Vulnerabilities > Tdengine

DATE CVE VULNERABILITY TITLE RISK
2023-07-25 CVE-2023-38502 Unspecified vulnerability in Tdengine
TDengine is an open source, time-series database optimized for Internet of Things devices.
network
low complexity
tdengine
6.5
2023-06-06 CVE-2023-34111 Command Injection vulnerability in Tdengine Grafana
The `Release PR Merged` workflow in the github repo taosdata/grafanaplugin is subject to a command injection vulnerability which allows for arbitrary code execution within the github action context due to the insecure usage of `${{ github.event.pull_request.title }}` in a bash command within the GitHub workflow.
network
low complexity
tdengine CWE-77
critical
9.8