Weaviate records
4 published records for vendor weaviate.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-266 Incorrect Privilege Assignment1
- CWE-617 Reachable Assertion1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2026-59093No exploit | Weaviate < 1.38.0 - Privilege Escalation via Unchecked Permissions in RBAC Role Assignmentweaviate · weaviate · CWE-266 | High8.7 | — | 0.7% | Jul 2, 2026 |
31Monitor | CVE-2023-38976No exploit | An issue in weaviate v.1.20.0 allows a remote attacker to cause a denial of service via the handleUnbatchedGraphQLRequest function.weaviate · weaviate · CWE-617 | High7.5 | — | 2.1% | Aug 21, 2023 |
28Monitor | CVE-2025-67818No exploit | An issue was discovered in Weaviate OSS before 1.33.4.weaviate · weaviate · CWE-22 | High7.2 | — | 0.9% | Dec 12, 2025 |
19Monitor | CVE-2025-67819No exploit | An issue was discovered in Weaviate OSS before 1.33.4.weaviate · weaviate · CWE-22 | Medium4.9 | — | 0.5% | Dec 12, 2025 |
- CVE-2026-5909334Monitor
Weaviate < 1.38.0 - Privilege Escalation via Unchecked Permissions in RBAC Role Assignment
HighCVSS 8.7No exploitEPSS 1%weaviate · weaviateJul 2, 2026
- CVE-2023-3897631Monitor
An issue in weaviate v.1.20.0 allows a remote attacker to cause a denial of service via the handleUnbatchedGraphQLRequest function.
HighCVSS 7.5No exploitEPSS 2%weaviate · weaviateAug 21, 2023
- CVE-2025-6781828Monitor
An issue was discovered in Weaviate OSS before 1.33.4.
HighCVSS 7.2No exploitEPSS 1%weaviate · weaviateDec 12, 2025
- CVE-2025-6781919Monitor
An issue was discovered in Weaviate OSS before 1.33.4.
MediumCVSS 4.9No exploitEPSS 1%weaviate · weaviateDec 12, 2025