Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2026-14587
Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. When an unauthenticated cli…
Neo4j
5.26.29 / 2026.07+
CRITICAL 9.8
CVE-2026-1524
An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following c…
Neo4j
5.26.22 / 2026.02+
MEDIUM 6.5
CVE-2026-1471
Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticated users inheriting the conte…
Neo4j
5.26.22 / 2026.01.4+
HIGH 7.2
CVE-2026-1497
Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following …
Neo4j
5.26.22 / 2026.02+
MEDIUM 5.4
CVE-2026-1337
Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user open…
Neo4j
2026.01+
MEDIUM 6.5
CVE-2024-34517
The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.
Neo4j
5.19.0+
HIGH 8.1
CVE-2023-23926
APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j. An XML External Entity (XXE) vulnerability found in the apoc.import.graphml proce…
Awesome Procedures On Cyper
5.5.0+
MEDIUM 6.5
CVE-2022-23532
APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j that provides hundreds of procedures and functions. A path traversal vulnerability…
Awesome Procedures On Cyper
4.3.0.12 / 4.4.0.12+
HIGH 7.5
CVE-2022-37423
Neo4j APOC (Awesome Procedures on Cypher) before 4.3.0.7 and 4.x before 4.4.0.8 allows Directory Traversal to sibling directories via apoc.log.stream.
Awesome Procedures On Cypher
4.3.0.7 / 4.4.0.8+
CRITICAL 9.1
CVE-2021-42767
A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local files, and sometimes cr…
Awesome Procedures
3.5.0.17 / 4.2.10+
CRITICAL 9.8
CVE-2021-34371EPSS 13%
Neo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that arbitrarily deserializes Java objects, e.g., through setSessionVaria…
Neo4j
after 3.4.18
HIGH 8.8
CVE-2021-34802
A failure in resetting the security context in some transaction actions in Neo4j Graph Database 4.2 and 4.3 could allow authenticated users to execut…
Graph Databse
Mitigation only
CRITICAL 10.0
CVE-2018-1000820
neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML External Entity (XXE) vulnerability in XML Parser that can result in…
Awesome Procedures On Cyper
Patch available
CRITICAL 9.8
CVE-2018-18389
Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and Sys…
Neo4j
3.4.9+
MEDIUM 6.8
CVE-2013-7259
Multiple cross-site request forgery (CSRF) vulnerabilities in Neo4J 1.9.2 allow remote attackers to hijack the authentication of administrators for r…
Neo4j
Mitigation only