redis kayıtları
redis üreticisine ait 51 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %2
- Silahlaştırılmış
- 1 · %2
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %90,2
- Yayından KEV’e ortanca
- 38 gün
Tekrar eden sınıflar
- CWE-190 Integer Overflow or Wraparound13
- CWE-20 Improper Input Validation6
- CWE-122 Heap-based Buffer Overflow5
- CWE-416 Use After Free4
- CWE-770 Allocation of Resources Without Limits or Throttling3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
51 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
100Hemen | CVE-2022-0543Silahlaştırılmış | It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escaperedis · redis · CWE-862 | Kritik10,0 | KEV | %99,4 | 18 Şub 2022 |
64Bu hafta | CVE-2025-49844Kavram kanıtı | Redis Lua Use-After-Free may lead to remote code executionredis · redis · CWE-416 | Kritik9,9 | — | %82,3 | 3 Eki 2025 |
58Planlayın | CVE-2023-36824İstismar yok | Heap overflow in COMMAND GETKEYS and ACL evaluation in Redisredis · redis · CWE-122 | Yüksek8,8 | — | %77,4 | 11 Tem 2023 |
47Planlayın | CVE-2022-24834Kavram kanıtı | Heap overflow issue with the Lua cjson library used by Redisredis · redis · CWE-122 | Yüksek8,8 | — | %41,1 | 13 Tem 2023 |
44Planlayın | CVE-2023-22458İstismar yok | Integer overflow in multiple Redis commands can lead to denial-of-serviceredis · redis · CWE-190 | Orta5,5 | — | %72,0 | 20 Oca 2023 |
41Planlayın | CVE-2024-46981Kavram kanıtı | Redis' Lua library commands may lead to remote code executionredis · redis · CWE-416 | Kritik9,8 | — | %8,2 | 6 Oca 2025 |
40Planlayın | CVE-2022-36021İstismar yok | Redis string pattern matching can be abused to achieve Denial of Serviceredis · redis · CWE-407 | Orta5,5 | — | %59,8 | 1 Mar 2023 |
40Planlayın | CVE-2021-32626İstismar yok | Lua scripts can overflow the heap-based Lua stack in Redisredis · redis · CWE-122 | Yüksek8,8 | — | %16,2 | 4 Eki 2021 |
40Planlayın | CVE-2022-35951İstismar yok | Redis subject to Integer Overflow leading to Remote Code Execution via Heap Overflowredis · redis · CWE-190 | Kritik9,8 | — | %3,9 | 23 Eyl 2022 |
39İzleyin | CVE-2025-27151İstismar yok | redis-check-aof may lead to stack overflow and potential RCEredis · redis · CWE-20 | Kritik9,8 | — | %1,0 | 29 May 2025 |
39İzleyin | CVE-2022-3734İstismar yok | Redis on Windows dbghelp.dll uncontrolled search pathredis · redis · CWE-426 | Kritik9,8 | — | %0,6 | 28 Eki 2022 |
39İzleyin | CVE-2023-31654İstismar yok | Redis raft master-1b8bd86 to master-7b46079 was discovered to contain an ODR violation via the component hiredisAllocFns at /opt/fs/redisrafredis · redisraft | Kritik9,8 | — | %0,6 | 23 Oca 2024 |
38İzleyin | CVE-2023-28425İstismar yok | Specially crafted MSETNX command can lead to denial-of-serviceredis · redis · CWE-77 | Orta5,5 | — | %54,7 | 20 Mar 2023 |
36İzleyin | CVE-2024-31449Kavram kanıtı | Lua library commands may lead to stack overflow and RCE in Redisredis · redis · CWE-20 | Yüksek8,8 | — | %4,5 | 7 Eki 2024 |
36İzleyin | CVE-2025-46817Kavram kanıtı | Lua library commands may lead to integer overflow and potential RCEredis · redis · CWE-190 | Yüksek8,8 | — | %3,8 | 3 Eki 2025 |
36İzleyin | CVE-2022-31144Kavram kanıtı | Potential heap overflow in Redisredis · redis · CWE-122 | Yüksek8,8 | — | %3,2 | 19 Tem 2022 |
36İzleyin | CVE-2021-32762İstismar yok | Integer overflow that can lead to heap overflow in redis-cli, redis-sentinel on some platformsredis · redis · CWE-190 | Yüksek8,8 | — | %2,6 | 4 Eki 2021 |
36İzleyin | CVE-2021-32765İstismar yok | Integer Overflow to Buffer Overflow in Hiredisredis · hiredis · CWE-190 | Yüksek8,8 | — | %2,1 | 4 Eki 2021 |
35İzleyin | CVE-2021-32675Kavram kanıtı | DoS vulnerability in Redisredis · redis · CWE-770 | Yüksek7,5 | — | %16,1 | 4 Eki 2021 |
34İzleyin | CVE-2021-32628İstismar yok | Vulnerability in handling large ziplistsredis · redis · CWE-190 | Yüksek7,5 | — | %13,5 | 4 Eki 2021 |
33İzleyin | CVE-2023-41056İstismar yok | Redis vulnerable to integer overflow in certain payloadsredis · redis · CWE-190 | Yüksek8,1 | — | %2,6 | 10 Oca 2024 |
32İzleyin | CVE-2025-62507Kavram kanıtı | Redis: Bug in XACKDEL may lead to stack overflow and potential RCEredis · redis · CWE-20 | Yüksek7,7 | — | %6,8 | 4 Kas 2025 |
32İzleyin | CVE-2025-32023Kavram kanıtı | Redis allows out of bounds writes in hyperloglog commands leading to RCEredis · redis · CWE-680 | Yüksek7,8 | — | %4,2 | 7 Tem 2025 |
32İzleyin | CVE-2022-24735İstismar yok | Lua scripts can be manipulated to overcome ACL rules in Redisredis · redis · CWE-94 | Yüksek7,8 | — | %2,3 | 27 Nis 2022 |
31İzleyin | CVE-2021-32687İstismar yok | Integer overflow issue with intsets in Redisredis · redis · CWE-190 | Yüksek7,5 | — | %4,1 | 4 Eki 2021 |
- CVE-2022-0543100Hemen
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %99redis · redis18 Şub 2022
- CVE-2025-4984464Bu hafta
Redis Lua Use-After-Free may lead to remote code execution
KritikCVSS 9,9Kavram kanıtıEPSS %82redis · redis3 Eki 2025
- CVE-2023-3682458Planlayın
Heap overflow in COMMAND GETKEYS and ACL evaluation in Redis
YüksekCVSS 8,8İstismar yokEPSS %77redis · redis11 Tem 2023
- CVE-2022-2483447Planlayın
Heap overflow issue with the Lua cjson library used by Redis
YüksekCVSS 8,8Kavram kanıtıEPSS %41redis · redis13 Tem 2023
- CVE-2023-2245844Planlayın
Integer overflow in multiple Redis commands can lead to denial-of-service
OrtaCVSS 5,5İstismar yokEPSS %72redis · redis20 Oca 2023
- CVE-2024-4698141Planlayın
Redis' Lua library commands may lead to remote code execution
KritikCVSS 9,8Kavram kanıtıEPSS %8redis · redis6 Oca 2025
- CVE-2022-3602140Planlayın
Redis string pattern matching can be abused to achieve Denial of Service
OrtaCVSS 5,5İstismar yokEPSS %60redis · redis1 Mar 2023
- CVE-2021-3262640Planlayın
Lua scripts can overflow the heap-based Lua stack in Redis
YüksekCVSS 8,8İstismar yokEPSS %16redis · redis4 Eki 2021
- CVE-2022-3595140Planlayın
Redis subject to Integer Overflow leading to Remote Code Execution via Heap Overflow
KritikCVSS 9,8İstismar yokEPSS %4redis · redis23 Eyl 2022
- CVE-2025-2715139İzleyin
redis-check-aof may lead to stack overflow and potential RCE
KritikCVSS 9,8İstismar yokEPSS %1redis · redis29 May 2025
- CVE-2022-373439İzleyin
Redis on Windows dbghelp.dll uncontrolled search path
KritikCVSS 9,8İstismar yokEPSS %1redis · redis28 Eki 2022
- CVE-2023-3165439İzleyin
Redis raft master-1b8bd86 to master-7b46079 was discovered to contain an ODR violation via the component hiredisAllocFns at /opt/fs/redisraf
KritikCVSS 9,8İstismar yokEPSS %1redis · redisraft23 Oca 2024
- CVE-2023-2842538İzleyin
Specially crafted MSETNX command can lead to denial-of-service
OrtaCVSS 5,5İstismar yokEPSS %55redis · redis20 Mar 2023
- CVE-2024-3144936İzleyin
Lua library commands may lead to stack overflow and RCE in Redis
YüksekCVSS 8,8Kavram kanıtıEPSS %4redis · redis7 Eki 2024
- CVE-2025-4681736İzleyin
Lua library commands may lead to integer overflow and potential RCE
YüksekCVSS 8,8Kavram kanıtıEPSS %4redis · redis3 Eki 2025
- CVE-2022-3114436İzleyin
Potential heap overflow in Redis
YüksekCVSS 8,8Kavram kanıtıEPSS %3redis · redis19 Tem 2022
- CVE-2021-3276236İzleyin
Integer overflow that can lead to heap overflow in redis-cli, redis-sentinel on some platforms
YüksekCVSS 8,8İstismar yokEPSS %3redis · redis4 Eki 2021
- CVE-2021-3276536İzleyin
Integer Overflow to Buffer Overflow in Hiredis
YüksekCVSS 8,8İstismar yokEPSS %2redis · hiredis4 Eki 2021
- CVE-2021-3267535İzleyin
DoS vulnerability in Redis
YüksekCVSS 7,5Kavram kanıtıEPSS %16redis · redis4 Eki 2021
- CVE-2021-3262834İzleyin
Vulnerability in handling large ziplists
YüksekCVSS 7,5İstismar yokEPSS %14redis · redis4 Eki 2021
- CVE-2023-4105633İzleyin
Redis vulnerable to integer overflow in certain payloads
YüksekCVSS 8,1İstismar yokEPSS %3redis · redis10 Oca 2024
- CVE-2025-6250732İzleyin
Redis: Bug in XACKDEL may lead to stack overflow and potential RCE
YüksekCVSS 7,7Kavram kanıtıEPSS %7redis · redis4 Kas 2025
- CVE-2025-3202332İzleyin
Redis allows out of bounds writes in hyperloglog commands leading to RCE
YüksekCVSS 7,8Kavram kanıtıEPSS %4redis · redis7 Tem 2025
- CVE-2022-2473532İzleyin
Lua scripts can be manipulated to overcome ACL rules in Redis
YüksekCVSS 7,8İstismar yokEPSS %2redis · redis27 Nis 2022
- CVE-2021-3268731İzleyin
Integer overflow issue with intsets in Redis
YüksekCVSS 7,5İstismar yokEPSS %4redis · redis4 Eki 2021