Snapcenter

Vendor:

First CVE: Apr 30, 2007 · Active for 19 years

575
Total CVEs
More Total CVEs than 100% of tracked products
52.3
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.5%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Snapcenter over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 30, 2007
19 years ago
Most Recent CVE
Apr 15, 2025
465 days ago

CVE Severity & Scoring

Snapcenter575 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local26 (4.5%)
Network530 (92.2%)
Unknown1 (0.2%)
Physical0 (0.0%)
Adjacent Network18 (3.1%)
Attack Complexity
Low471 (81.9%)
High103 (17.9%)
Unknown1 (0.2%)
User Interaction
None531 (92.3%)
Unknown1 (0.2%)
Required43 (7.5%)
Privileges Required
Low117 (20.3%)
High367 (63.8%)
None90 (15.7%)
Unknown1 (0.2%)

Top CVEs

Signals from CVEs in this product scope (575 CVEs).

575 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai
Dec 10, 202110.099YESYES
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention
Aug 22, 20188.199YESYES
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation
Oct 4, 20178.199YESYES
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, r
Oct 17, 20189.190NOYES
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources withi
Apr 1, 20215.386NOYES
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payloa
Apr 17, 20179.886NOYES
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append
Apr 29, 20206.183NOYES
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first tim
Aug 24, 20219.879NONO
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source ob
Apr 20, 20196.178NOYES
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (R
Jan 17, 20207.573NONO

Exploit Exposure

Signals from CVEs in this product scope (575 CVEs).

CISA KEV
3 CVEs
0.5% of CVEs· 96th percentile
Metasploit
5 CVEs
0.9% of CVEs· 96th percentile
Nuclei
5 CVEs
0.9% of CVEs· 96th percentile
ExploitDB
7 CVEs
1.2% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (575 CVEs).

Media Mentions

Signals from CVEs in this product scope (575 CVEs).

Top CNAs Publishing CVEs For Snapcenter

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.119.90.7%00
6.0.119.90.7%00
5.016.50.2%00
4.819.81.0%00
4.719.81.0%00