Yugabyte, Inc.
First CVE: Aug 12, 2022Active for: 4 years
18
CVEs Published
More CVEs Published than 37% of tracked CNAs
3.6
Avg CVEs / Year
More Avg CVEs / Year than 26% of tracked CNAs
6.8
Avg CVSS Score
Higher Avg CVSS Score than 34% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Yugabyte, Inc. as a CNA, 38.9% affect products that Yugabyte, Inc. develops as a vendor.
38.9%
61.1%
Self-reported: 7Third-party: 11
Of all the CVEs published that affect products developed by Yugabyte, Inc., 77.8% are self-published by Yugabyte, Inc. as a CNA.
77.8%
22.2%
Self-published: 7Published by other CNAs: 2
Trends Over Time
The number and severity of CVEs published by Yugabyte, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 12, 2022
3 years ago
Most Recent CVE
Feb 5, 2026
169 days ago
Top CVEs
All CVEs published by Yugabyte, Inc. as a CNA, regardless of affected vendor or product.
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0745CRITICAL
The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary
files through the backup upload endpoint by using path trave | Feb 9, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-37397CRITICAL An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is en | Aug 12, 2022 | 9.8 | 30 | NO | NO |
CVE-2023-0574CRITICAL Server-Side Request Forgery (SSRF), Improperly Controlled Modification of Dynamically-Determined Object Attributes, Improper Restriction of Excessive Authentication Attempts vulner | Feb 9, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-0575CRITICAL External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (Devops | Feb 9, 2023 | 9.8 | 27 | NO | NO |
CVE-2025-8863HIGH YugabyteDB diagnostic information was transmitted over HTTP, which could expose sensitive data during transmission | Aug 11, 2025 | 7.0 | 23 | NO | NO |
CVE-2025-8864MEDIUM Shared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup logs | Aug 11, 2025 | 6.8 | 22 | NO | NO |
CVE-2025-8862HIGH YugabyteDB has been collecting diagnostics information from YugabyteDB servers, which may include sensitive gflag configurations. To mitigate this, we recommend upgrading the datab | Aug 11, 2025 | 7.0 | 21 | NO | NO |
CVE-2024-0006MEDIUM Information exposure in the logging system in Yugabyte Platform allows local attackers with access to application logs to obtain database user credentials in log files, potentially | Jul 19, 2024 | 5.4 | 21 | NO | NO |
CVE-2023-6001HIGH Prometheus metrics are available without
authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment. | Nov 8, 2023 | 7.5 | 21 | NO | NO |
CVE-2023-4640HIGH The controller responsible for setting the logging level does not include any authorization
checks to ensure the user is authenticated. This can be seen by noting that it extends
C | Aug 30, 2023 | 7.5 | 21 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA18 CVEs
50%
22%
22%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (5.6%)
Network10 (55.6%)
Unknown0 (0.0%)
Physical1 (5.6%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (55.6%)
High8 (44.4%)
Unknown0 (0.0%)
User Interaction
None12 (66.7%)
Unknown0 (0.0%)
Required1 (5.6%)
Privileges Required
Low2 (11.1%)
High7 (38.9%)
None9 (50.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Yugabyte, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Yugabyte, Inc. as a CNA — matched by CVE ID, not by organization name.