Vulnerabilities > Redis

DATE CVE VULNERABILITY TITLE RISK
2024-01-23 CVE-2023-31654 Unspecified vulnerability in Redis Redisraft
Redis raft master-1b8bd86 to master-7b46079 was discovered to contain an ODR violation via the component hiredisAllocFns at /opt/fs/redisraft/deps/hiredis/alloc.c.
network
low complexity
redis
critical
9.8
2024-01-10 CVE-2023-41056 Mismatched Memory Management Routines vulnerability in multiple products
Redis is an in-memory database that persists on disk.
network
high complexity
redis fedoraproject CWE-762
8.1
2023-10-18 CVE-2023-45145 Exposure of Resource to Wrong Sphere vulnerability in multiple products
Redis is an in-memory database that persists on disk.
local
high complexity
redis fedoraproject debian CWE-668
3.6
2023-09-06 CVE-2023-41053 Improper Privilege Management vulnerability in Redis
Redis is an in-memory database that persists on disk.
local
low complexity
redis CWE-269
3.3
2023-07-15 CVE-2021-31294 Reachable Assertion vulnerability in Redis
Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET command).
network
high complexity
redis CWE-617
5.9
2023-07-13 CVE-2022-24834 Integer Overflow to Buffer Overflow vulnerability in multiple products
Redis is an in-memory database that persists on disk.
network
low complexity
redis fedoraproject CWE-680
8.8
2023-07-11 CVE-2023-36824 Incorrect Calculation of Buffer Size vulnerability in multiple products
Redis is an in-memory database that persists on disk.
network
low complexity
redis fedoraproject CWE-131
8.8
2023-05-18 CVE-2023-31655 Unspecified vulnerability in Redis 7.0.10
redis v7.0.10 was discovered to contain a segmentation violation.
network
low complexity
redis
7.5
2023-04-18 CVE-2023-28856 Reachable Assertion vulnerability in multiple products
Redis is an open source, in-memory database that persists on disk.
network
low complexity
redis debian fedoraproject CWE-617
6.5
2023-03-26 CVE-2023-28858 Off-by-one Error vulnerability in Redis Redis-Py
redis-py before 4.5.3 leaves a connection open after canceling an async Redis command at an inopportune time, and can send response data to the client of an unrelated request in an off-by-one manner.
network
high complexity
redis CWE-193
3.7