Vulnerability index

Browse CVEs

43 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-25243 Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values… Redis 8.6.3+ Fix from $1,9502026-05-05 HIGH 8.1 CVE-2026-23631 Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-repl… Redis 8.6.3+ Fix from $1,9502026-05-05 HIGH 8.8 CVE-2026-23479 Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `pro… Redis 8.6.3+ Fix from $1,9502026-05-05 HIGH 8.8 CVE-2025-62507EPSS 7% Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKDEL command with multiple ID's… Redis 8.2.3+ Fix from $1,9502025-11-04 CRITICAL 9.9 CVE-2025-49844EPSS 87% Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lu… Redis 6.2.20 / 7.2.11+ Fix from $2,3002025-10-03 HIGH 7.3 CVE-2025-46818 Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lu… Redis 6.2.20 / 7.2.11+ Fix from $1,9502025-10-03 HIGH 7.1 CVE-2025-46819 Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted LU… Redis 6.2.20 / 7.2.11+ Fix from $1,9502025-10-03 HIGH 8.8 CVE-2025-46817 Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lu… Redis 6.2.20 / 7.2.11+ Fix from $1,9502025-10-03 HIGH 7.5 CVE-2025-48367 Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to cl… Redis 6.2.19 / 7.2.10+ Fix from $1,9502025-07-07 HIGH 7.8 CVE-2025-32023 Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use… Redis 6.2.19 / 7.2.10+ Fix from $1,9502025-07-07 CRITICAL 9.8 CVE-2025-27151 Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exi… Redis 7.2.9 / 7.4.4+ Fix from $2,3002025-05-29 HIGH 7.5 CVE-2025-21605 Redis is an open source, in-memory database that persists on disk. In versions starting at 2.6 and prior to 7.4.3, An unauthenticated client can caus… Redis 6.2.18 / 7.2.8+ Fix from $1,9502025-04-23 CRITICAL 9.8 CVE-2024-46981EPSS 8% Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to manipulate the gar… Redis 6.2.17 / 7.2.7+ Fix from $2,3002025-01-06 HIGH 8.8 CVE-2024-31449 Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack bu… Redis 6.2.16 / 7.2.6+ Fix from $1,9502024-10-07 MEDIUM 6.5 CVE-2024-31228 Redis is an open source, in-memory database that persists on disk. Authenticated users can trigger a denial-of-service by using specially crafted, lo… Redis 6.2.16 / 7.2.6+ Fix from $1,6002024-10-07 CRITICAL 9.8 CVE-2023-31654 Redis raft master-1b8bd86 to master-7b46079 was discovered to contain an ODR violation via the component hiredisAllocFns at /opt/fs/redisraft/deps/hi… Redisraft No fix yet Fix from $2,3002024-01-23 HIGH 8.1 CVE-2023-41056 Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that … Redis 7.0.15 / 7.2.4+ Fix from $1,9502024-01-10 MEDIUM 5.9 CVE-2021-31294 Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET … Redis 6.2.0+ Fix from $1,6002023-07-15 HIGH 8.8 CVE-2022-24834EPSS 41% Redis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson libr… Redis 6.0.20 / 6.2.13+ Fix from $1,9502023-07-13 HIGH 8.8 CVE-2023-36824EPSS 77% Redis is an in-memory database that persists on disk. In Redit 7.0 prior to 7.0.12, extracting key names from a command and a list of arguments may, … Redis 7.0.12+ Fix from $1,9502023-07-11 HIGH 7.5 CVE-2023-31655 redis v7.0.10 was discovered to contain a segmentation violation. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecif… Redis Patch available Fix from $1,9502023-05-18 MEDIUM 6.5 CVE-2023-28856 Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` command to create an invalid hash f… Redis 6.0.19 / 6.2.12+ Fix from $1,6002023-04-18 MEDIUM 6.5 CVE-2023-28859 redis-py before 4.4.4 and 4.5.x before 4.5.4 leaves a connection open after canceling an async Redis command at an inopportune time, and can send res… Redis Py 4.4.4 / 4.5.4+ Fix from $1,6002023-03-26 MEDIUM 5.5 CVE-2023-28425EPSS 55% Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticated users can use the MSETNX c… Redis 7.0.10+ Fix from $1,6002023-03-20 MEDIUM 6.5 CVE-2023-25155 Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SRANDMEMBER`, `ZRANDMEMBER`, and `HRANDFIELD` co… Redis 6.0.18 / 6.2.11+ Fix from $1,6002023-03-02 MEDIUM 5.5 CVE-2022-36021EPSS 60% Redis is an in-memory database that persists on disk. Authenticated users can use string matching commands (like `SCAN` or `KEYS`) with a specially c… Redis 6.0.18 / 6.2.11+ Fix from $1,6002023-03-01 MEDIUM 5.5 CVE-2023-22458EPSS 72% Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted ar… Redis 6.2.9 / 7.0.8+ Fix from $1,6002023-01-20 MEDIUM 5.5 CVE-2022-35977EPSS 13% Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SETRANGE` and `SORT(_RO)` commands can trigger a… Redis 6.0.17 / 6.2.9+ Fix from $1,6002023-01-20 CRITICAL 9.8 CVE-2022-3734 A vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unknown code in the library C:/Pro… Redis Mitigation only Fix from $2,3002022-10-28 CRITICAL 9.8 CVE-2022-35951 Redis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Integer Overflow. Executing an `X… Redis 7.0.5+ Fix from $2,3002022-09-23