Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Neo4j HIGH 7.5
CVE-2026-14587

Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. When an unauthenticated cli…

Fix: 5.26.29 / 2026.07+
Fix from $1,950 2026-08-05
Neo4j CRITICAL 9.8
CVE-2026-1524

An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following c…

Fix: 5.26.22 / 2026.02+
Fix from $2,300 2026-03-11
Neo4j MEDIUM 6.5
CVE-2026-1471

Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticated users inheriting the conte…

Fix: 5.26.22 / 2026.01.4+
Fix from $1,600 2026-03-11
Neo4j HIGH 7.2
CVE-2026-1497

Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following …

Fix: 5.26.22 / 2026.02+
Fix from $1,950 2026-03-11
Neo4j MEDIUM 5.4
CVE-2026-1337

Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user open…

Fix: 2026.01+
Fix from $1,600 2026-02-06
Neo4j MEDIUM 6.5
CVE-2024-34517

The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.

Fix: 5.19.0+
Fix from $1,600 2024-05-07
Awesome Procedures On Cyper HIGH 8.1
CVE-2023-23926

APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j. An XML External Entity (XXE) vulnerability found in the apoc.import.graphml proce…

Fix: 5.5.0+
Fix from $1,950 2023-02-16
Awesome Procedures On Cyper MEDIUM 6.5
CVE-2022-23532

APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j that provides hundreds of procedures and functions. A path traversal vulnerability…

Fix: 4.3.0.12 / 4.4.0.12+
Fix from $1,600 2023-01-14
Awesome Procedures On Cypher HIGH 7.5
CVE-2022-37423

Neo4j APOC (Awesome Procedures on Cypher) before 4.3.0.7 and 4.x before 4.4.0.8 allows Directory Traversal to sibling directories via apoc.log.stream.

Fix: 4.3.0.7 / 4.4.0.8+
Fix from $1,950 2022-08-12
Awesome Procedures CRITICAL 9.1
CVE-2021-42767

A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local files, and sometimes cr…

Fix: 3.5.0.17 / 4.2.10+
Fix from $2,300 2022-03-01
Neo4j CRITICAL 9.8
CVE-2021-34371EPSS 13%

Neo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that arbitrarily deserializes Java objects, e.g., through setSessionVaria…

Fix: after 3.4.18
Fix from $2,300 2021-08-05
Graph Databse HIGH 8.8
CVE-2021-34802

A failure in resetting the security context in some transaction actions in Neo4j Graph Database 4.2 and 4.3 could allow authenticated users to execut…

Mitigation only
Fix from $1,950 2021-07-30
Awesome Procedures On Cyper CRITICAL 10.0
CVE-2018-1000820

neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML External Entity (XXE) vulnerability in XML Parser that can result in…

Patch available
Fix from $2,300 2018-12-20
Neo4j CRITICAL 9.8
CVE-2018-18389

Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and Sys…

Fix: 3.4.9+
Fix from $2,300 2018-10-16
Neo4j MEDIUM 6.8
CVE-2013-7259

Multiple cross-site request forgery (CSRF) vulnerabilities in Neo4J 1.9.2 allow remote attackers to hijack the authentication of administrators for r…

Mitigation only
Fix from $1,600 2014-04-29