Home / Security / CVE index / 2025

2025 NetApp CVEs

Showing 300 CVEs with a 2025 identifier — page 1 of 3. Sorted by CVE id.

Always verify. NetApp's advisory is authoritative for affected versions and fixes; NVD carries the CVSS record.
Showing 300 of 300
CVEPublishedSeverityCVSSSummary / Sources
CVE-2025-01672025-02-05LOW3.4When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host NVD ↗ · NTAP-20250306-0008
CVE-2025-0306——— NVD ↗ · NTAP-20250221-0009
CVE-2025-0373——— NVD ↗ · NTAP-20250207-0009
CVE-2025-0374——— NVD ↗ · NTAP-20250207-0007
CVE-2025-0395——— NVD ↗ · NTAP-20250228-0006
CVE-2025-0411——— NVD ↗ · NTAP-20250207-0005
CVE-2025-0426——— NVD ↗ · NTAP-20260327-0012
CVE-2025-0509——— NVD ↗ · NTAP-20250124-0008
CVE-2025-0620——— NVD ↗ · NTAP-20251224-0005
CVE-2025-0624——— NVD ↗ · NTAP-20250516-0006
CVE-2025-0662——— NVD ↗ · NTAP-20250207-0006
CVE-2025-0665——— NVD ↗ · NTAP-20250306-0007
CVE-2025-0689——— NVD ↗ · NTAP-20260102-0003
CVE-2025-0725——— NVD ↗ · NTAP-20250306-0009
CVE-2025-0736——— NVD ↗ · NTAP-20260206-0014
CVE-2025-0840——— NVD ↗ · NTAP-20250704-0005
CVE-2025-0913——— NVD ↗ · NTAP-20250814-0007
CVE-2025-0915——— NVD ↗ · NTAP-20250516-0002
CVE-2025-09382025-01-31MEDIUM6.3The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to NVD ↗ · NTAP-20250314-0002
CVE-2025-1000——— NVD ↗ · NTAP-20250516-0002
CVE-2025-10059——— NVD ↗ · NTAP-20251219-0009
CVE-2025-10060——— NVD ↗ · NTAP-20251219-0010
CVE-2025-10148——— NVD ↗ · NTAP-20251031-0008
CVE-2025-10230——— NVD ↗ · NTAP-20251024-0001
CVE-2025-10263——— NVD ↗ · NTAP-20260619-0015
CVE-2025-1053——— NVD ↗ · NTAP-20251114-0005
CVE-2025-10911——— NVD ↗ · NTAP-20251205-0003
CVE-2025-10942025-02-13HIGH8.1Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allo NVD ↗ · NTAP-20250221-0010
CVE-2025-10966——— NVD ↗ · NTAP-20251224-0002
CVE-2025-1097——— NVD ↗ · NTAP-20250328-0008
CVE-2025-1098——— NVD ↗ · NTAP-20250328-0008
CVE-2025-11001——— NVD ↗ · NTAP-20260213-0012
CVE-2025-11002——— NVD ↗ · NTAP-20260213-0011
CVE-2025-11081——— NVD ↗ · NTAP-20251212-0013
CVE-2025-11082——— NVD ↗ · NTAP-20251212-0014
CVE-2025-11083——— NVD ↗ · NTAP-20251212-0012
CVE-2025-111432026-03-05LOW3.7The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using mul NVD ↗ · NTAP-20260918-0013
CVE-2025-111872026-01-27MEDIUM6.1Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer derefe NVD ↗ · NTAP-20260204-0012
CVE-2025-11234——— NVD ↗ · NTAP-20260327-0015
CVE-2025-1125——— NVD ↗ · NTAP-20260102-0002
CVE-2025-11413——— NVD ↗ · NTAP-20260313-0011
CVE-2025-11468——— NVD ↗ · NTAP-20260305-0009
CVE-2025-1147——— NVD ↗ · NTAP-20250404-0003
CVE-2025-1148——— NVD ↗ · NTAP-20250404-0004
CVE-2025-1149——— NVD ↗ · NTAP-20250808-0007
CVE-2025-1150——— NVD ↗ · NTAP-20250808-0007
CVE-2025-1151——— NVD ↗ · NTAP-20250808-0007
CVE-2025-1152——— NVD ↗ · NTAP-20250808-0007
CVE-2025-1153——— NVD ↗ · NTAP-20250404-0005
CVE-2025-11731——— NVD ↗ · NTAP-20251107-0011
CVE-2025-1176——— NVD ↗ · NTAP-20250411-0007
CVE-2025-1178——— NVD ↗ · NTAP-20250411-0008
CVE-2025-1179——— NVD ↗ · NTAP-20250704-0006
CVE-2025-11802025-02-11LOW3.1A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh- NVD ↗ · NTAP-20250814-0008
CVE-2025-1181——— NVD ↗ · NTAP-20250425-0007
CVE-2025-1182——— NVD ↗ · NTAP-20251031-0004
CVE-2025-11839——— NVD ↗ · NTAP-20251212-0015
CVE-2025-1215——— NVD ↗ · NTAP-20250321-0005
CVE-2025-1217——— NVD ↗ · NTAP-20250523-0008
CVE-2025-12183——— NVD ↗ · NTAP-20260422-0010
CVE-2025-12192025-03-30MEDIUM5.3In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when requesting a HTTP resource using the DOM or S NVD ↗ · NTAP-20250523-0007
CVE-2025-1220——— NVD ↗ · NTAP-20260102-0014
CVE-2025-12543——— NVD ↗ · NTAP-20260130-0005
CVE-2025-126352025-12-08MEDIUM5.4IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are affected by cross-site scripting due to im NVD ↗ · NTAP-20260917-0001
CVE-2025-12781——— NVD ↗ · NTAP-20260305-0010
CVE-2025-12817——— NVD ↗ · NTAP-20251128-0006
CVE-2025-12818——— NVD ↗ · NTAP-20251128-0007
CVE-2025-13034——— NVD ↗ · NTAP-20260327-0006
CVE-2025-13151——— NVD ↗ · NTAP-20260116-0001
CVE-2025-134652026-01-21MEDIUM5.3Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause NVD ↗ · NTAP-20260917-0001
CVE-2025-13473——— NVD ↗ · NTAP-20260305-0001
CVE-2025-13601——— NVD ↗ · NTAP-20251224-0001
CVE-2025-13755——— NVD ↗ · NTAP-20260529-0010
CVE-2025-13836——— NVD ↗ · NTAP-20251219-0007
CVE-2025-13837——— NVD ↗ · NTAP-20251219-0008
CVE-2025-13867——— NVD ↗ · NTAP-20260227-0013
CVE-2025-13878——— NVD ↗ · NTAP-20260130-0001
CVE-2025-1390——— NVD ↗ · NTAP-20251205-0002
CVE-2025-140092026-02-18HIGH8.8A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfi NVD ↗ · NTAP-20260917-0001
CVE-2025-14017——— NVD ↗ · NTAP-20260429-0005 · NTAP-20260130-0009
CVE-2025-14087——— NVD ↗ · NTAP-20260605-0002
CVE-2025-14104——— NVD ↗ · NTAP-20260313-0012
CVE-2025-14505——— NVD ↗ · NTAP-20260410-0016
CVE-2025-14512——— NVD ↗ · NTAP-20260605-0003
CVE-2025-145242026-01-08MEDIUM5.3When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 NVD ↗ · NTAP-20260213-0015
CVE-2025-14550——— NVD ↗ · NTAP-20260305-0001
CVE-2025-14558——— NVD ↗ · NTAP-20251219-0005
CVE-2025-14688——— NVD ↗ · NTAP-20260422-0015
CVE-2025-14689——— NVD ↗ · NTAP-20260227-0014
CVE-2025-14769——— NVD ↗ · NTAP-20251219-0006
CVE-2025-14813——— NVD ↗ · NTAP-20260626-0006
CVE-2025-14819——— NVD ↗ · NTAP-20260213-0014
CVE-2025-14831——— NVD ↗ · NTAP-20260305-0015
CVE-2025-148472025-12-19HIGH7.5Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all NVD ↗ · NTAP-20260102-0016
CVE-2025-149152026-03-25MEDIUM6.5IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affected by privilege escalation. A privileged NVD ↗ · NTAP-20260917-0001
CVE-2025-149232026-03-03MEDIUM4.7IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when u NVD ↗ · NTAP-20260917-0001
CVE-2025-1493——— NVD ↗ · NTAP-20250516-0001
CVE-2025-15079——— NVD ↗ · NTAP-20260213-0013
CVE-2025-15224——— NVD ↗ · NTAP-20260327-0005
CVE-2025-152812026-01-20HIGH7.5Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized NVD ↗ · NTAP-20260313-0001
CVE-2025-15282——— NVD ↗ · NTAP-20260305-0011
CVE-2025-15284——— NVD ↗ · NTAP-20260605-0004
CVE-2025-15366——— NVD ↗ · NTAP-20260305-0012
CVE-2025-15367——— NVD ↗ · NTAP-20260305-0013
CVE-2025-154672026-01-27HIGH8.8Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summa NVD ↗ · NTAP-20260429-0005 · NTAP-20260204-0011
CVE-2025-154682026-01-27MEDIUM5.9Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL NVD ↗ · NTAP-20260204-0013
CVE-2025-15469——— NVD ↗ · NTAP-20260204-0014
CVE-2025-15547——— NVD ↗ · NTAP-20260206-0015
CVE-2025-15661——— NVD ↗ · NTAP-20260703-0019
CVE-2025-1734——— NVD ↗ · NTAP-20250523-0009
CVE-2025-1735——— NVD ↗ · NTAP-20250814-0009
CVE-2025-17362025-03-30HIGH7.3In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insuffici NVD ↗ · NTAP-20250523-0006
CVE-2025-1861——— NVD ↗ · NTAP-20250523-0005
CVE-2025-1948——— NVD ↗ · NTAP-20250711-0008
CVE-2025-1974——— NVD ↗ · NTAP-20250328-0008
CVE-2025-1976——— NVD ↗ · NTAP-20250718-0011
CVE-2025-1992——— NVD ↗ · NTAP-20250516-0002
CVE-2025-20004——— NVD ↗ · NTAP-20260403-0011
CVE-2025-20005——— NVD ↗ · NTAP-20260814-0006
CVE-2025-20027——— NVD ↗ · NTAP-20260814-0006
CVE-2025-20028——— NVD ↗ · NTAP-20260814-0006
CVE-2025-20037——— NVD ↗ · NTAP-20250912-0006
CVE-2025-20044——— NVD ↗ · NTAP-20260403-0014
CVE-2025-20053——— NVD ↗ · NTAP-20250912-0008
CVE-2025-20054——— NVD ↗ · NTAP-20260403-0009
CVE-2025-20064——— NVD ↗ · NTAP-20260814-0006
CVE-2025-20067——— NVD ↗ · NTAP-20250912-0007
CVE-2025-20068——— NVD ↗ · NTAP-20260814-0006
CVE-2025-20073——— NVD ↗ · NTAP-20260814-0006
CVE-2025-20077——— NVD ↗ · NTAP-20260522-0018
CVE-2025-20080——— NVD ↗ · NTAP-20260313-0015
CVE-2025-20096——— NVD ↗ · NTAP-20260501-0012
CVE-2025-20100——— NVD ↗ · NTAP-20260403-0010
CVE-2025-20103——— NVD ↗ · NTAP-20260403-0009
CVE-2025-20105——— NVD ↗ · NTAP-20260814-0006
CVE-2025-20109——— NVD ↗ · NTAP-20260109-0003
CVE-2025-20613——— NVD ↗ · NTAP-20250926-0007
CVE-2025-21090——— NVD ↗ · NTAP-20250912-0009
CVE-2025-21096——— NVD ↗ · NTAP-20250926-0005
CVE-2025-21490——— NVD ↗ · NTAP-20250131-0004
CVE-2025-21491——— NVD ↗ · NTAP-20250131-0004
CVE-2025-21492——— NVD ↗ · NTAP-20250124-0011
CVE-2025-21493——— NVD ↗ · NTAP-20250124-0013
CVE-2025-21494——— NVD ↗ · NTAP-20250124-0010
CVE-2025-21497——— NVD ↗ · NTAP-20250131-0004
CVE-2025-21499——— NVD ↗ · NTAP-20250124-0013
CVE-2025-21500——— NVD ↗ · NTAP-20250131-0004
CVE-2025-21501——— NVD ↗ · NTAP-20250131-0004
CVE-2025-21502——— NVD ↗ · NTAP-20250124-0009
CVE-2025-21503——— NVD ↗ · NTAP-20250131-0004
CVE-2025-21504——— NVD ↗ · NTAP-20250124-0010
CVE-2025-21505——— NVD ↗ · NTAP-20250131-0004
CVE-2025-21518——— NVD ↗ · NTAP-20250131-0004
CVE-2025-21519——— NVD ↗ · NTAP-20250131-0004
CVE-2025-21520——— NVD ↗ · NTAP-20250131-0004
CVE-2025-21521——— NVD ↗ · NTAP-20250124-0010
CVE-2025-21522——— NVD ↗ · NTAP-20250131-0004
CVE-2025-21523——— NVD ↗ · NTAP-20250131-0004
CVE-2025-21525——— NVD ↗ · NTAP-20250124-0010
CVE-2025-21529——— NVD ↗ · NTAP-20250131-0004
CVE-2025-21531——— NVD ↗ · NTAP-20250131-0004
CVE-2025-21534——— NVD ↗ · NTAP-20250124-0010
CVE-2025-21536——— NVD ↗ · NTAP-20250124-0010
CVE-2025-21540——— NVD ↗ · NTAP-20250131-0004
CVE-2025-21543——— NVD ↗ · NTAP-20250131-0004
CVE-2025-21546——— NVD ↗ · NTAP-20250131-0004
CVE-2025-21555——— NVD ↗ · NTAP-20250131-0004
CVE-2025-21559——— NVD ↗ · NTAP-20250131-0004
CVE-2025-21566——— NVD ↗ · NTAP-20250124-0014
CVE-2025-21567——— NVD ↗ · NTAP-20250124-0014
CVE-2025-21574——— NVD ↗ · NTAP-20250502-0006
CVE-2025-21575——— NVD ↗ · NTAP-20250502-0006
CVE-2025-21577——— NVD ↗ · NTAP-20250502-0006
CVE-2025-21579——— NVD ↗ · NTAP-20250502-0006
CVE-2025-21580——— NVD ↗ · NTAP-20250502-0006
CVE-2025-21581——— NVD ↗ · NTAP-20250502-0006
CVE-2025-21583——— NVD ↗ · NTAP-20250418-0009
CVE-2025-21584——— NVD ↗ · NTAP-20250502-0006
CVE-2025-21585——— NVD ↗ · NTAP-20250502-0006
CVE-2025-21587——— NVD ↗ · NTAP-20260522-0001 · NTAP-20250502-0005
CVE-2025-21588——— NVD ↗ · NTAP-20250418-0008
CVE-2025-217392025-02-27HIGH7.8In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix use-after free in init error and remove paths devm_blk_crypto_profile_i NVD ↗ · NTAP-20260925-0003
CVE-2025-218632025-03-12HIGH7.8In the Linux kernel, the following vulnerability has been resolved: io_uring: prevent opcode speculation sqe->opcode is used for different tables, make sure we NVD ↗ · NTAP-20260925-0004
CVE-2025-219472025-04-01HIGH8.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix type confusion via race condition when using ipc_msg_send_request req->handle is NVD ↗ · NTAP-20260424-0018
CVE-2025-220402025-04-16HIGH8.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix session use-after-free in multichannel connection There is a race condition betwe NVD ↗ · NTAP-20260424-0017
CVE-2025-220412025-04-16HIGH8.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_sessions_deregister() In multichannel mode, UAF issue can NVD ↗ · NTAP-20260424-0016
CVE-2025-221052025-04-16MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bonding: check xdp prog when set bond mode Following operations can trigger a warning[1]: ip NVD ↗ · NTAP-20260925-0010
CVE-2025-22134——— NVD ↗ · NTAP-20250314-0004
CVE-2025-22228——— NVD ↗ · NTAP-20250425-0009
CVE-2025-22233——— NVD ↗ · NTAP-20250704-0008
CVE-2025-22235——— NVD ↗ · NTAP-20250516-0010
CVE-2025-22247——— NVD ↗ · NTAP-20250627-0008
CVE-2025-22392——— NVD ↗ · NTAP-20250912-0005
CVE-2025-22444——— NVD ↗ · NTAP-20260814-0006
CVE-2025-2251——— NVD ↗ · NTAP-20251224-0003
CVE-2025-22839——— NVD ↗ · NTAP-20260121-0012
CVE-2025-22840——— NVD ↗ · NTAP-20260121-0013
CVE-2025-22850——— NVD ↗ · NTAP-20260814-0006
CVE-2025-22853——— NVD ↗ · NTAP-20250926-0006
CVE-2025-22866——— NVD ↗ · NTAP-20250221-0002
CVE-2025-22868——— NVD ↗ · NTAP-20250822-0008
CVE-2025-22869——— NVD ↗ · NTAP-20250411-0010
CVE-2025-22870——— NVD ↗ · NTAP-20250509-0007
CVE-2025-228712025-04-08CRITICAL9.1The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server NVD ↗ · NTAP-20250530-0004
CVE-2025-22872——— NVD ↗ · NTAP-20250516-0007
CVE-2025-22873——— NVD ↗ · NTAP-20260313-0005
CVE-2025-22874——— NVD ↗ · NTAP-20251219-0001
CVE-2025-22885——— NVD ↗ · NTAP-20260311-0004
CVE-2025-22889——— NVD ↗ · NTAP-20260121-0014
CVE-2025-23015——— NVD ↗ · NTAP-20250214-0006
CVE-2025-230482025-07-10CRITICAL9.1In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session res NVD ↗ · NTAP-20250718-0013
CVE-2025-23061——— NVD ↗ · NTAP-20250613-0004
CVE-2025-23083——— NVD ↗ · NTAP-20250228-0008
CVE-2025-23084——— NVD ↗ · NTAP-20250321-0003
CVE-2025-23085——— NVD ↗ · NTAP-20250321-0003
CVE-2025-23165——— NVD ↗ · NTAP-20251121-0012
CVE-2025-23166——— NVD ↗ · NTAP-20260311-0013
CVE-2025-23167——— NVD ↗ · NTAP-20251107-0005
CVE-2025-231842025-01-21MEDIUM5.9A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream inst NVD ↗ · NTAP-20250214-0003
CVE-2025-23362025-06-04MEDIUM4.8Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS's 'ngSanitize' module allows attackers to by NVD ↗ · NTAP-20251128-0015
CVE-2025-23366——— NVD ↗ · NTAP-20251224-0004
CVE-2025-23367——— NVD ↗ · NTAP-20251128-0012
CVE-2025-23419——— NVD ↗ · NTAP-20250904-0007
CVE-2025-24014——— NVD ↗ · NTAP-20250314-0005
CVE-2025-24293——— NVD ↗ · NTAP-20260213-0001
CVE-2025-242962025-08-12MEDIUM6.0Improper input validation in some firmware for the Intel(R) E810 Ethernet before version 4.6 may allow a privileged user to enable denial of service via local a NVD ↗ · NTAP-20260109-0004
CVE-2025-24305——— NVD ↗ · NTAP-20250912-0010
CVE-2025-24513——— NVD ↗ · NTAP-20250328-0008
CVE-2025-24514——— NVD ↗ · NTAP-20250328-0008
CVE-2025-24528——— NVD ↗ · NTAP-20260130-0015
CVE-2025-24813——— NVD ↗ · NTAP-20250321-0001
CVE-2025-24814——— NVD ↗ · NTAP-20250214-0002
CVE-2025-248512026-02-10MEDIUM6.0Uncaught exception in the firmware for some 100GbE Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x within Ring 0: Bare Metal OS may allow a deni NVD ↗ · NTAP-20260313-0014
CVE-2025-248552025-03-14HIGH7.8numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is NVD ↗ · NTAP-20250724-0012 · NTAP-20250613-0006
CVE-2025-24860——— NVD ↗ · NTAP-20250214-0005
CVE-2025-249282025-02-18HIGH7.8libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur NVD ↗ · NTAP-20250321-0006
CVE-2025-24934——— NVD ↗ · NTAP-20251107-0012
CVE-2025-24970——— NVD ↗ · NTAP-20250221-0005
CVE-2025-2518——— NVD ↗ · NTAP-20250620-0003
CVE-2025-25184——— NVD ↗ · NTAP-20250613-0001
CVE-2025-25193——— NVD ↗ · NTAP-20250221-0006
CVE-2025-25291——— NVD ↗ · NTAP-20250314-0010
CVE-2025-25292——— NVD ↗ · NTAP-20250314-0009
CVE-2025-25293——— NVD ↗ · NTAP-20250314-0008
CVE-2025-2533——— NVD ↗ · NTAP-20250829-0010
CVE-2025-2534——— NVD ↗ · NTAP-20260305-0002
CVE-2025-26403——— NVD ↗ · NTAP-20260121-0015
CVE-2025-264652025-02-18MEDIUM6.8A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine imperso NVD ↗ · NTAP-20250228-0003
CVE-2025-264662025-02-28MEDIUM5.9A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of pa NVD ↗ · NTAP-20250228-0002
CVE-2025-26512——— NVD ↗ · NTAP-20250324-0001
CVE-2025-26513——— NVD ↗ · NTAP-20250806-0001
CVE-2025-26514——— NVD ↗ · NTAP-20250910-0001
CVE-2025-26515——— NVD ↗ · NTAP-20250910-0002
CVE-2025-26516——— NVD ↗ · NTAP-20250910-0003
CVE-2025-26517——— NVD ↗ · NTAP-20250910-0004
CVE-2025-26595——— NVD ↗ · NTAP-20251107-0006
CVE-2025-26596——— NVD ↗ · NTAP-20251107-0007
CVE-2025-26597——— NVD ↗ · NTAP-20251114-0002
CVE-2025-26598——— NVD ↗ · NTAP-20251107-0008
CVE-2025-26599——— NVD ↗ · NTAP-20250904-0009
CVE-2025-26600——— NVD ↗ · NTAP-20250516-0005
CVE-2025-26601——— NVD ↗ · NTAP-20250516-0004
CVE-2025-26603——— NVD ↗ · NTAP-20250306-0003
CVE-2025-26618——— NVD ↗ · NTAP-20250627-0009
CVE-2025-26646——— NVD ↗ · NTAP-20251114-0001
CVE-2025-2668——— NVD ↗ · NTAP-20260220-0001
CVE-2025-2703——— NVD ↗ · NTAP-20250822-0004
CVE-2025-27111——— NVD ↗ · NTAP-20250613-0002
CVE-2025-271132025-02-18LOW2.9libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c. NVD ↗ · NTAP-20250724-0012 · NTAP-20250306-0004
CVE-2025-27144——— NVD ↗ · NTAP-20250808-0009
CVE-2025-27152——— NVD ↗ · NTAP-20251114-0004
CVE-2025-27209——— NVD ↗ · NTAP-20251121-0013
CVE-2025-27210——— NVD ↗ · NTAP-20250801-0001
CVE-2025-272432026-02-10MEDIUM6.0Out-of-bounds write in the firmware for some Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x within Ring 0: Bare Metal OS may allow a denial of NVD ↗ · NTAP-20260313-0014
CVE-2025-273632025-03-11HIGH8.1An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph struc NVD ↗ · NTAP-20250613-0008
CVE-2025-27391——— NVD ↗ · NTAP-20260102-0010
CVE-2025-27423——— NVD ↗ · NTAP-20250502-0002
CVE-2025-27427——— NVD ↗ · NTAP-20251003-0009
CVE-2025-27516——— NVD ↗ · NTAP-20260522-0001
CVE-2025-27533——— NVD ↗ · NTAP-20250704-0007
CVE-2025-275352026-02-10MEDIUM5.3Exposed ioctl with insufficient access control in the firmware for some Intel(R) Ethernet Connection E825-C. before version NVM ver. 3.84 within Ring 0: Bare Me NVD ↗ · NTAP-20260313-0014
CVE-2025-275582025-05-21CRITICAL9.1IEEE P802.11-REVme D1.1 through D7.0 allows FragAttacks against mesh networks. In mesh networks using Wi-Fi Protected Access (WPA, WPA2, or WPA3) or Wired Equiv NVD ↗ · NTAP-20260116-0017
CVE-2025-27560——— NVD ↗ · NTAP-20260522-0020
CVE-2025-27572——— NVD ↗ · NTAP-20260311-0003
CVE-2025-27610——— NVD ↗ · NTAP-20250613-0003
CVE-2025-27708——— NVD ↗ · NTAP-20260313-0013
CVE-2025-27817——— NVD ↗ · NTAP-20251024-0006
CVE-2025-27818——— NVD ↗ · NTAP-20251024-0007
CVE-2025-27819——— NVD ↗ · NTAP-20251024-0008
CVE-2025-278202025-04-24HIGH7.5A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apach NVD ↗ · NTAP-20250516-0003
CVE-2025-27940——— NVD ↗ · NTAP-20260311-0003
CVE-2025-28842025-06-10MEDIUM6.6TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with NVD ↗ · NTAP-20250620-0007
CVE-2025-2900——— NVD ↗ · NTAP-20260522-0001
CVE-2025-29087——— NVD ↗ · NTAP-20250704-0003
CVE-2025-29088——— NVD ↗ · NTAP-20250605-0010
CVE-2025-29768——— NVD ↗ · NTAP-20250502-0001
CVE-2025-29927——— NVD ↗ · NTAP-20250328-0002
CVE-2025-30065——— NVD ↗ · NTAP-20260123-0008 · NTAP-20250711-0001
CVE-2025-30167——— NVD ↗ · NTAP-20260522-0001
CVE-2025-30185——— NVD ↗ · NTAP-20260522-0019

Years: 2026 · 2025 · 2024 · 2023 · 2022 · 2021 · 2020 · 2019 · 2018 · 2017 · 2016 · 2015 · 2014 · 2013 · 2012 · 2011 · 2010 · 2009 · 2008 · 2007 · 2006 · 2005 · 2004 · 2003 · 2002 · 1999

← CVE index · Security hub