CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

netapp

active_iq_performance_analytics_services

15 known vulnerabilities · sorted by CVSS score

CVE-2019-7612
CRITICAL9.8

A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL could be inadvertently logged as part of the error message.

elastic / logstash+2
Network
Published Mar 25, 2019
CVE-2018-17182
HIGH7.8

An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An attacker can trigger a use-after-free (and possibly gain privileges) via certain thread creation, map, unmap, invalidation, and dereference operations.

linux / linux_kernel+12
Local
Published Sep 19, 2018
CVE-2019-7221
HIGH7.8

The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free.

linux / linux_kernel+18
Local
Published Mar 21, 2019
CVE-2018-19039
MEDIUM6.5

Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.

grafana / grafana+7
Network
Published Dec 13, 2018
CVE-2018-12099
MEDIUM6.1

Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.

grafana / grafana+2
Network
Published Jun 11, 2018
CVE-2019-15902
MEDIUM5.6

A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg()" commit reintroduced the Spectre vulnerability that it aimed to eliminate. This occurred because the backport process depends on cherry picking specific commits, and because two (correctly ordered) code lines were swapped.

linux / linux_kernel+12
Local
Published Sep 4, 2019
CVE-2019-5489
MEDIUM5.5

The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page cache access patterns of other processes on the same system, potentially allowing sniffing of secret information. (Fixing this affects the output of the fincore program.) Limited remote exploitation may be possible, as demonstrated by latency differences in accessing public files from an Apache HTTP Server.

linux / linux_kernel+2
Local
Published Jan 7, 2019
CVE-2019-7222
MEDIUM5.5

The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.

linux / linux_kernel+34
Local
Published Mar 21, 2019
CVE-2019-6454
MEDIUM5.5

An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the stack pointer to jump over the stack guard pages into an unmapped memory region and trigger a denial of service (systemd PID1 crash and kernel panic).

redhat / enterprise_linux_workstation+54
Local
Published Mar 21, 2019
CVE-2018-16597
MEDIUM5.5

An issue was discovered in the Linux kernel before 4.8. Incorrect access checking in overlayfs mounts could be used by local attackers to modify or truncate files in the underlying filesystem.

linux / linux_kernel+3
Local
Published Sep 21, 2018
CVE-2018-16888
MEDIUM4.7

It was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When a service is run from an unprivileged user (e.g. User field set in the service file), a local attacker who is able to write to the PIDFile of the mentioned service may use this flaw to trick systemd into killing other services and/or privileged processes. Versions before v237 are vulnerable.

systemd_project / systemd+6
Local
Published Jan 14, 2019
CVE-2019-15098
MEDIUM4.6

drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through 5.2.9 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.

linux / linux_kernel+11
Physical
Published Aug 16, 2019
CVE-2018-19985
MEDIUM4.6

The function hso_get_config_data in drivers/net/usb/hso.c in the Linux kernel through 4.19.8 reads if_num from the USB device (as a u8) and uses it to index a small array, resulting in an object out-of-bounds (OOB) read that potentially allows arbitrary read in the kernel address space.

linux / linux_kernel+3
Physical
Published Mar 21, 2019
CVE-2018-16866
LOW3.3

An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable.

systemd_project / systemd+26
Local
Published Jan 11, 2019
CVE-2018-20855
LOW3.3

An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace.

linux / linux_kernel+6
Local
Published Jul 26, 2019