Skip to content
Noroxi

redis records

51 published records for vendor redis.

Researcher profile

Entered KEV
1 · 2%
Weaponized
1 · 2%
Pre-auth RCE
5
With a fix record
90.2%
Median publish → KEV
38 days

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

51 records
  • It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape

    CriticalCVSS 10.0KEVWeaponizedEPSS 99%

    redis · redisFeb 18, 2022

  • CVE-2025-49844
    64This week

    Redis Lua Use-After-Free may lead to remote code execution

    CriticalCVSS 9.9Proof of conceptEPSS 82%

    redis · redisOct 3, 2025

  • Heap overflow in COMMAND GETKEYS and ACL evaluation in Redis

    HighCVSS 8.8No exploitEPSS 77%

    redis · redisJul 11, 2023

  • Heap overflow issue with the Lua cjson library used by Redis

    HighCVSS 8.8Proof of conceptEPSS 41%

    redis · redisJul 13, 2023

  • Integer overflow in multiple Redis commands can lead to denial-of-service

    MediumCVSS 5.5No exploitEPSS 72%

    redis · redisJan 20, 2023

  • Redis' Lua library commands may lead to remote code execution

    CriticalCVSS 9.8Proof of conceptEPSS 8%

    redis · redisJan 6, 2025

  • Redis string pattern matching can be abused to achieve Denial of Service

    MediumCVSS 5.5No exploitEPSS 60%

    redis · redisMar 1, 2023

  • Lua scripts can overflow the heap-based Lua stack in Redis

    HighCVSS 8.8No exploitEPSS 16%

    redis · redisOct 4, 2021

  • Redis subject to Integer Overflow leading to Remote Code Execution via Heap Overflow

    CriticalCVSS 9.8No exploitEPSS 4%

    redis · redisSep 23, 2022

  • redis-check-aof may lead to stack overflow and potential RCE

    CriticalCVSS 9.8No exploitEPSS 1%

    redis · redisMay 29, 2025

  • CVE-2022-3734
    39Monitor

    Redis on Windows dbghelp.dll uncontrolled search path

    CriticalCVSS 9.8No exploitEPSS 1%

    redis · redisOct 28, 2022

  • Redis raft master-1b8bd86 to master-7b46079 was discovered to contain an ODR violation via the component hiredisAllocFns at /opt/fs/redisraf

    CriticalCVSS 9.8No exploitEPSS 1%

    redis · redisraftJan 23, 2024

  • Specially crafted MSETNX command can lead to denial-of-service

    MediumCVSS 5.5No exploitEPSS 55%

    redis · redisMar 20, 2023

  • Lua library commands may lead to stack overflow and RCE in Redis

    HighCVSS 8.8Proof of conceptEPSS 4%

    redis · redisOct 7, 2024

  • Lua library commands may lead to integer overflow and potential RCE

    HighCVSS 8.8Proof of conceptEPSS 4%

    redis · redisOct 3, 2025

  • Potential heap overflow in Redis

    HighCVSS 8.8Proof of conceptEPSS 3%

    redis · redisJul 19, 2022

  • Integer overflow that can lead to heap overflow in redis-cli, redis-sentinel on some platforms

    HighCVSS 8.8No exploitEPSS 3%

    redis · redisOct 4, 2021

  • Integer Overflow to Buffer Overflow in Hiredis

    HighCVSS 8.8No exploitEPSS 2%

    redis · hiredisOct 4, 2021

  • DoS vulnerability in Redis

    HighCVSS 7.5Proof of conceptEPSS 16%

    redis · redisOct 4, 2021

  • Vulnerability in handling large ziplists

    HighCVSS 7.5No exploitEPSS 14%

    redis · redisOct 4, 2021

  • Redis vulnerable to integer overflow in certain payloads

    HighCVSS 8.1No exploitEPSS 3%

    redis · redisJan 10, 2024

  • Redis: Bug in XACKDEL may lead to stack overflow and potential RCE

    HighCVSS 7.7Proof of conceptEPSS 7%

    redis · redisNov 4, 2025

  • Redis allows out of bounds writes in hyperloglog commands leading to RCE

    HighCVSS 7.8Proof of conceptEPSS 4%

    redis · redisJul 7, 2025

  • Lua scripts can be manipulated to overcome ACL rules in Redis

    HighCVSS 7.8No exploitEPSS 2%

    redis · redisApr 27, 2022

  • Integer overflow issue with intsets in Redis

    HighCVSS 7.5No exploitEPSS 4%

    redis · redisOct 4, 2021