11 entries matching redis — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-66373 | Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code executio | HIGH | 7.5 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-25243 | redis-server RESTORE invalid memory access may allow remote code execution | UNKNOWN | — | 87%ile | Microsoft | 2026-05-12 |
| CVE-2026-23631 | redis-server Lua use-after-free may allow remote code execution | UNKNOWN | — | 85%ile | Microsoft | 2026-05-12 |
| CVE-2026-23479 | redis-server use-after-free in unblock client flow may allow remote code execution | UNKNOWN | — | 67%ile | Microsoft | 2026-05-12 |
| CVE-2026-25588 | RedisTimeSeries RESTORE invalid memory access may allow remote code execution | UNKNOWN | — | 62%ile | Microsoft | 2026-05-12 |
| CVE-2026-25589 | RedisBloom RESTORE invalid memory access may allow remote code execution | UNKNOWN | — | 69%ile | Microsoft | 2026-05-12 |
| CVE-2025-48367 | Redis DoS Vulnerability due to bad connection error handling | HIGH | 7.5 | 51%ile | Microsoft | 2025-07-08 |
| CVE-2025-32023 | Redis allows out of bounds writes in hyperloglog commands leading to RCE | HIGH | 7.0 | 89%ile | Microsoft | 2025-07-08 |
| CVE-2025-27151 | redis-check-aof may lead to stack overflow and potential RCE | MEDIUM | 4.7 | 54%ile | Microsoft | 2025-05-13 |
| CVE-2022-35977 | Integer overflow in certain command arguments can drive Redis to OOM panic | MEDIUM | 5.5 | 98%ile | Microsoft | 2023-01-10 |
| CVE-2023-22458 | Integer overflow in multiple Redis commands can lead to denial-of-service | MEDIUM | 5.5 | 99%ile | Microsoft | 2023-01-10 |