redis records
51 published records for vendor redis.
Researcher profile
- Entered KEV
- 1 · 2%
- Weaponized
- 1 · 2%
- Pre-auth RCE
- 5
- With a fix record
- 90.2%
- Median publish → KEV
- 38 days
Recurring classes
- CWE-190 Integer Overflow or Wraparound13
- CWE-20 Improper Input Validation6
- CWE-122 Heap-based Buffer Overflow5
- CWE-416 Use After Free4
- CWE-770 Allocation of Resources Without Limits or Throttling3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
51 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2022-0543Weaponized | It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escaperedis · redis · CWE-862 | Critical10.0 | KEV | 99.4% | Feb 18, 2022 |
64This week | CVE-2025-49844Proof of concept | Redis Lua Use-After-Free may lead to remote code executionredis · redis · CWE-416 | Critical9.9 | — | 82.3% | Oct 3, 2025 |
58Plan | CVE-2023-36824No exploit | Heap overflow in COMMAND GETKEYS and ACL evaluation in Redisredis · redis · CWE-122 | High8.8 | — | 77.4% | Jul 11, 2023 |
47Plan | CVE-2022-24834Proof of concept | Heap overflow issue with the Lua cjson library used by Redisredis · redis · CWE-122 | High8.8 | — | 41.1% | Jul 13, 2023 |
44Plan | CVE-2023-22458No exploit | Integer overflow in multiple Redis commands can lead to denial-of-serviceredis · redis · CWE-190 | Medium5.5 | — | 72.0% | Jan 20, 2023 |
41Plan | CVE-2024-46981Proof of concept | Redis' Lua library commands may lead to remote code executionredis · redis · CWE-416 | Critical9.8 | — | 8.2% | Jan 6, 2025 |
40Plan | CVE-2022-36021No exploit | Redis string pattern matching can be abused to achieve Denial of Serviceredis · redis · CWE-407 | Medium5.5 | — | 59.8% | Mar 1, 2023 |
40Plan | CVE-2021-32626No exploit | Lua scripts can overflow the heap-based Lua stack in Redisredis · redis · CWE-122 | High8.8 | — | 16.2% | Oct 4, 2021 |
40Plan | CVE-2022-35951No exploit | Redis subject to Integer Overflow leading to Remote Code Execution via Heap Overflowredis · redis · CWE-190 | Critical9.8 | — | 3.9% | Sep 23, 2022 |
39Monitor | CVE-2025-27151No exploit | redis-check-aof may lead to stack overflow and potential RCEredis · redis · CWE-20 | Critical9.8 | — | 1.0% | May 29, 2025 |
39Monitor | CVE-2022-3734No exploit | Redis on Windows dbghelp.dll uncontrolled search pathredis · redis · CWE-426 | Critical9.8 | — | 0.6% | Oct 28, 2022 |
39Monitor | CVE-2023-31654No exploit | Redis raft master-1b8bd86 to master-7b46079 was discovered to contain an ODR violation via the component hiredisAllocFns at /opt/fs/redisrafredis · redisraft | Critical9.8 | — | 0.6% | Jan 23, 2024 |
38Monitor | CVE-2023-28425No exploit | Specially crafted MSETNX command can lead to denial-of-serviceredis · redis · CWE-77 | Medium5.5 | — | 54.7% | Mar 20, 2023 |
36Monitor | CVE-2024-31449Proof of concept | Lua library commands may lead to stack overflow and RCE in Redisredis · redis · CWE-20 | High8.8 | — | 4.5% | Oct 7, 2024 |
36Monitor | CVE-2025-46817Proof of concept | Lua library commands may lead to integer overflow and potential RCEredis · redis · CWE-190 | High8.8 | — | 3.8% | Oct 3, 2025 |
36Monitor | CVE-2022-31144Proof of concept | Potential heap overflow in Redisredis · redis · CWE-122 | High8.8 | — | 3.2% | Jul 19, 2022 |
36Monitor | CVE-2021-32762No exploit | Integer overflow that can lead to heap overflow in redis-cli, redis-sentinel on some platformsredis · redis · CWE-190 | High8.8 | — | 2.7% | Oct 4, 2021 |
36Monitor | CVE-2021-32765No exploit | Integer Overflow to Buffer Overflow in Hiredisredis · hiredis · CWE-190 | High8.8 | — | 2.1% | Oct 4, 2021 |
35Monitor | CVE-2021-32675Proof of concept | DoS vulnerability in Redisredis · redis · CWE-770 | High7.5 | — | 16.1% | Oct 4, 2021 |
34Monitor | CVE-2021-32628No exploit | Vulnerability in handling large ziplistsredis · redis · CWE-190 | High7.5 | — | 13.5% | Oct 4, 2021 |
33Monitor | CVE-2023-41056No exploit | Redis vulnerable to integer overflow in certain payloadsredis · redis · CWE-190 | High8.1 | — | 2.6% | Jan 10, 2024 |
32Monitor | CVE-2025-62507Proof of concept | Redis: Bug in XACKDEL may lead to stack overflow and potential RCEredis · redis · CWE-20 | High7.7 | — | 6.8% | Nov 4, 2025 |
32Monitor | CVE-2025-32023Proof of concept | Redis allows out of bounds writes in hyperloglog commands leading to RCEredis · redis · CWE-680 | High7.8 | — | 4.2% | Jul 7, 2025 |
32Monitor | CVE-2022-24735No exploit | Lua scripts can be manipulated to overcome ACL rules in Redisredis · redis · CWE-94 | High7.8 | — | 2.3% | Apr 27, 2022 |
31Monitor | CVE-2021-32687No exploit | Integer overflow issue with intsets in Redisredis · redis · CWE-190 | High7.5 | — | 4.1% | Oct 4, 2021 |
- CVE-2022-0543100Now
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape
CriticalCVSS 10.0KEVWeaponizedEPSS 99%redis · redisFeb 18, 2022
- CVE-2025-4984464This week
Redis Lua Use-After-Free may lead to remote code execution
CriticalCVSS 9.9Proof of conceptEPSS 82%redis · redisOct 3, 2025
- CVE-2023-3682458Plan
Heap overflow in COMMAND GETKEYS and ACL evaluation in Redis
HighCVSS 8.8No exploitEPSS 77%redis · redisJul 11, 2023
- CVE-2022-2483447Plan
Heap overflow issue with the Lua cjson library used by Redis
HighCVSS 8.8Proof of conceptEPSS 41%redis · redisJul 13, 2023
- CVE-2023-2245844Plan
Integer overflow in multiple Redis commands can lead to denial-of-service
MediumCVSS 5.5No exploitEPSS 72%redis · redisJan 20, 2023
- CVE-2024-4698141Plan
Redis' Lua library commands may lead to remote code execution
CriticalCVSS 9.8Proof of conceptEPSS 8%redis · redisJan 6, 2025
- CVE-2022-3602140Plan
Redis string pattern matching can be abused to achieve Denial of Service
MediumCVSS 5.5No exploitEPSS 60%redis · redisMar 1, 2023
- CVE-2021-3262640Plan
Lua scripts can overflow the heap-based Lua stack in Redis
HighCVSS 8.8No exploitEPSS 16%redis · redisOct 4, 2021
- CVE-2022-3595140Plan
Redis subject to Integer Overflow leading to Remote Code Execution via Heap Overflow
CriticalCVSS 9.8No exploitEPSS 4%redis · redisSep 23, 2022
- CVE-2025-2715139Monitor
redis-check-aof may lead to stack overflow and potential RCE
CriticalCVSS 9.8No exploitEPSS 1%redis · redisMay 29, 2025
- CVE-2022-373439Monitor
Redis on Windows dbghelp.dll uncontrolled search path
CriticalCVSS 9.8No exploitEPSS 1%redis · redisOct 28, 2022
- CVE-2023-3165439Monitor
Redis raft master-1b8bd86 to master-7b46079 was discovered to contain an ODR violation via the component hiredisAllocFns at /opt/fs/redisraf
CriticalCVSS 9.8No exploitEPSS 1%redis · redisraftJan 23, 2024
- CVE-2023-2842538Monitor
Specially crafted MSETNX command can lead to denial-of-service
MediumCVSS 5.5No exploitEPSS 55%redis · redisMar 20, 2023
- CVE-2024-3144936Monitor
Lua library commands may lead to stack overflow and RCE in Redis
HighCVSS 8.8Proof of conceptEPSS 4%redis · redisOct 7, 2024
- CVE-2025-4681736Monitor
Lua library commands may lead to integer overflow and potential RCE
HighCVSS 8.8Proof of conceptEPSS 4%redis · redisOct 3, 2025
- CVE-2022-3114436Monitor
Potential heap overflow in Redis
HighCVSS 8.8Proof of conceptEPSS 3%redis · redisJul 19, 2022
- CVE-2021-3276236Monitor
Integer overflow that can lead to heap overflow in redis-cli, redis-sentinel on some platforms
HighCVSS 8.8No exploitEPSS 3%redis · redisOct 4, 2021
- CVE-2021-3276536Monitor
Integer Overflow to Buffer Overflow in Hiredis
HighCVSS 8.8No exploitEPSS 2%redis · hiredisOct 4, 2021
- CVE-2021-3267535Monitor
DoS vulnerability in Redis
HighCVSS 7.5Proof of conceptEPSS 16%redis · redisOct 4, 2021
- CVE-2021-3262834Monitor
Vulnerability in handling large ziplists
HighCVSS 7.5No exploitEPSS 14%redis · redisOct 4, 2021
- CVE-2023-4105633Monitor
Redis vulnerable to integer overflow in certain payloads
HighCVSS 8.1No exploitEPSS 3%redis · redisJan 10, 2024
- CVE-2025-6250732Monitor
Redis: Bug in XACKDEL may lead to stack overflow and potential RCE
HighCVSS 7.7Proof of conceptEPSS 7%redis · redisNov 4, 2025
- CVE-2025-3202332Monitor
Redis allows out of bounds writes in hyperloglog commands leading to RCE
HighCVSS 7.8Proof of conceptEPSS 4%redis · redisJul 7, 2025
- CVE-2022-2473532Monitor
Lua scripts can be manipulated to overcome ACL rules in Redis
HighCVSS 7.8No exploitEPSS 2%redis · redisApr 27, 2022
- CVE-2021-3268731Monitor
Integer overflow issue with intsets in Redis
HighCVSS 7.5No exploitEPSS 4%redis · redisOct 4, 2021