Ontap Tools
29 CVEs tracked. 2 of them are in CISA KEV.
This hub aggregates every CVE we track for Ontap Tools, a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.
Ontap Tools CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 2 |
| 2024-11 | 2 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 1 |
| 2025-03 | 0 |
| 2025-04 | 1 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 29 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical3
- High17
- Medium8
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Ontap Tools.
- CVE-2025-27820Apache HttpComponents: PSL (Public Suffix List) validation bypass7.5
- CVE-2025-0167netrc and default credential leak3.4
- CVE-2024-52533gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.9.8
- CVE-2024-38286Apache Tomcat: Denial of Service8.6
- CVE-2024-49761REXML ReDoS vulnerability7.5
- CVE-2024-47554Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader4.3
- CVE-2024-7254Stack overflow in Protocol Buffers Java Lite7.5
- CVE-2024-8096OCSP stapling bypass with GnuTLS6.5
- CVE-2024-6119Possible denial of service in X.509 name checks7.5
- CVE-2024-39689Certifi removes GLOBALTRUST root certificate7.5
- CVE-2024-39884Apache HTTP Server: source code disclosure with handlers configured via AddType6.2
- CVE-2024-34750Apache Tomcat: HTTP/2 excess header handling DoS7.5
- CVE-2024-6387Openssh: regresshion - race condition in ssh allows rce/dos8.1
- CVE-2024-34397An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a s...5.2
- CVE-2024-24795Apache HTTP Server: HTTP Response Splitting in multiple modules6.3
Product grouping is registry-driven, with AI assist and human review. How it works