Cassandra

Vendor:

First CVE: Apr 3, 2015 · Active for 11 years

16
Total CVEs
More Total CVEs than 92% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
6.3%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Cassandra over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 3, 2015
11 years ago
Most Recent CVE
Apr 7, 2026
108 days ago

CVE Severity & Scoring

Cassandra16 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local3 (18.8%)
Network12 (75.0%)
Unknown1 (6.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (81.3%)
High2 (12.5%)
Unknown1 (6.3%)
User Interaction
None14 (87.5%)
Unknown1 (6.3%)
Required1 (6.3%)
Privileges Required
Low7 (43.8%)
High1 (6.3%)
None7 (43.8%)
Unknown1 (6.3%)

Top CVEs

Signals from CVEs in this product scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and avai
Apr 21, 20169.895YESNO
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threa
Feb 11, 20229.171NOYES
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java
Apr 23, 20195.940NONO
The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbi
Jun 28, 20189.831NONO
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).
Apr 13, 20177.530NONO
Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associate their own certificate identi
Apr 7, 20268.829NONO
Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cass
Aug 25, 20258.828NONO
Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cass
Feb 4, 20258.825NONO
Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra This issue affects Apache Cassandra: fr
May 30, 20237.825NONO
Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes. Users are recommended to upgrade to v
Apr 7, 20266.523NONO

Exploit Exposure

Signals from CVEs in this product scope (16 CVEs).

CISA KEV
1 CVE
6.2% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
6.2% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (16 CVEs).

Media Mentions

Signals from CVEs in this product scope (16 CVEs).

Top CNAs Publishing CVEs For Cassandra

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.0.015.30.3%00
4.0.036.520.7%10
3.11.417.511.3%00
2.1.317.56.7%00
2.1.217.56.7%00
2.1.117.56.7%00
2.1.017.56.7%00
2.0.917.56.7%00
2.0.817.56.7%00
2.0.717.56.7%00
2.0.617.56.7%00
2.0.517.56.7%00
2.0.417.56.7%00
2.0.317.56.7%00
2.0.217.56.7%00
2.0.1317.56.7%00
2.0.1217.56.7%00
2.0.1117.56.7%00
2.0.1017.56.7%00
2.0.117.56.7%00