aiven records
8 published records for vendor aiven.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 62.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-215 Insertion of Sensitive Information Into Debugging Code1
- CWE-20 Improper Input Validation1
- CWE-285 Improper Authorization1
- CWE-402 Transmission of Private Resources into a New Sphere ('Resource Leak')1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2023-32305No exploit | aiven-extras PostgreSQL Privilege Escalation Through Overloaded Search Pathaiven · aiven · CWE-20 | High8.8 | — | 0.7% | May 12, 2023 |
30Monitor | CVE-2023-51390No exploit | Information Disclosure Vulnerability in Journalpumpaiven · journalpump · CWE-215 | High7.5 | — | 0.3% | Dec 20, 2023 |
30Monitor | CVE-2025-67745No exploit | Myhoard logs backup encryption key in plain textaiven · myhoard · CWE-402 | High7.5 | — | 0.2% | Dec 18, 2025 |
28Monitor | CVE-2025-55282No exploit | aiven-db-migrate allows Privilege Escalation via unrestricted search_path during migrationaiven · aiven-db-migrate · CWE-22 | High7.2 | — | 0.7% | Aug 18, 2025 |
28Monitor | CVE-2025-55283No exploit | aiven-db-migrate allows Privilege Escalation through use of psql during migrationaiven · aiven-db-migrate · CWE-77 | High7.2 | — | 0.6% | Aug 18, 2025 |
21Monitor | CVE-2026-29190No exploit | Karapace: Path Traversal in Backup Readeraiven · karapace · CWE-22 | Medium5.3 | — | 0.4% | Mar 7, 2026 |
19Monitor | CVE-2026-39961No exploit | Aiven Operator has cross-namespace secret exfiltration via ClickhouseUser connInfoSecretSourceaiven · aiven operator · CWE-269 | Medium4.9 | — | 0.5% | Apr 9, 2026 |
17Monitor | CVE-2026-25999No exploit | Klaw has an improper authorisation check on /resetMemoryCacheaiven · klaw · CWE-285 | Medium4.3 | — | 0.4% | Feb 11, 2026 |
- CVE-2023-3230535Monitor
aiven-extras PostgreSQL Privilege Escalation Through Overloaded Search Path
HighCVSS 8.8No exploitEPSS 1%aiven · aivenMay 12, 2023
- CVE-2023-5139030Monitor
Information Disclosure Vulnerability in Journalpump
HighCVSS 7.5No exploitEPSS 0%aiven · journalpumpDec 20, 2023
- CVE-2025-6774530Monitor
Myhoard logs backup encryption key in plain text
HighCVSS 7.5No exploitEPSS 0%aiven · myhoardDec 18, 2025
- CVE-2025-5528228Monitor
aiven-db-migrate allows Privilege Escalation via unrestricted search_path during migration
HighCVSS 7.2No exploitEPSS 1%aiven · aiven-db-migrateAug 18, 2025
- CVE-2025-5528328Monitor
aiven-db-migrate allows Privilege Escalation through use of psql during migration
HighCVSS 7.2No exploitEPSS 1%aiven · aiven-db-migrateAug 18, 2025
- CVE-2026-2919021Monitor
Karapace: Path Traversal in Backup Reader
MediumCVSS 5.3No exploitEPSS 0%aiven · karapaceMar 7, 2026
- CVE-2026-3996119Monitor
Aiven Operator has cross-namespace secret exfiltration via ClickhouseUser connInfoSecretSource
MediumCVSS 4.9No exploitEPSS 0%aiven · aiven operatorApr 9, 2026
- CVE-2026-2599917Monitor
Klaw has an improper authorisation check on /resetMemoryCache
MediumCVSS 4.3No exploitEPSS 0%aiven · klawFeb 11, 2026