Записи redis
51 опубликованных записей вендора redis.
Профиль для исследователя
- Попали в KEV
- 1 · 2 %
- С эксплойтом
- 1 · 2 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 90,2 %
- Медиана: публикация → KEV
- 38 дн.
Повторяющиеся классы
- CWE-190 Integer Overflow or Wraparound13
- CWE-20 Improper Input Validation6
- CWE-122 Heap-based Buffer Overflow5
- CWE-416 Use After Free4
- CWE-770 Allocation of Resources Without Limits or Throttling3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
51 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2022-0543Готовый эксплойт | It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escaperedis · redis · CWE-862 | Критическая10,0 | KEV | 99,4 % | 18 февр. 2022 г. |
64На этой неделе | CVE-2025-49844Proof of concept | Redis Lua Use-After-Free may lead to remote code executionredis · redis · CWE-416 | Критическая9,9 | — | 82,3 % | 3 окт. 2025 г. |
58В плане | CVE-2023-36824Эксплойта нет | Heap overflow in COMMAND GETKEYS and ACL evaluation in Redisredis · redis · CWE-122 | Высокая8,8 | — | 77,4 % | 11 июл. 2023 г. |
47В плане | CVE-2022-24834Proof of concept | Heap overflow issue with the Lua cjson library used by Redisredis · redis · CWE-122 | Высокая8,8 | — | 41,1 % | 13 июл. 2023 г. |
44В плане | CVE-2023-22458Эксплойта нет | Integer overflow in multiple Redis commands can lead to denial-of-serviceredis · redis · CWE-190 | Средняя5,5 | — | 72,0 % | 20 янв. 2023 г. |
41В плане | CVE-2024-46981Proof of concept | Redis' Lua library commands may lead to remote code executionredis · redis · CWE-416 | Критическая9,8 | — | 8,2 % | 6 янв. 2025 г. |
40В плане | CVE-2022-36021Эксплойта нет | Redis string pattern matching can be abused to achieve Denial of Serviceredis · redis · CWE-407 | Средняя5,5 | — | 59,8 % | 1 мар. 2023 г. |
40В плане | CVE-2021-32626Эксплойта нет | Lua scripts can overflow the heap-based Lua stack in Redisredis · redis · CWE-122 | Высокая8,8 | — | 16,2 % | 4 окт. 2021 г. |
40В плане | CVE-2022-35951Эксплойта нет | Redis subject to Integer Overflow leading to Remote Code Execution via Heap Overflowredis · redis · CWE-190 | Критическая9,8 | — | 3,9 % | 23 сент. 2022 г. |
39Наблюдать | CVE-2025-27151Эксплойта нет | redis-check-aof may lead to stack overflow and potential RCEredis · redis · CWE-20 | Критическая9,8 | — | 1,0 % | 29 мая 2025 г. |
39Наблюдать | CVE-2022-3734Эксплойта нет | Redis on Windows dbghelp.dll uncontrolled search pathredis · redis · CWE-426 | Критическая9,8 | — | 0,6 % | 28 окт. 2022 г. |
39Наблюдать | CVE-2023-31654Эксплойта нет | Redis raft master-1b8bd86 to master-7b46079 was discovered to contain an ODR violation via the component hiredisAllocFns at /opt/fs/redisrafredis · redisraft | Критическая9,8 | — | 0,6 % | 23 янв. 2024 г. |
38Наблюдать | CVE-2023-28425Эксплойта нет | Specially crafted MSETNX command can lead to denial-of-serviceredis · redis · CWE-77 | Средняя5,5 | — | 54,7 % | 20 мар. 2023 г. |
36Наблюдать | CVE-2024-31449Proof of concept | Lua library commands may lead to stack overflow and RCE in Redisredis · redis · CWE-20 | Высокая8,8 | — | 4,5 % | 7 окт. 2024 г. |
36Наблюдать | CVE-2025-46817Proof of concept | Lua library commands may lead to integer overflow and potential RCEredis · redis · CWE-190 | Высокая8,8 | — | 3,8 % | 3 окт. 2025 г. |
36Наблюдать | CVE-2022-31144Proof of concept | Potential heap overflow in Redisredis · redis · CWE-122 | Высокая8,8 | — | 3,2 % | 19 июл. 2022 г. |
36Наблюдать | CVE-2021-32762Эксплойта нет | Integer overflow that can lead to heap overflow in redis-cli, redis-sentinel on some platformsredis · redis · CWE-190 | Высокая8,8 | — | 2,7 % | 4 окт. 2021 г. |
36Наблюдать | CVE-2021-32765Эксплойта нет | Integer Overflow to Buffer Overflow in Hiredisredis · hiredis · CWE-190 | Высокая8,8 | — | 2,1 % | 4 окт. 2021 г. |
35Наблюдать | CVE-2021-32675Proof of concept | DoS vulnerability in Redisredis · redis · CWE-770 | Высокая7,5 | — | 16,1 % | 4 окт. 2021 г. |
34Наблюдать | CVE-2021-32628Эксплойта нет | Vulnerability in handling large ziplistsredis · redis · CWE-190 | Высокая7,5 | — | 13,5 % | 4 окт. 2021 г. |
33Наблюдать | CVE-2023-41056Эксплойта нет | Redis vulnerable to integer overflow in certain payloadsredis · redis · CWE-190 | Высокая8,1 | — | 2,6 % | 10 янв. 2024 г. |
32Наблюдать | CVE-2025-62507Proof of concept | Redis: Bug in XACKDEL may lead to stack overflow and potential RCEredis · redis · CWE-20 | Высокая7,7 | — | 6,8 % | 4 нояб. 2025 г. |
32Наблюдать | CVE-2025-32023Proof of concept | Redis allows out of bounds writes in hyperloglog commands leading to RCEredis · redis · CWE-680 | Высокая7,8 | — | 4,2 % | 7 июл. 2025 г. |
32Наблюдать | CVE-2022-24735Эксплойта нет | Lua scripts can be manipulated to overcome ACL rules in Redisredis · redis · CWE-94 | Высокая7,8 | — | 2,3 % | 27 апр. 2022 г. |
31Наблюдать | CVE-2021-32687Эксплойта нет | Integer overflow issue with intsets in Redisredis · redis · CWE-190 | Высокая7,5 | — | 4,1 % | 4 окт. 2021 г. |
- CVE-2022-0543100Срочно
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 99 %redis · redis18 февр. 2022 г.
- CVE-2025-4984464На этой неделе
Redis Lua Use-After-Free may lead to remote code execution
КритическаяCVSS 9,9Proof of conceptEPSS 82 %redis · redis3 окт. 2025 г.
- CVE-2023-3682458В плане
Heap overflow in COMMAND GETKEYS and ACL evaluation in Redis
ВысокаяCVSS 8,8Эксплойта нетEPSS 77 %redis · redis11 июл. 2023 г.
- CVE-2022-2483447В плане
Heap overflow issue with the Lua cjson library used by Redis
ВысокаяCVSS 8,8Proof of conceptEPSS 41 %redis · redis13 июл. 2023 г.
- CVE-2023-2245844В плане
Integer overflow in multiple Redis commands can lead to denial-of-service
СредняяCVSS 5,5Эксплойта нетEPSS 72 %redis · redis20 янв. 2023 г.
- CVE-2024-4698141В плане
Redis' Lua library commands may lead to remote code execution
КритическаяCVSS 9,8Proof of conceptEPSS 8 %redis · redis6 янв. 2025 г.
- CVE-2022-3602140В плане
Redis string pattern matching can be abused to achieve Denial of Service
СредняяCVSS 5,5Эксплойта нетEPSS 60 %redis · redis1 мар. 2023 г.
- CVE-2021-3262640В плане
Lua scripts can overflow the heap-based Lua stack in Redis
ВысокаяCVSS 8,8Эксплойта нетEPSS 16 %redis · redis4 окт. 2021 г.
- CVE-2022-3595140В плане
Redis subject to Integer Overflow leading to Remote Code Execution via Heap Overflow
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %redis · redis23 сент. 2022 г.
- CVE-2025-2715139Наблюдать
redis-check-aof may lead to stack overflow and potential RCE
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %redis · redis29 мая 2025 г.
- CVE-2022-373439Наблюдать
Redis on Windows dbghelp.dll uncontrolled search path
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %redis · redis28 окт. 2022 г.
- CVE-2023-3165439Наблюдать
Redis raft master-1b8bd86 to master-7b46079 was discovered to contain an ODR violation via the component hiredisAllocFns at /opt/fs/redisraf
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %redis · redisraft23 янв. 2024 г.
- CVE-2023-2842538Наблюдать
Specially crafted MSETNX command can lead to denial-of-service
СредняяCVSS 5,5Эксплойта нетEPSS 55 %redis · redis20 мар. 2023 г.
- CVE-2024-3144936Наблюдать
Lua library commands may lead to stack overflow and RCE in Redis
ВысокаяCVSS 8,8Proof of conceptEPSS 4 %redis · redis7 окт. 2024 г.
- CVE-2025-4681736Наблюдать
Lua library commands may lead to integer overflow and potential RCE
ВысокаяCVSS 8,8Proof of conceptEPSS 4 %redis · redis3 окт. 2025 г.
- CVE-2022-3114436Наблюдать
Potential heap overflow in Redis
ВысокаяCVSS 8,8Proof of conceptEPSS 3 %redis · redis19 июл. 2022 г.
- CVE-2021-3276236Наблюдать
Integer overflow that can lead to heap overflow in redis-cli, redis-sentinel on some platforms
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %redis · redis4 окт. 2021 г.
- CVE-2021-3276536Наблюдать
Integer Overflow to Buffer Overflow in Hiredis
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %redis · hiredis4 окт. 2021 г.
- CVE-2021-3267535Наблюдать
DoS vulnerability in Redis
ВысокаяCVSS 7,5Proof of conceptEPSS 16 %redis · redis4 окт. 2021 г.
- CVE-2021-3262834Наблюдать
Vulnerability in handling large ziplists
ВысокаяCVSS 7,5Эксплойта нетEPSS 14 %redis · redis4 окт. 2021 г.
- CVE-2023-4105633Наблюдать
Redis vulnerable to integer overflow in certain payloads
ВысокаяCVSS 8,1Эксплойта нетEPSS 3 %redis · redis10 янв. 2024 г.
- CVE-2025-6250732Наблюдать
Redis: Bug in XACKDEL may lead to stack overflow and potential RCE
ВысокаяCVSS 7,7Proof of conceptEPSS 7 %redis · redis4 нояб. 2025 г.
- CVE-2025-3202332Наблюдать
Redis allows out of bounds writes in hyperloglog commands leading to RCE
ВысокаяCVSS 7,8Proof of conceptEPSS 4 %redis · redis7 июл. 2025 г.
- CVE-2022-2473532Наблюдать
Lua scripts can be manipulated to overcome ACL rules in Redis
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %redis · redis27 апр. 2022 г.
- CVE-2021-3268731Наблюдать
Integer overflow issue with intsets in Redis
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %redis · redis4 окт. 2021 г.