Home / Security / CVE index / 2026
2026 NetApp CVEs (page 3)
Showing 300 CVEs with a 2026 identifier — page 3 of 4. Sorted by CVE id.
Always verify. NetApp's advisory is authoritative for affected versions and fixes; NVD carries the CVSS record.
Showing 300 of 300
| CVE | Published | Severity | CVSS | Summary / Sources |
|---|---|---|---|---|
CVE-2026-46242 | — | — | — | NVD ↗ · NTAP-20260710-0020 |
CVE-2026-46300 | — | — | — | NVD ↗ · NTAP-20260522-0016 |
CVE-2026-46303 | — | — | — | NVD ↗ · NTAP-20260724-0007 |
CVE-2026-46304 | — | — | — | NVD ↗ · NTAP-20260724-0008 |
CVE-2026-46306 | — | — | — | NVD ↗ · NTAP-20260724-0009 |
CVE-2026-46307 | — | — | — | NVD ↗ · NTAP-20260724-0006 |
CVE-2026-46331 | — | — | — | NVD ↗ · NTAP-20260703-0002 |
CVE-2026-46333 | — | — | — | NVD ↗ · NTAP-20260717-0009 |
CVE-2026-46340 | — | — | — | NVD ↗ · NTAP-20260626-0020 |
CVE-2026-4652 | — | — | — | NVD ↗ · NTAP-20260417-0004 |
CVE-2026-46595 | — | — | — | NVD ↗ · NTAP-20260617-0019 |
CVE-2026-46597 | — | — | — | NVD ↗ · NTAP-20260617-0019 |
CVE-2026-46598 | — | — | — | NVD ↗ · NTAP-20260617-0019 |
CVE-2026-46605 | — | — | — | NVD ↗ · NTAP-20260710-0001 |
CVE-2026-46863 | — | — | — | NVD ↗ · NTAP-20260626-0016 |
CVE-2026-46917 | — | — | — | NVD ↗ · NTAP-20260724-0019 |
CVE-2026-46936 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-46968 | — | — | — | NVD ↗ · NTAP-20260724-0016 |
CVE-2026-47008 | — | — | — | NVD ↗ · NTAP-20260731-0019 |
CVE-2026-47010 | — | — | — | NVD ↗ · NTAP-20260724-0016 |
CVE-2026-47012 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-47013 | — | — | — | NVD ↗ · NTAP-20260724-0020 |
CVE-2026-47021 | — | — | — | NVD ↗ · NTAP-20260724-0016 |
CVE-2026-47023 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-47027 | — | — | — | NVD ↗ · NTAP-20260724-0016 |
CVE-2026-47030 | — | — | — | NVD ↗ · NTAP-20260724-0020 |
CVE-2026-47034 | — | — | — | NVD ↗ · NTAP-20260724-0020 |
CVE-2026-47035 | — | — | — | NVD ↗ · NTAP-20260724-0020 |
CVE-2026-47052 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-47057 | — | — | — | NVD ↗ · NTAP-20260724-0017 |
CVE-2026-47058 | — | — | — | NVD ↗ · NTAP-20260724-0017 |
CVE-2026-47059 | — | — | — | NVD ↗ · NTAP-20260724-0016 |
CVE-2026-47063 | — | — | — | NVD ↗ · NTAP-20260724-0016 |
CVE-2026-47064 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-47244 | 2026-06-12 | MEDIUM | 5.3 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, DefaultHttp2Connecti NVD ↗ · NTAP-20260917-0001 · NTAP-20260626-0020 |
CVE-2026-4747 | — | — | — | NVD ↗ · NTAP-20260410-0014 |
CVE-2026-4748 | — | — | — | NVD ↗ · NTAP-20260417-0006 |
CVE-2026-47691 | — | — | — | NVD ↗ · NTAP-20260626-0020 |
CVE-2026-47770 | 2026-06-25 | MEDIUM | 5.5 | jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq's ordinary NVD ↗ · NTAP-20260925-0026 |
CVE-2026-47884 | 2026-08-27 | CRITICAL | 9.8 | Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where NVD ↗ · NTAP-20260924-0001 |
CVE-2026-47886 | 2026-08-27 | HIGH | 7.5 | Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power oper NVD ↗ · NTAP-20260924-0005 |
CVE-2026-47887 | 2026-08-27 | MEDIUM | 6.1 | A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open NVD ↗ · NTAP-20260924-0008 |
CVE-2026-47888 | — | — | — | NVD ↗ · NTAP-20260917-0020 |
CVE-2026-47891 | 2026-08-27 | CRITICAL | 9.8 | A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7. NVD ↗ · NTAP-20260924-0002 |
CVE-2026-47892 | 2026-08-27 | CRITICAL | 9.8 | A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spr NVD ↗ · NTAP-20260924-0003 |
CVE-2026-47893 | 2026-08-27 | HIGH | 7.5 | A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception r NVD ↗ · NTAP-20260924-0006 |
CVE-2026-4800 | — | — | — | NVD ↗ · NTAP-20260917-0001 · NTAP-20260717-0010 |
CVE-2026-48006 | — | — | — | NVD ↗ · NTAP-20260626-0020 |
CVE-2026-48043 | 2026-06-12 | MEDIUM | 5.3 | Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, NVD ↗ · NTAP-20260917-0001 · NTAP-20260626-0020 |
CVE-2026-48059 | — | — | — | NVD ↗ · NTAP-20260626-0020 |
CVE-2026-48095 | 2026-06-05 | HIGH | 8.8 | 7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in t NVD ↗ · NTAP-20260619-0001 |
CVE-2026-48155 | 2026-05-28 | MEDIUM | 5.5 | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to large memory us NVD ↗ · NTAP-20260917-0001 |
CVE-2026-48156 | 2026-05-28 | LOW | 3.3 | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. NVD ↗ · NTAP-20260917-0001 |
CVE-2026-48617 | 2026-06-18 | HIGH | 8.2 | A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or b NVD ↗ · NTAP-20260925-0017 |
CVE-2026-4867 | 2026-03-26 | HIGH | 7.5 | Impact: A bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (. NVD ↗ · NTAP-20260917-0001 |
CVE-2026-48710 | 2026-05-26 | MEDIUM | 6.5 | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `re NVD ↗ · NTAP-20260917-0001 · NTAP-20260605-0011 |
CVE-2026-48735 | 2026-05-28 | MEDIUM | 5.5 | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can craft a PDF which leads to large memory us NVD ↗ · NTAP-20260917-0001 |
CVE-2026-48748 | — | — | — | NVD ↗ · NTAP-20260724-0013 |
CVE-2026-48817 | 2026-06-17 | MEDIUM | 5.3 | Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the NVD ↗ · NTAP-20260917-0001 |
CVE-2026-48818 | 2026-06-17 | HIGH | 7.5 | Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.c NVD ↗ · NTAP-20260917-0001 |
CVE-2026-48864 | 2026-05-26 | HIGH | 7.8 | A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insuff NVD ↗ · NTAP-20260925-0022 |
CVE-2026-48913 | — | — | — | NVD ↗ · NTAP-20260610-0004 |
CVE-2026-48937 | 2026-06-18 | HIGH | 7.5 | A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affects two supported relea NVD ↗ · NTAP-20260925-0018 |
CVE-2026-49157 | — | — | — | NVD ↗ · NTAP-20260710-0001 |
CVE-2026-49261 | — | — | — | NVD ↗ · NTAP-20260710-0016 |
CVE-2026-49270 | — | — | — | NVD ↗ · NTAP-20260710-0001 |
CVE-2026-49412 | — | — | — | NVD ↗ · NTAP-20260619-0018 |
CVE-2026-49413 | — | — | — | NVD ↗ · NTAP-20260626-0003 |
CVE-2026-49414 | — | — | — | NVD ↗ · NTAP-20260619-0017 |
CVE-2026-49415 | — | — | — | NVD ↗ · NTAP-20260710-0012 |
CVE-2026-49416 | — | — | — | NVD ↗ · NTAP-20260619-0019 |
CVE-2026-49417 | — | — | — | NVD ↗ · NTAP-20260626-0002 |
CVE-2026-49418 | — | — | — | NVD ↗ · NTAP-20260710-0014 |
CVE-2026-49419 | — | — | — | NVD ↗ · NTAP-20260710-0013 |
CVE-2026-49420 | — | — | — | NVD ↗ · NTAP-20260710-0011 |
CVE-2026-49421 | — | — | — | NVD ↗ · NTAP-20260710-0010 |
CVE-2026-49422 | — | — | — | NVD ↗ · NTAP-20260710-0015 |
CVE-2026-49423 | — | — | — | NVD ↗ · NTAP-20260710-0007 |
CVE-2026-49424 | — | — | — | NVD ↗ · NTAP-20260710-0006 |
CVE-2026-49425 | — | — | — | NVD ↗ · NTAP-20260710-0005 |
CVE-2026-49426 | — | — | — | NVD ↗ · NTAP-20260710-0008 |
CVE-2026-49427 | — | — | — | NVD ↗ · NTAP-20260710-0009 |
CVE-2026-49428 | — | — | — | NVD ↗ · NTAP-20260710-0009 |
CVE-2026-49429 | — | — | — | NVD ↗ · NTAP-20260828-0005 |
CVE-2026-49430 | — | — | — | NVD ↗ · NTAP-20260828-0005 |
CVE-2026-49431 | — | — | — | NVD ↗ · NTAP-20260828-0005 |
CVE-2026-49460 | 2026-06-22 | LOW | 3.3 | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. NVD ↗ · NTAP-20260917-0001 |
CVE-2026-49461 | 2026-06-22 | MEDIUM | 5.5 | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to large memory us NVD ↗ · NTAP-20260917-0001 |
CVE-2026-49759 | 2026-06-10 | HIGH | 8.2 | Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP NVD ↗ · NTAP-20260626-0014 |
CVE-2026-49839 | 2026-06-25 | HIGH | 7.1 | jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bo NVD ↗ · NTAP-20260925-0024 |
CVE-2026-49844 | — | — | — | NVD ↗ · NTAP-20260724-0012 |
CVE-2026-49851 | — | — | — | NVD ↗ · NTAP-20260917-0001 |
CVE-2026-49875 | — | — | — | NVD ↗ · NTAP-20260618-0004 |
CVE-2026-49975 | — | — | — | NVD ↗ · NTAP-20260610-0003 |
CVE-2026-50009 | — | — | — | NVD ↗ · NTAP-20260724-0013 |
CVE-2026-50010 | 2026-06-12 | HIGH | 7.5 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFa NVD ↗ · NTAP-20260917-0005 · NTAP-20260626-0020 |
CVE-2026-50011 | — | — | — | NVD ↗ · NTAP-20260626-0020 |
CVE-2026-50020 | — | — | — | NVD ↗ · NTAP-20260626-0020 |
CVE-2026-50219 | 2026-06-04 | MEDIUM | 4.9 | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within h NVD ↗ · NTAP-20260924-0022 |
CVE-2026-50229 | — | — | — | NVD ↗ · NTAP-20260703-0016 |
CVE-2026-50560 | — | — | — | NVD ↗ · NTAP-20260626-0020 |
CVE-2026-50623 | — | — | — | NVD ↗ · NTAP-20260618-0004 |
CVE-2026-50627 | — | — | — | NVD ↗ · NTAP-20260618-0004 |
CVE-2026-50628 | — | — | — | NVD ↗ · NTAP-20260618-0004 |
CVE-2026-50629 | — | — | — | NVD ↗ · NTAP-20260618-0004 |
CVE-2026-50630 | — | — | — | NVD ↗ · NTAP-20260618-0004 |
CVE-2026-50631 | — | — | — | NVD ↗ · NTAP-20260618-0004 |
CVE-2026-50632 | — | — | — | NVD ↗ · NTAP-20260618-0004 |
CVE-2026-50633 | — | — | — | NVD ↗ · NTAP-20260618-0004 |
CVE-2026-50634 | — | — | — | NVD ↗ · NTAP-20260618-0004 |
CVE-2026-50645 | — | — | — | NVD ↗ · NTAP-20260618-0004 |
CVE-2026-53359 | — | — | — | NVD ↗ · NTAP-20260710-0017 |
CVE-2026-53362 | — | — | — | NVD ↗ · NTAP-20260903-0010 |
CVE-2026-53404 | — | — | — | NVD ↗ · NTAP-20260703-0017 |
CVE-2026-53434 | — | — | — | NVD ↗ · NTAP-20260703-0013 |
CVE-2026-53537 | 2026-06-22 | LOW | 3.7 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with em NVD ↗ · NTAP-20260917-0001 |
CVE-2026-53538 | 2026-06-22 | LOW | 3.7 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlenco NVD ↗ · NTAP-20260917-0001 |
CVE-2026-53539 | 2026-06-22 | HIGH | 7.5 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlencoded bodies, QuerystringParser located t NVD ↗ · NTAP-20260917-0001 |
CVE-2026-53540 | 2026-06-22 | LOW | 3.7 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound i NVD ↗ · NTAP-20260917-0001 |
CVE-2026-53655 | — | — | — | NVD ↗ · NTAP-20260807-0006 |
CVE-2026-5398 | — | — | — | NVD ↗ · NTAP-20260429-0013 |
CVE-2026-54225 | — | — | — | NVD ↗ · NTAP-20260911-0008 |
CVE-2026-54282 | 2026-06-22 | LOW | 3.7 | Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because NVD ↗ · NTAP-20260917-0001 |
CVE-2026-54283 | 2026-06-22 | HIGH | 7.5 | Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption whi NVD ↗ · NTAP-20260917-0001 |
CVE-2026-54293 | 2026-06-22 | HIGH | 7.5 | NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Proce NVD ↗ · NTAP-20260917-0001 |
CVE-2026-5435 | — | — | — | NVD ↗ · NTAP-20260513-0005 |
CVE-2026-54369 | — | — | — | NVD ↗ · NTAP-20260828-0010 |
CVE-2026-54370 | — | — | — | NVD ↗ · NTAP-20260828-0011 |
CVE-2026-54371 | — | — | — | NVD ↗ · NTAP-20260828-0012 |
CVE-2026-5450 | — | — | — | NVD ↗ · NTAP-20260513-0006 |
CVE-2026-54512 | — | — | — | NVD ↗ · NTAP-20260828-0013 |
CVE-2026-54513 | — | — | — | NVD ↗ · NTAP-20260828-0014 |
CVE-2026-54530 | 2026-06-22 | MEDIUM | 5.5 | pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loo NVD ↗ · NTAP-20260917-0001 |
CVE-2026-54531 | 2026-06-22 | MEDIUM | 5.5 | pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loo NVD ↗ · NTAP-20260917-0001 |
CVE-2026-54651 | 2026-06-22 | MEDIUM | 5.5 | pypdf is a free and open-source pure-python PDF library. Prior to 6.13.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loo NVD ↗ · NTAP-20260917-0001 |
CVE-2026-54679 | 2026-06-25 | MEDIUM | 5.5 | jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive NVD ↗ · NTAP-20260925-0025 |
CVE-2026-54874 | — | — | — | NVD ↗ · NTAP-20260903-0001 · NTAP-20260902-0005 |
CVE-2026-54876 | — | — | — | NVD ↗ · NTAP-20260814-0019 |
CVE-2026-55200 | 2026-06-17 | HIGH | 8.1 | libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on pac NVD ↗ · NTAP-20260703-0020 |
CVE-2026-55276 | — | — | — | NVD ↗ · NTAP-20260703-0018 |
CVE-2026-5545 | — | — | — | NVD ↗ · NTAP-20260515-0005 |
CVE-2026-55831 | 2026-07-21 | HIGH | 7.5 | Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder NVD ↗ · NTAP-20260917-0005 |
CVE-2026-55833 | 2026-07-21 | HIGH | 7.5 | Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding co NVD ↗ · NTAP-20260917-0005 |
CVE-2026-5588 | — | — | — | NVD ↗ · NTAP-20260626-0006 |
CVE-2026-55953 | — | — | — | NVD ↗ · NTAP-20260828-0008 |
CVE-2026-55955 | — | — | — | NVD ↗ · NTAP-20260703-0015 |
CVE-2026-55956 | — | — | — | NVD ↗ · NTAP-20260703-0016 |
CVE-2026-55957 | — | — | — | NVD ↗ · NTAP-20260703-0014 |
CVE-2026-5598 | — | — | — | NVD ↗ · NTAP-20260626-0006 |
CVE-2026-56131 | 2026-06-19 | MEDIUM | 4.9 | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-fre NVD ↗ · NTAP-20260924-0023 |
CVE-2026-56144 | — | — | — | NVD ↗ · NTAP-20260807-0020 |
CVE-2026-56145 | — | — | — | NVD ↗ · NTAP-20260807-0015 |
CVE-2026-56403 | 2026-06-21 | MEDIUM | 6.9 | libexpat before 2.8.2 has an integer overflow in storeAtts. NVD ↗ · NTAP-20260924-0012 |
CVE-2026-56404 | 2026-06-21 | MEDIUM | 6.9 | libexpat before 2.8.2 has an integer overflow in addBinding. NVD ↗ · NTAP-20260924-0013 |
CVE-2026-56405 | 2026-06-21 | MEDIUM | 6.9 | libexpat before 2.8.2 has an integer overflow in getAttributeId. NVD ↗ · NTAP-20260924-0014 |
CVE-2026-56406 | 2026-06-21 | MEDIUM | 6.9 | libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse. NVD ↗ · NTAP-20260924-0015 |
CVE-2026-56407 | 2026-06-21 | MEDIUM | 6.9 | libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen. NVD ↗ · NTAP-20260924-0016 |
CVE-2026-56408 | 2026-06-21 | MEDIUM | 6.9 | libexpat before 2.8.2 has an integer overflow in copyString. NVD ↗ · NTAP-20260924-0017 |
CVE-2026-56409 | 2026-06-21 | MEDIUM | 6.5 | xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used. NVD ↗ · NTAP-20260924-0020 |
CVE-2026-56410 | 2026-06-21 | MEDIUM | 6.9 | xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId. NVD ↗ · NTAP-20260924-0018 |
CVE-2026-56411 | — | — | — | NVD ↗ · NTAP-20260924-0019 |
CVE-2026-56412 | 2026-06-21 | MEDIUM | 4.9 | libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers i NVD ↗ · NTAP-20260924-0024 |
CVE-2026-56745 | 2026-07-21 | HIGH | 7.5 | Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4 NVD ↗ · NTAP-20260917-0005 |
CVE-2026-56746 | 2026-07-21 | MEDIUM | 6.5 | Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1. NVD ↗ · NTAP-20260917-0005 |
CVE-2026-56819 | 2026-07-21 | HIGH | 7.5 | Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4 NVD ↗ · NTAP-20260917-0005 |
CVE-2026-56848 | 2026-08-04 | HIGH | 7.5 | A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a NVD ↗ · NTAP-20260925-0019 |
CVE-2026-5704 | — | — | — | NVD ↗ · NTAP-20260424-0010 |
CVE-2026-57204 | 2026-06-30 | MEDIUM | 6.5 | pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An attacker who uses this vulnerability can c NVD ↗ · NTAP-20260917-0001 |
CVE-2026-5773 | — | — | — | NVD ↗ · NTAP-20260515-0004 |
CVE-2026-57817 | — | — | — | NVD ↗ · NTAP-20260911-0006 |
CVE-2026-57818 | — | — | — | NVD ↗ · NTAP-20260911-0007 |
CVE-2026-57819 | — | — | — | NVD ↗ · NTAP-20260911-0009 |
CVE-2026-58011 | 2026-06-30 | MEDIUM | 6.5 | A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDate NVD ↗ · NTAP-20260924-0026 |
CVE-2026-58012 | 2026-06-30 | MEDIUM | 6.5 | A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement NVD ↗ · NTAP-20260924-0027 |
CVE-2026-58013 | 2026-06-30 | MEDIUM | 6.5 | A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length NVD ↗ · NTAP-20260924-0028 |
CVE-2026-58015 | 2026-06-30 | MEDIUM | 5.9 | A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parame NVD ↗ · NTAP-20260924-0029 |
CVE-2026-58041 | 2026-08-04 | MEDIUM | 5.3 | A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared stateme NVD ↗ · NTAP-20260925-0021 |
CVE-2026-58043 | — | — | — | NVD ↗ · NTAP-20260821-0001 |
CVE-2026-58052 | — | — | — | NVD ↗ · NTAP-20260724-0011 |
CVE-2026-58055 | 2026-06-28 | MEDIUM | 5.4 | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend NVD ↗ · NTAP-20260925-0027 |
CVE-2026-58081 | — | — | — | NVD ↗ · NTAP-20260710-0004 |
CVE-2026-58082 | — | — | — | NVD ↗ · NTAP-20260710-0004 |
CVE-2026-58083 | — | — | — | NVD ↗ · NTAP-20260814-0013 |
CVE-2026-58084 | — | — | — | NVD ↗ · NTAP-20260814-0018 |
CVE-2026-58085 | — | — | — | NVD ↗ · NTAP-20260814-0016 |
CVE-2026-58086 | — | — | — | NVD ↗ · NTAP-20260814-0017 |
CVE-2026-58087 | — | — | — | NVD ↗ · NTAP-20260814-0014 |
CVE-2026-58088 | — | — | — | NVD ↗ · NTAP-20260814-0015 |
CVE-2026-58089 | — | — | — | NVD ↗ · NTAP-20260903-0003 |
CVE-2026-58090 | — | — | — | NVD ↗ · NTAP-20260903-0004 |
CVE-2026-58091 | — | — | — | NVD ↗ · NTAP-20260903-0005 |
CVE-2026-58092 | — | — | — | NVD ↗ · NTAP-20260903-0008 |
CVE-2026-58093 | — | — | — | NVD ↗ · NTAP-20260903-0007 |
CVE-2026-58094 | — | — | — | NVD ↗ · NTAP-20260903-0006 |
CVE-2026-58095 | — | — | — | NVD ↗ · NTAP-20260903-0002 |
CVE-2026-58096 | — | — | — | NVD ↗ · NTAP-20260903-0002 |
CVE-2026-58097 | — | — | — | NVD ↗ · NTAP-20260903-0002 |
CVE-2026-58216 | — | — | — | NVD ↗ · NTAP-20260821-0015 |
CVE-2026-58218 | — | — | — | NVD ↗ · NTAP-20260821-0016 |
CVE-2026-58221 | — | — | — | NVD ↗ · NTAP-20260821-0017 |
CVE-2026-58222 | — | — | — | NVD ↗ · NTAP-20260821-0018 |
CVE-2026-58224 | — | — | — | NVD ↗ · NTAP-20260821-0019 |
CVE-2026-59083 | — | — | — | NVD ↗ · NTAP-20260717-0018 |
CVE-2026-59084 | — | — | — | NVD ↗ · NTAP-20260717-0019 |
CVE-2026-59250 | — | — | — | NVD ↗ · NTAP-20260828-0009 |
CVE-2026-5928 | — | — | — | NVD ↗ · NTAP-20260513-0004 |
CVE-2026-59280 | 2026-08-27 | MEDIUM | 4.3 | Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from unt NVD ↗ · NTAP-20260924-0011 |
CVE-2026-59281 | 2026-08-27 | MEDIUM | 6.1 | Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and then render field errors using the no-argument Err NVD ↗ · NTAP-20260924-0009 |
CVE-2026-59283 | 2026-08-27 | CRITICAL | 9.1 | Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL NVD ↗ · NTAP-20261002-0017 |
CVE-2026-5946 | 2026-05-20 | HIGH | 7.5 | Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or NVD ↗ · NTAP-20260529-0002 |
CVE-2026-5947 | — | — | — | NVD ↗ · NTAP-20260529-0003 |
CVE-2026-5950 | — | — | — | NVD ↗ · NTAP-20260529-0006 |
CVE-2026-59844 | — | — | — | NVD ↗ · NTAP-20260807-0008 |
CVE-2026-59845 | — | — | — | NVD ↗ · NTAP-20260807-0009 |
CVE-2026-59846 | — | — | — | NVD ↗ · NTAP-20260807-0012 |
CVE-2026-59847 | — | — | — | NVD ↗ · NTAP-20260807-0010 |
CVE-2026-59848 | — | — | — | NVD ↗ · NTAP-20260807-0013 |
CVE-2026-59849 | — | — | — | NVD ↗ · NTAP-20260807-0014 |
CVE-2026-59850 | — | — | — | NVD ↗ · NTAP-20260807-0011 |
CVE-2026-59871 | — | — | — | NVD ↗ · NTAP-20260828-0003 |
CVE-2026-59873 | — | — | — | NVD ↗ · NTAP-20260828-0001 |
CVE-2026-59874 | — | — | — | NVD ↗ · NTAP-20260828-0002 |
CVE-2026-59875 | — | — | — | NVD ↗ · NTAP-20260828-0004 |
CVE-2026-59888 | — | — | — | NVD ↗ · NTAP-20260828-0015 |
CVE-2026-59889 | — | — | — | NVD ↗ · NTAP-20260828-0016 |
CVE-2026-59935 | 2026-07-08 | HIGH | 7.5 | pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not terminated inl NVD ↗ · NTAP-20260917-0001 |
CVE-2026-59936 | 2026-07-08 | HIGH | 7.5 | pypdf is a free and open-source pure-python PDF library. Prior to 6.14.1, an attacker can craft a PDF with a page content stream containing a not terminated inl NVD ↗ · NTAP-20260917-0001 |
CVE-2026-59937 | 2026-07-08 | HIGH | 7.5 | pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with repeated malformed cross-reference streams that cause NVD ↗ · NTAP-20260917-0001 |
CVE-2026-59938 | 2026-07-08 | MEDIUM | 5.3 | pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared image size values that are much too large co NVD ↗ · NTAP-20260917-0001 |
CVE-2026-59995 | 2026-07-08 | MEDIUM | 4.2 | sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server. NVD ↗ · NTAP-20260717-0012 |
CVE-2026-59996 | 2026-07-08 | MEDIUM | 4.2 | scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations. NVD ↗ · NTAP-20260717-0012 |
CVE-2026-59997 | 2026-07-08 | MEDIUM | 4.2 | internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would h NVD ↗ · NTAP-20260717-0012 |
CVE-2026-59998 | 2026-07-08 | MEDIUM | 4.8 | sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory. NVD ↗ · NTAP-20260717-0012 |
CVE-2026-59999 | 2026-07-08 | MEDIUM | 5.9 | In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not. NVD ↗ · NTAP-20260717-0012 |
CVE-2026-60000 | 2026-07-08 | LOW | 3.7 | sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTr NVD ↗ · NTAP-20260717-0012 |
CVE-2026-60001 | 2026-07-08 | MEDIUM | 6.5 | sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay. NVD ↗ · NTAP-20260717-0012 |
CVE-2026-60002 | 2026-07-08 | HIGH | 7.7 | ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.) NVD ↗ · NTAP-20260717-0012 |
CVE-2026-60005 | — | — | — | NVD ↗ · NTAP-20260730-0010 |
CVE-2026-60145 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-60147 | — | — | — | NVD ↗ · NTAP-20260724-0016 |
CVE-2026-60163 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-60164 | — | — | — | NVD ↗ · NTAP-20260724-0020 |
CVE-2026-60166 | — | — | — | NVD ↗ · NTAP-20260724-0020 |
CVE-2026-60174 | — | — | — | NVD ↗ · NTAP-20260731-0019 |
CVE-2026-60177 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-60178 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-60181 | — | — | — | NVD ↗ · NTAP-20260731-0019 |
CVE-2026-60182 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-60183 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-60184 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-60185 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-60186 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-60187 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-60188 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-60189 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-60190 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-60191 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-60194 | — | — | — | NVD ↗ · NTAP-20260731-0019 |
CVE-2026-60195 | — | — | — | NVD ↗ · NTAP-20260731-0019 |
CVE-2026-60311 | — | — | — | NVD ↗ · NTAP-20260731-0020 |
CVE-2026-60315 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-60316 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-60324 | — | — | — | NVD ↗ · NTAP-20260731-0019 |
CVE-2026-60331 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-60332 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-6051 | — | — | — | NVD ↗ · NTAP-20260529-0012 |
CVE-2026-6052 | — | — | — | NVD ↗ · NTAP-20260529-0008 |
CVE-2026-60526 | — | — | — | NVD ↗ · NTAP-20260724-0018 |
CVE-2026-6053 | — | — | — | NVD ↗ · NTAP-20260529-0011 |
CVE-2026-60585 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-60586 | — | — | — | NVD ↗ · NTAP-20260731-0018 |
CVE-2026-60589 | — | — | — | NVD ↗ · NTAP-20260821-0009 |
CVE-2026-60623 | — | — | — | NVD ↗ · NTAP-20260731-0018 |
CVE-2026-60624 | — | — | — | NVD ↗ · NTAP-20260731-0018 |
CVE-2026-60718 | — | — | — | NVD ↗ · NTAP-20260731-0019 |
CVE-2026-60747 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-6100 | — | — | — | NVD ↗ · NTAP-20260717-0015 |
CVE-2026-61081 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-61082 | — | — | — | NVD ↗ · NTAP-20260731-0018 |
CVE-2026-61093 | — | — | — | NVD ↗ · NTAP-20260731-0019 |
CVE-2026-61094 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-61096 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-61108 | — | — | — | NVD ↗ · NTAP-20260731-0019 |
CVE-2026-61109 | — | — | — | NVD ↗ · NTAP-20260731-0017 |
CVE-2026-61128 | — | — | — | NVD ↗ · NTAP-20260731-0019 |
CVE-2026-61144 | — | — | — | NVD ↗ · NTAP-20260731-0019 |
CVE-2026-61308 | — | — | — | NVD ↗ · NTAP-20260821-0009 |
CVE-2026-61466 | — | — | — | NVD ↗ · NTAP-20260911-0003 |
CVE-2026-6238 | — | — | — | NVD ↗ · NTAP-20260612-0002 |
CVE-2026-6253 | — | — | — | NVD ↗ · NTAP-20260515-0006 |
CVE-2026-62574 | 2026-07-21 | HIGH | 7.8 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Install). Supported version NVD ↗ · NTAP-20261002-0018 |
CVE-2026-6276 | — | — | — | NVD ↗ · NTAP-20260515-0009 |
CVE-2026-63072 | — | — | — | NVD ↗ · NTAP-20260903-0001 · NTAP-20260902-0006 |
CVE-2026-63073 | — | — | — | NVD ↗ · NTAP-20260903-0001 · NTAP-20260902-0001 |
CVE-2026-63074 | — | — | — | NVD ↗ · NTAP-20260903-0001 · NTAP-20260902-0009 |
CVE-2026-63075 | — | — | — | NVD ↗ · NTAP-20260903-0001 · NTAP-20260902-0007 |
CVE-2026-63076 | — | — | — | NVD ↗ · NTAP-20260903-0001 · NTAP-20260902-0008 |
CVE-2026-63136 | — | — | — | NVD ↗ · NTAP-20260807-0016 |
CVE-2026-63140 | — | — | — | NVD ↗ · NTAP-20260807-0017 |
CVE-2026-63144 | — | — | — | NVD ↗ · NTAP-20260807-0018 |
Years: 2026 · 2025 · 2024 · 2023 · 2022 · 2021 · 2020 · 2019 · 2018 · 2017 · 2016 · 2015 · 2014 · 2013 · 2012 · 2011 · 2010 · 2009 · 2008 · 2007 · 2006 · 2005 · 2004 · 2003 · 2002 · 1999