Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2024-41435
YugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the "insert into" parameter.
Yugabytedb
No fix yet
MEDIUM 6.1
CVE-2023-6002
YugabyteDB is vulnerable to cross site scripting (XSS) via log injection. Writing invalidated user input to log files can allow an unprivileged attac…
Yugabytedb
2.14.14.0 / 2.16.8.0+
HIGH 7.5
CVE-2023-6001
Prometheus metrics are available without
authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment.
Yugabytedb
2.18.4.0+
HIGH 7.5
CVE-2023-4640
The controller responsible for setting the logging level does not include any authorization
checks to ensure the user is authenticated. This can be s…
Yugabytedb
after 2.17.3.0
CRITICAL 9.8
CVE-2023-0745
The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary
files through the backup upload endpoint by using path trav…
Yugabytedb Managed
after 2.13
CRITICAL 9.8
CVE-2023-0575
External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Win…
Yugabytedb
2.2.0.0+
CRITICAL 9.8
CVE-2023-0574
Server-Side Request Forgery (SSRF), Improperly Controlled Modification of Dynamically-Determined Object Attributes, Improper Restriction of Excessive…
Yugabytedb Managed
after 2.13
CRITICAL 9.8
CVE-2022-37397
An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or una…
Yugabytedb
Mitigation only