Home / Security / CVE index / 2026

2026 NetApp CVEs (page 3)

Showing 300 CVEs with a 2026 identifier — page 3 of 4. Sorted by CVE id.

Always verify. NetApp's advisory is authoritative for affected versions and fixes; NVD carries the CVSS record.
Showing 300 of 300
CVEPublishedSeverityCVSSSummary / Sources
CVE-2026-46242——— NVD ↗ · NTAP-20260710-0020
CVE-2026-46300——— NVD ↗ · NTAP-20260522-0016
CVE-2026-46303——— NVD ↗ · NTAP-20260724-0007
CVE-2026-46304——— NVD ↗ · NTAP-20260724-0008
CVE-2026-46306——— NVD ↗ · NTAP-20260724-0009
CVE-2026-46307——— NVD ↗ · NTAP-20260724-0006
CVE-2026-46331——— NVD ↗ · NTAP-20260703-0002
CVE-2026-46333——— NVD ↗ · NTAP-20260717-0009
CVE-2026-46340——— NVD ↗ · NTAP-20260626-0020
CVE-2026-4652——— NVD ↗ · NTAP-20260417-0004
CVE-2026-46595——— NVD ↗ · NTAP-20260617-0019
CVE-2026-46597——— NVD ↗ · NTAP-20260617-0019
CVE-2026-46598——— NVD ↗ · NTAP-20260617-0019
CVE-2026-46605——— NVD ↗ · NTAP-20260710-0001
CVE-2026-46863——— NVD ↗ · NTAP-20260626-0016
CVE-2026-46917——— NVD ↗ · NTAP-20260724-0019
CVE-2026-46936——— NVD ↗ · NTAP-20260731-0017
CVE-2026-46968——— NVD ↗ · NTAP-20260724-0016
CVE-2026-47008——— NVD ↗ · NTAP-20260731-0019
CVE-2026-47010——— NVD ↗ · NTAP-20260724-0016
CVE-2026-47012——— NVD ↗ · NTAP-20260731-0017
CVE-2026-47013——— NVD ↗ · NTAP-20260724-0020
CVE-2026-47021——— NVD ↗ · NTAP-20260724-0016
CVE-2026-47023——— NVD ↗ · NTAP-20260731-0017
CVE-2026-47027——— NVD ↗ · NTAP-20260724-0016
CVE-2026-47030——— NVD ↗ · NTAP-20260724-0020
CVE-2026-47034——— NVD ↗ · NTAP-20260724-0020
CVE-2026-47035——— NVD ↗ · NTAP-20260724-0020
CVE-2026-47052——— NVD ↗ · NTAP-20260731-0017
CVE-2026-47057——— NVD ↗ · NTAP-20260724-0017
CVE-2026-47058——— NVD ↗ · NTAP-20260724-0017
CVE-2026-47059——— NVD ↗ · NTAP-20260724-0016
CVE-2026-47063——— NVD ↗ · NTAP-20260724-0016
CVE-2026-47064——— NVD ↗ · NTAP-20260731-0017
CVE-2026-472442026-06-12MEDIUM5.3Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, DefaultHttp2Connecti NVD ↗ · NTAP-20260917-0001 · NTAP-20260626-0020
CVE-2026-4747——— NVD ↗ · NTAP-20260410-0014
CVE-2026-4748——— NVD ↗ · NTAP-20260417-0006
CVE-2026-47691——— NVD ↗ · NTAP-20260626-0020
CVE-2026-477702026-06-25MEDIUM5.5jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq's ordinary NVD ↗ · NTAP-20260925-0026
CVE-2026-478842026-08-27CRITICAL9.8Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where NVD ↗ · NTAP-20260924-0001
CVE-2026-478862026-08-27HIGH7.5Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power oper NVD ↗ · NTAP-20260924-0005
CVE-2026-478872026-08-27MEDIUM6.1A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open NVD ↗ · NTAP-20260924-0008
CVE-2026-47888——— NVD ↗ · NTAP-20260917-0020
CVE-2026-478912026-08-27CRITICAL9.8A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7. NVD ↗ · NTAP-20260924-0002
CVE-2026-478922026-08-27CRITICAL9.8A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spr NVD ↗ · NTAP-20260924-0003
CVE-2026-478932026-08-27HIGH7.5A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception r NVD ↗ · NTAP-20260924-0006
CVE-2026-4800——— NVD ↗ · NTAP-20260917-0001 · NTAP-20260717-0010
CVE-2026-48006——— NVD ↗ · NTAP-20260626-0020
CVE-2026-480432026-06-12MEDIUM5.3Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, NVD ↗ · NTAP-20260917-0001 · NTAP-20260626-0020
CVE-2026-48059——— NVD ↗ · NTAP-20260626-0020
CVE-2026-480952026-06-05HIGH8.87-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in t NVD ↗ · NTAP-20260619-0001
CVE-2026-481552026-05-28MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to large memory us NVD ↗ · NTAP-20260917-0001
CVE-2026-481562026-05-28LOW3.3pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. NVD ↗ · NTAP-20260917-0001
CVE-2026-486172026-06-18HIGH8.2A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or b NVD ↗ · NTAP-20260925-0017
CVE-2026-48672026-03-26HIGH7.5Impact: A bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (. NVD ↗ · NTAP-20260917-0001
CVE-2026-487102026-05-26MEDIUM6.5Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `re NVD ↗ · NTAP-20260917-0001 · NTAP-20260605-0011
CVE-2026-487352026-05-28MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can craft a PDF which leads to large memory us NVD ↗ · NTAP-20260917-0001
CVE-2026-48748——— NVD ↗ · NTAP-20260724-0013
CVE-2026-488172026-06-17MEDIUM5.3Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the NVD ↗ · NTAP-20260917-0001
CVE-2026-488182026-06-17HIGH7.5Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.c NVD ↗ · NTAP-20260917-0001
CVE-2026-488642026-05-26HIGH7.8A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insuff NVD ↗ · NTAP-20260925-0022
CVE-2026-48913——— NVD ↗ · NTAP-20260610-0004
CVE-2026-489372026-06-18HIGH7.5A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affects two supported relea NVD ↗ · NTAP-20260925-0018
CVE-2026-49157——— NVD ↗ · NTAP-20260710-0001
CVE-2026-49261——— NVD ↗ · NTAP-20260710-0016
CVE-2026-49270——— NVD ↗ · NTAP-20260710-0001
CVE-2026-49412——— NVD ↗ · NTAP-20260619-0018
CVE-2026-49413——— NVD ↗ · NTAP-20260626-0003
CVE-2026-49414——— NVD ↗ · NTAP-20260619-0017
CVE-2026-49415——— NVD ↗ · NTAP-20260710-0012
CVE-2026-49416——— NVD ↗ · NTAP-20260619-0019
CVE-2026-49417——— NVD ↗ · NTAP-20260626-0002
CVE-2026-49418——— NVD ↗ · NTAP-20260710-0014
CVE-2026-49419——— NVD ↗ · NTAP-20260710-0013
CVE-2026-49420——— NVD ↗ · NTAP-20260710-0011
CVE-2026-49421——— NVD ↗ · NTAP-20260710-0010
CVE-2026-49422——— NVD ↗ · NTAP-20260710-0015
CVE-2026-49423——— NVD ↗ · NTAP-20260710-0007
CVE-2026-49424——— NVD ↗ · NTAP-20260710-0006
CVE-2026-49425——— NVD ↗ · NTAP-20260710-0005
CVE-2026-49426——— NVD ↗ · NTAP-20260710-0008
CVE-2026-49427——— NVD ↗ · NTAP-20260710-0009
CVE-2026-49428——— NVD ↗ · NTAP-20260710-0009
CVE-2026-49429——— NVD ↗ · NTAP-20260828-0005
CVE-2026-49430——— NVD ↗ · NTAP-20260828-0005
CVE-2026-49431——— NVD ↗ · NTAP-20260828-0005
CVE-2026-494602026-06-22LOW3.3pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. NVD ↗ · NTAP-20260917-0001
CVE-2026-494612026-06-22MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to large memory us NVD ↗ · NTAP-20260917-0001
CVE-2026-497592026-06-10HIGH8.2Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP NVD ↗ · NTAP-20260626-0014
CVE-2026-498392026-06-25HIGH7.1jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bo NVD ↗ · NTAP-20260925-0024
CVE-2026-49844——— NVD ↗ · NTAP-20260724-0012
CVE-2026-49851——— NVD ↗ · NTAP-20260917-0001
CVE-2026-49875——— NVD ↗ · NTAP-20260618-0004
CVE-2026-49975——— NVD ↗ · NTAP-20260610-0003
CVE-2026-50009——— NVD ↗ · NTAP-20260724-0013
CVE-2026-500102026-06-12HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFa NVD ↗ · NTAP-20260917-0005 · NTAP-20260626-0020
CVE-2026-50011——— NVD ↗ · NTAP-20260626-0020
CVE-2026-50020——— NVD ↗ · NTAP-20260626-0020
CVE-2026-502192026-06-04MEDIUM4.9libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within h NVD ↗ · NTAP-20260924-0022
CVE-2026-50229——— NVD ↗ · NTAP-20260703-0016
CVE-2026-50560——— NVD ↗ · NTAP-20260626-0020
CVE-2026-50623——— NVD ↗ · NTAP-20260618-0004
CVE-2026-50627——— NVD ↗ · NTAP-20260618-0004
CVE-2026-50628——— NVD ↗ · NTAP-20260618-0004
CVE-2026-50629——— NVD ↗ · NTAP-20260618-0004
CVE-2026-50630——— NVD ↗ · NTAP-20260618-0004
CVE-2026-50631——— NVD ↗ · NTAP-20260618-0004
CVE-2026-50632——— NVD ↗ · NTAP-20260618-0004
CVE-2026-50633——— NVD ↗ · NTAP-20260618-0004
CVE-2026-50634——— NVD ↗ · NTAP-20260618-0004
CVE-2026-50645——— NVD ↗ · NTAP-20260618-0004
CVE-2026-53359——— NVD ↗ · NTAP-20260710-0017
CVE-2026-53362——— NVD ↗ · NTAP-20260903-0010
CVE-2026-53404——— NVD ↗ · NTAP-20260703-0017
CVE-2026-53434——— NVD ↗ · NTAP-20260703-0013
CVE-2026-535372026-06-22LOW3.7Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with em NVD ↗ · NTAP-20260917-0001
CVE-2026-535382026-06-22LOW3.7Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlenco NVD ↗ · NTAP-20260917-0001
CVE-2026-535392026-06-22HIGH7.5Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlencoded bodies, QuerystringParser located t NVD ↗ · NTAP-20260917-0001
CVE-2026-535402026-06-22LOW3.7Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound i NVD ↗ · NTAP-20260917-0001
CVE-2026-53655——— NVD ↗ · NTAP-20260807-0006
CVE-2026-5398——— NVD ↗ · NTAP-20260429-0013
CVE-2026-54225——— NVD ↗ · NTAP-20260911-0008
CVE-2026-542822026-06-22LOW3.7Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because NVD ↗ · NTAP-20260917-0001
CVE-2026-542832026-06-22HIGH7.5Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption whi NVD ↗ · NTAP-20260917-0001
CVE-2026-542932026-06-22HIGH7.5NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Proce NVD ↗ · NTAP-20260917-0001
CVE-2026-5435——— NVD ↗ · NTAP-20260513-0005
CVE-2026-54369——— NVD ↗ · NTAP-20260828-0010
CVE-2026-54370——— NVD ↗ · NTAP-20260828-0011
CVE-2026-54371——— NVD ↗ · NTAP-20260828-0012
CVE-2026-5450——— NVD ↗ · NTAP-20260513-0006
CVE-2026-54512——— NVD ↗ · NTAP-20260828-0013
CVE-2026-54513——— NVD ↗ · NTAP-20260828-0014
CVE-2026-545302026-06-22MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loo NVD ↗ · NTAP-20260917-0001
CVE-2026-545312026-06-22MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loo NVD ↗ · NTAP-20260917-0001
CVE-2026-546512026-06-22MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.13.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loo NVD ↗ · NTAP-20260917-0001
CVE-2026-546792026-06-25MEDIUM5.5jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive NVD ↗ · NTAP-20260925-0025
CVE-2026-54874——— NVD ↗ · NTAP-20260903-0001 · NTAP-20260902-0005
CVE-2026-54876——— NVD ↗ · NTAP-20260814-0019
CVE-2026-552002026-06-17HIGH8.1libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on pac NVD ↗ · NTAP-20260703-0020
CVE-2026-55276——— NVD ↗ · NTAP-20260703-0018
CVE-2026-5545——— NVD ↗ · NTAP-20260515-0005
CVE-2026-558312026-07-21HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder NVD ↗ · NTAP-20260917-0005
CVE-2026-558332026-07-21HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding co NVD ↗ · NTAP-20260917-0005
CVE-2026-5588——— NVD ↗ · NTAP-20260626-0006
CVE-2026-55953——— NVD ↗ · NTAP-20260828-0008
CVE-2026-55955——— NVD ↗ · NTAP-20260703-0015
CVE-2026-55956——— NVD ↗ · NTAP-20260703-0016
CVE-2026-55957——— NVD ↗ · NTAP-20260703-0014
CVE-2026-5598——— NVD ↗ · NTAP-20260626-0006
CVE-2026-561312026-06-19MEDIUM4.9libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-fre NVD ↗ · NTAP-20260924-0023
CVE-2026-56144——— NVD ↗ · NTAP-20260807-0020
CVE-2026-56145——— NVD ↗ · NTAP-20260807-0015
CVE-2026-564032026-06-21MEDIUM6.9libexpat before 2.8.2 has an integer overflow in storeAtts. NVD ↗ · NTAP-20260924-0012
CVE-2026-564042026-06-21MEDIUM6.9libexpat before 2.8.2 has an integer overflow in addBinding. NVD ↗ · NTAP-20260924-0013
CVE-2026-564052026-06-21MEDIUM6.9libexpat before 2.8.2 has an integer overflow in getAttributeId. NVD ↗ · NTAP-20260924-0014
CVE-2026-564062026-06-21MEDIUM6.9libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse. NVD ↗ · NTAP-20260924-0015
CVE-2026-564072026-06-21MEDIUM6.9libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen. NVD ↗ · NTAP-20260924-0016
CVE-2026-564082026-06-21MEDIUM6.9libexpat before 2.8.2 has an integer overflow in copyString. NVD ↗ · NTAP-20260924-0017
CVE-2026-564092026-06-21MEDIUM6.5xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used. NVD ↗ · NTAP-20260924-0020
CVE-2026-564102026-06-21MEDIUM6.9xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId. NVD ↗ · NTAP-20260924-0018
CVE-2026-56411——— NVD ↗ · NTAP-20260924-0019
CVE-2026-564122026-06-21MEDIUM4.9libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers i NVD ↗ · NTAP-20260924-0024
CVE-2026-567452026-07-21HIGH7.5Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4 NVD ↗ · NTAP-20260917-0005
CVE-2026-567462026-07-21MEDIUM6.5Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1. NVD ↗ · NTAP-20260917-0005
CVE-2026-568192026-07-21HIGH7.5Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4 NVD ↗ · NTAP-20260917-0005
CVE-2026-568482026-08-04HIGH7.5A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a NVD ↗ · NTAP-20260925-0019
CVE-2026-5704——— NVD ↗ · NTAP-20260424-0010
CVE-2026-572042026-06-30MEDIUM6.5pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An attacker who uses this vulnerability can c NVD ↗ · NTAP-20260917-0001
CVE-2026-5773——— NVD ↗ · NTAP-20260515-0004
CVE-2026-57817——— NVD ↗ · NTAP-20260911-0006
CVE-2026-57818——— NVD ↗ · NTAP-20260911-0007
CVE-2026-57819——— NVD ↗ · NTAP-20260911-0009
CVE-2026-580112026-06-30MEDIUM6.5A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDate NVD ↗ · NTAP-20260924-0026
CVE-2026-580122026-06-30MEDIUM6.5A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement NVD ↗ · NTAP-20260924-0027
CVE-2026-580132026-06-30MEDIUM6.5A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length NVD ↗ · NTAP-20260924-0028
CVE-2026-580152026-06-30MEDIUM5.9A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parame NVD ↗ · NTAP-20260924-0029
CVE-2026-580412026-08-04MEDIUM5.3A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared stateme NVD ↗ · NTAP-20260925-0021
CVE-2026-58043——— NVD ↗ · NTAP-20260821-0001
CVE-2026-58052——— NVD ↗ · NTAP-20260724-0011
CVE-2026-580552026-06-28MEDIUM5.4nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend NVD ↗ · NTAP-20260925-0027
CVE-2026-58081——— NVD ↗ · NTAP-20260710-0004
CVE-2026-58082——— NVD ↗ · NTAP-20260710-0004
CVE-2026-58083——— NVD ↗ · NTAP-20260814-0013
CVE-2026-58084——— NVD ↗ · NTAP-20260814-0018
CVE-2026-58085——— NVD ↗ · NTAP-20260814-0016
CVE-2026-58086——— NVD ↗ · NTAP-20260814-0017
CVE-2026-58087——— NVD ↗ · NTAP-20260814-0014
CVE-2026-58088——— NVD ↗ · NTAP-20260814-0015
CVE-2026-58089——— NVD ↗ · NTAP-20260903-0003
CVE-2026-58090——— NVD ↗ · NTAP-20260903-0004
CVE-2026-58091——— NVD ↗ · NTAP-20260903-0005
CVE-2026-58092——— NVD ↗ · NTAP-20260903-0008
CVE-2026-58093——— NVD ↗ · NTAP-20260903-0007
CVE-2026-58094——— NVD ↗ · NTAP-20260903-0006
CVE-2026-58095——— NVD ↗ · NTAP-20260903-0002
CVE-2026-58096——— NVD ↗ · NTAP-20260903-0002
CVE-2026-58097——— NVD ↗ · NTAP-20260903-0002
CVE-2026-58216——— NVD ↗ · NTAP-20260821-0015
CVE-2026-58218——— NVD ↗ · NTAP-20260821-0016
CVE-2026-58221——— NVD ↗ · NTAP-20260821-0017
CVE-2026-58222——— NVD ↗ · NTAP-20260821-0018
CVE-2026-58224——— NVD ↗ · NTAP-20260821-0019
CVE-2026-59083——— NVD ↗ · NTAP-20260717-0018
CVE-2026-59084——— NVD ↗ · NTAP-20260717-0019
CVE-2026-59250——— NVD ↗ · NTAP-20260828-0009
CVE-2026-5928——— NVD ↗ · NTAP-20260513-0004
CVE-2026-592802026-08-27MEDIUM4.3Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from unt NVD ↗ · NTAP-20260924-0011
CVE-2026-592812026-08-27MEDIUM6.1Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and then render field errors using the no-argument Err NVD ↗ · NTAP-20260924-0009
CVE-2026-592832026-08-27CRITICAL9.1Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL NVD ↗ · NTAP-20261002-0017
CVE-2026-59462026-05-20HIGH7.5Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or NVD ↗ · NTAP-20260529-0002
CVE-2026-5947——— NVD ↗ · NTAP-20260529-0003
CVE-2026-5950——— NVD ↗ · NTAP-20260529-0006
CVE-2026-59844——— NVD ↗ · NTAP-20260807-0008
CVE-2026-59845——— NVD ↗ · NTAP-20260807-0009
CVE-2026-59846——— NVD ↗ · NTAP-20260807-0012
CVE-2026-59847——— NVD ↗ · NTAP-20260807-0010
CVE-2026-59848——— NVD ↗ · NTAP-20260807-0013
CVE-2026-59849——— NVD ↗ · NTAP-20260807-0014
CVE-2026-59850——— NVD ↗ · NTAP-20260807-0011
CVE-2026-59871——— NVD ↗ · NTAP-20260828-0003
CVE-2026-59873——— NVD ↗ · NTAP-20260828-0001
CVE-2026-59874——— NVD ↗ · NTAP-20260828-0002
CVE-2026-59875——— NVD ↗ · NTAP-20260828-0004
CVE-2026-59888——— NVD ↗ · NTAP-20260828-0015
CVE-2026-59889——— NVD ↗ · NTAP-20260828-0016
CVE-2026-599352026-07-08HIGH7.5pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not terminated inl NVD ↗ · NTAP-20260917-0001
CVE-2026-599362026-07-08HIGH7.5pypdf is a free and open-source pure-python PDF library. Prior to 6.14.1, an attacker can craft a PDF with a page content stream containing a not terminated inl NVD ↗ · NTAP-20260917-0001
CVE-2026-599372026-07-08HIGH7.5pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with repeated malformed cross-reference streams that cause NVD ↗ · NTAP-20260917-0001
CVE-2026-599382026-07-08MEDIUM5.3pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared image size values that are much too large co NVD ↗ · NTAP-20260917-0001
CVE-2026-599952026-07-08MEDIUM4.2sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server. NVD ↗ · NTAP-20260717-0012
CVE-2026-599962026-07-08MEDIUM4.2scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations. NVD ↗ · NTAP-20260717-0012
CVE-2026-599972026-07-08MEDIUM4.2internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would h NVD ↗ · NTAP-20260717-0012
CVE-2026-599982026-07-08MEDIUM4.8sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory. NVD ↗ · NTAP-20260717-0012
CVE-2026-599992026-07-08MEDIUM5.9In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not. NVD ↗ · NTAP-20260717-0012
CVE-2026-600002026-07-08LOW3.7sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTr NVD ↗ · NTAP-20260717-0012
CVE-2026-600012026-07-08MEDIUM6.5sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay. NVD ↗ · NTAP-20260717-0012
CVE-2026-600022026-07-08HIGH7.7ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.) NVD ↗ · NTAP-20260717-0012
CVE-2026-60005——— NVD ↗ · NTAP-20260730-0010
CVE-2026-60145——— NVD ↗ · NTAP-20260731-0017
CVE-2026-60147——— NVD ↗ · NTAP-20260724-0016
CVE-2026-60163——— NVD ↗ · NTAP-20260731-0017
CVE-2026-60164——— NVD ↗ · NTAP-20260724-0020
CVE-2026-60166——— NVD ↗ · NTAP-20260724-0020
CVE-2026-60174——— NVD ↗ · NTAP-20260731-0019
CVE-2026-60177——— NVD ↗ · NTAP-20260731-0017
CVE-2026-60178——— NVD ↗ · NTAP-20260731-0017
CVE-2026-60181——— NVD ↗ · NTAP-20260731-0019
CVE-2026-60182——— NVD ↗ · NTAP-20260731-0017
CVE-2026-60183——— NVD ↗ · NTAP-20260731-0017
CVE-2026-60184——— NVD ↗ · NTAP-20260731-0017
CVE-2026-60185——— NVD ↗ · NTAP-20260731-0017
CVE-2026-60186——— NVD ↗ · NTAP-20260731-0017
CVE-2026-60187——— NVD ↗ · NTAP-20260731-0017
CVE-2026-60188——— NVD ↗ · NTAP-20260731-0017
CVE-2026-60189——— NVD ↗ · NTAP-20260731-0017
CVE-2026-60190——— NVD ↗ · NTAP-20260731-0017
CVE-2026-60191——— NVD ↗ · NTAP-20260731-0017
CVE-2026-60194——— NVD ↗ · NTAP-20260731-0019
CVE-2026-60195——— NVD ↗ · NTAP-20260731-0019
CVE-2026-60311——— NVD ↗ · NTAP-20260731-0020
CVE-2026-60315——— NVD ↗ · NTAP-20260731-0017
CVE-2026-60316——— NVD ↗ · NTAP-20260731-0017
CVE-2026-60324——— NVD ↗ · NTAP-20260731-0019
CVE-2026-60331——— NVD ↗ · NTAP-20260731-0017
CVE-2026-60332——— NVD ↗ · NTAP-20260731-0017
CVE-2026-6051——— NVD ↗ · NTAP-20260529-0012
CVE-2026-6052——— NVD ↗ · NTAP-20260529-0008
CVE-2026-60526——— NVD ↗ · NTAP-20260724-0018
CVE-2026-6053——— NVD ↗ · NTAP-20260529-0011
CVE-2026-60585——— NVD ↗ · NTAP-20260731-0017
CVE-2026-60586——— NVD ↗ · NTAP-20260731-0018
CVE-2026-60589——— NVD ↗ · NTAP-20260821-0009
CVE-2026-60623——— NVD ↗ · NTAP-20260731-0018
CVE-2026-60624——— NVD ↗ · NTAP-20260731-0018
CVE-2026-60718——— NVD ↗ · NTAP-20260731-0019
CVE-2026-60747——— NVD ↗ · NTAP-20260731-0017
CVE-2026-6100——— NVD ↗ · NTAP-20260717-0015
CVE-2026-61081——— NVD ↗ · NTAP-20260731-0017
CVE-2026-61082——— NVD ↗ · NTAP-20260731-0018
CVE-2026-61093——— NVD ↗ · NTAP-20260731-0019
CVE-2026-61094——— NVD ↗ · NTAP-20260731-0017
CVE-2026-61096——— NVD ↗ · NTAP-20260731-0017
CVE-2026-61108——— NVD ↗ · NTAP-20260731-0019
CVE-2026-61109——— NVD ↗ · NTAP-20260731-0017
CVE-2026-61128——— NVD ↗ · NTAP-20260731-0019
CVE-2026-61144——— NVD ↗ · NTAP-20260731-0019
CVE-2026-61308——— NVD ↗ · NTAP-20260821-0009
CVE-2026-61466——— NVD ↗ · NTAP-20260911-0003
CVE-2026-6238——— NVD ↗ · NTAP-20260612-0002
CVE-2026-6253——— NVD ↗ · NTAP-20260515-0006
CVE-2026-625742026-07-21HIGH7.8Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Install). Supported version NVD ↗ · NTAP-20261002-0018
CVE-2026-6276——— NVD ↗ · NTAP-20260515-0009
CVE-2026-63072——— NVD ↗ · NTAP-20260903-0001 · NTAP-20260902-0006
CVE-2026-63073——— NVD ↗ · NTAP-20260903-0001 · NTAP-20260902-0001
CVE-2026-63074——— NVD ↗ · NTAP-20260903-0001 · NTAP-20260902-0009
CVE-2026-63075——— NVD ↗ · NTAP-20260903-0001 · NTAP-20260902-0007
CVE-2026-63076——— NVD ↗ · NTAP-20260903-0001 · NTAP-20260902-0008
CVE-2026-63136——— NVD ↗ · NTAP-20260807-0016
CVE-2026-63140——— NVD ↗ · NTAP-20260807-0017
CVE-2026-63144——— NVD ↗ · NTAP-20260807-0018

Years: 2026 · 2025 · 2024 · 2023 · 2022 · 2021 · 2020 · 2019 · 2018 · 2017 · 2016 · 2015 · 2014 · 2013 · 2012 · 2011 · 2010 · 2009 · 2008 · 2007 · 2006 · 2005 · 2004 · 2003 · 2002 · 1999

← CVE index · Security hub