma...

Jun 9, 2022
CVE-2022-30556 7.5

CVE-2022-30556 is a buffer overflow vulnerability in Apache HTTP Server's r:wsread() function that can cause memory corruption. It affects Apache HTTP...

Jun 9, 2022
CVE-2022-31813 9.8

This vulnerability in Apache HTTP Server allows attackers to bypass IP-based authentication by manipulating the Connection header to prevent X-Forward...

Jun 9, 2022
CVE-2022-1998 7.8

CVE-2022-1998 is a use-after-free vulnerability in the Linux kernel's fanotify file system notification subsystem. A local attacker could trigger this...

Jun 9, 2022
CVE-2022-32250 7.8

This vulnerability in the Linux kernel's netfilter component allows a local user with namespace creation privileges to escalate to root via a use-afte...

Jun 2, 2022
CVE-2022-27780 7.5

The curl URL parser incorrectly accepts percent-encoded URL separators like '/' in hostnames, allowing attackers to bypass filters and checks by makin...

Jun 2, 2022
CVE-2022-27775 7.5

This curl vulnerability allows information disclosure when an attacker can force curl to reuse an existing IPv6 connection from the pool with a differ...

Jun 2, 2022
CVE-2022-27778 8.1

This vulnerability in curl versions before 7.83.1 could cause the wrong file to be deleted when using the --no-clobber option with --remove-on-error. ...

Jun 2, 2022
CVE-2022-1786 7.8

A use-after-free vulnerability in the Linux kernel's io_uring subsystem allows local attackers to crash the system or potentially escalate privileges....

Jun 2, 2022
CVE-2022-1652 7.8

CVE-2022-1652 is a use-after-free vulnerability in the Linux kernel's floppy disk driver that allows local attackers to execute arbitrary code or caus...

Jun 2, 2022
CVE-2022-1882 7.8

CVE-2022-1882 is a use-after-free vulnerability in the Linux kernel's pipes functionality that allows a local user to crash the system or potentially ...

May 26, 2022
CVE-2022-1664 9.8

This vulnerability in dpkg allows directory traversal when extracting specially crafted source packages, enabling attackers to write arbitrary files o...

May 26, 2022
CVE-2022-1183 7.5

This vulnerability causes the BIND DNS server to crash with an assertion failure when configured with HTTP references in listen-on statements. It affe...

May 19, 2022

Why Monitor Netapp Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 350+ known vulnerabilities affecting Netapp products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Netapp packages in under 60 seconds. No agents required - completely agentless scanning that works across Netapp deployments.

Free vulnerability database: Access detailed information about every Netapp CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Netapp CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Netapp CVEs Free