Storagegrid

Vendor:

First CVE: Apr 21, 2016 · Active for 10 years

73
Total CVEs
More Total CVEs than 99% of tracked products
6.6
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 33% of tracked products
2.7%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Storagegrid over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 21, 2016
10 years ago
Most Recent CVE
Apr 20, 2026
95 days ago

CVE Severity & Scoring

Storagegrid73 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local2 (2.7%)
Network71 (97.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low39 (53.4%)
High34 (46.6%)
Unknown0 (0.0%)
User Interaction
None58 (79.5%)
Unknown0 (0.0%)
Required15 (20.5%)
Privileges Required
Low6 (8.2%)
High2 (2.7%)
None65 (89.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (73 CVEs).

73 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Sep 16, 20219.097YESYES
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and avai
Apr 21, 20169.895YESNO
In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the f
Mar 26, 20188.182NOYES
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 a
Mar 12, 20259.867NONO
The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsi
Mar 15, 20227.565NONO
A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared me
Mar 26, 20187.563NONO
Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.
Sep 16, 20217.561NONO
A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (
Sep 16, 20217.559NONO
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms
Mar 25, 20215.957NONO
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input str
Jun 20, 20177.556NONO

Exploit Exposure

Signals from CVEs in this product scope (73 CVEs).

CISA KEV
2 CVEs
2.7% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
4.1% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (73 CVEs).

Media Mentions

Signals from CVEs in this product scope (73 CVEs).

Top CNAs Publishing CVEs For Storagegrid

Top CWEs

Versions

No cataloged versions.