Storagegrid
Vendor:
First CVE: Apr 21, 2016 · Active for 10 years
73
Total CVEs
More Total CVEs than 99% of tracked products
6.6
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 33% of tracked products
2.7%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Storagegrid over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 21, 2016
10 years ago
Most Recent CVE
Apr 20, 2026
95 days ago
CVE Severity & Scoring
Storagegrid73 CVEs
15%
33%
40%
12%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (2.7%)
Network71 (97.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low39 (53.4%)
High34 (46.6%)
Unknown0 (0.0%)
User Interaction
None58 (79.5%)
Unknown0 (0.0%)
Required15 (20.5%)
Privileges Required
Low6 (8.2%)
High2 (2.7%)
None65 (89.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (73 CVEs).
73 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-40438CRITICAL A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | Sep 16, 2021 | 9.0 | 97 | YES | YES |
CVE-2016-3427CRITICAL Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and avai | Apr 21, 2016 | 9.8 | 95 | YES | NO |
CVE-2017-15715HIGH In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the f | Mar 26, 2018 | 8.1 | 82 | NO | YES |
CVE-2025-25292CRITICAL ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 a | Mar 12, 2025 | 9.8 | 67 | NO | NO |
CVE-2022-0778HIGH The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsi | Mar 15, 2022 | 7.5 | 65 | NO | NO |
CVE-2018-1303HIGH A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared me | Mar 26, 2018 | 7.5 | 63 | NO | NO |
CVE-2021-34798HIGH Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. | Sep 16, 2021 | 7.5 | 61 | NO | NO |
CVE-2021-36160HIGH A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 ( | Sep 16, 2021 | 7.5 | 59 | NO | NO |
CVE-2021-3449MEDIUM An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms | Mar 25, 2021 | 5.9 | 57 | NO | NO |
CVE-2017-7668HIGH The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input str | Jun 20, 2017 | 7.5 | 56 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (73 CVEs).
CISA KEV
2 CVEs
2.7% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
4.1% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (73 CVEs).
Media Mentions
Signals from CVEs in this product scope (73 CVEs).
Top CNAs Publishing CVEs For Storagegrid
Top CWEs
Versions
No cataloged versions.