Vulnerability index

Browse CVEs

43 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Redis HIGH 8.8
CVE-2026-25243

Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values…

Fix: 8.6.3+
Fix from $1,950 2026-05-05
Redis HIGH 8.1
CVE-2026-23631

Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-repl…

Fix: 8.6.3+
Fix from $1,950 2026-05-05
Redis HIGH 8.8
CVE-2026-23479

Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `pro…

Fix: 8.6.3+
Fix from $1,950 2026-05-05
Redis HIGH 8.8
CVE-2025-62507EPSS 7%

Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKDEL command with multiple ID's…

Fix: 8.2.3+
Fix from $1,950 2025-11-04
Redis CRITICAL 9.9
CVE-2025-49844EPSS 87%

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lu…

Fix: 6.2.20 / 7.2.11+
Fix from $2,300 2025-10-03
Redis HIGH 7.3
CVE-2025-46818

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lu…

Fix: 6.2.20 / 7.2.11+
Fix from $1,950 2025-10-03
Redis HIGH 7.1
CVE-2025-46819

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted LU…

Fix: 6.2.20 / 7.2.11+
Fix from $1,950 2025-10-03
Redis HIGH 8.8
CVE-2025-46817

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lu…

Fix: 6.2.20 / 7.2.11+
Fix from $1,950 2025-10-03
Redis HIGH 7.5
CVE-2025-48367

Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to cl…

Fix: 6.2.19 / 7.2.10+
Fix from $1,950 2025-07-07
Redis HIGH 7.8
CVE-2025-32023

Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use…

Fix: 6.2.19 / 7.2.10+
Fix from $1,950 2025-07-07
Redis CRITICAL 9.8
CVE-2025-27151

Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exi…

Fix: 7.2.9 / 7.4.4+
Fix from $2,300 2025-05-29
Redis HIGH 7.5
CVE-2025-21605

Redis is an open source, in-memory database that persists on disk. In versions starting at 2.6 and prior to 7.4.3, An unauthenticated client can caus…

Fix: 6.2.18 / 7.2.8+
Fix from $1,950 2025-04-23
Redis CRITICAL 9.8
CVE-2024-46981EPSS 8%

Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to manipulate the gar…

Fix: 6.2.17 / 7.2.7+
Fix from $2,300 2025-01-06
Redis HIGH 8.8
CVE-2024-31449

Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack bu…

Fix: 6.2.16 / 7.2.6+
Fix from $1,950 2024-10-07
Redis MEDIUM 6.5
CVE-2024-31228

Redis is an open source, in-memory database that persists on disk. Authenticated users can trigger a denial-of-service by using specially crafted, lo…

Fix: 6.2.16 / 7.2.6+
Fix from $1,600 2024-10-07
Redisraft CRITICAL 9.8
CVE-2023-31654

Redis raft master-1b8bd86 to master-7b46079 was discovered to contain an ODR violation via the component hiredisAllocFns at /opt/fs/redisraft/deps/hi…

No fix yet
Fix from $2,300 2024-01-23
Redis HIGH 8.1
CVE-2023-41056

Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that …

Fix: 7.0.15 / 7.2.4+
Fix from $1,950 2024-01-10
Redis MEDIUM 5.9
CVE-2021-31294

Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET …

Fix: 6.2.0+
Fix from $1,600 2023-07-15
Redis HIGH 8.8
CVE-2022-24834EPSS 41%

Redis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson libr…

Fix: 6.0.20 / 6.2.13+
Fix from $1,950 2023-07-13
Redis HIGH 8.8
CVE-2023-36824EPSS 77%

Redis is an in-memory database that persists on disk. In Redit 7.0 prior to 7.0.12, extracting key names from a command and a list of arguments may, …

Fix: 7.0.12+
Fix from $1,950 2023-07-11
Redis HIGH 7.5
CVE-2023-31655

redis v7.0.10 was discovered to contain a segmentation violation. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecif…

Patch available
Fix from $1,950 2023-05-18
Redis MEDIUM 6.5
CVE-2023-28856

Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` command to create an invalid hash f…

Fix: 6.0.19 / 6.2.12+
Fix from $1,600 2023-04-18
Redis Py MEDIUM 6.5
CVE-2023-28859

redis-py before 4.4.4 and 4.5.x before 4.5.4 leaves a connection open after canceling an async Redis command at an inopportune time, and can send res…

Fix: 4.4.4 / 4.5.4+
Fix from $1,600 2023-03-26
Redis MEDIUM 5.5
CVE-2023-28425EPSS 55%

Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticated users can use the MSETNX c…

Fix: 7.0.10+
Fix from $1,600 2023-03-20
Redis MEDIUM 6.5
CVE-2023-25155

Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SRANDMEMBER`, `ZRANDMEMBER`, and `HRANDFIELD` co…

Fix: 6.0.18 / 6.2.11+
Fix from $1,600 2023-03-02
Redis MEDIUM 5.5
CVE-2022-36021EPSS 60%

Redis is an in-memory database that persists on disk. Authenticated users can use string matching commands (like `SCAN` or `KEYS`) with a specially c…

Fix: 6.0.18 / 6.2.11+
Fix from $1,600 2023-03-01
Redis MEDIUM 5.5
CVE-2023-22458EPSS 72%

Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted ar…

Fix: 6.2.9 / 7.0.8+
Fix from $1,600 2023-01-20
Redis MEDIUM 5.5
CVE-2022-35977EPSS 13%

Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SETRANGE` and `SORT(_RO)` commands can trigger a…

Fix: 6.0.17 / 6.2.9+
Fix from $1,600 2023-01-20
Redis CRITICAL 9.8
CVE-2022-3734

A vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unknown code in the library C:/Pro…

Mitigation only
Fix from $2,300 2022-10-28
Redis CRITICAL 9.8
CVE-2022-35951

Redis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Integer Overflow. Executing an `X…

Fix: 7.0.5+
Fix from $2,300 2022-09-23