Dolphinscheduler
Vendor:
First CVE: Dec 18, 2020 · Active for 5 years
32
Total CVEs
More Total CVEs than 97% of tracked products
4.6
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Dolphinscheduler over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 18, 2020
5 years ago
Most Recent CVE
Jun 17, 2026
40 days ago
CVE Severity & Scoring
Dolphinscheduler32 CVEs
31%
44%
25%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network32 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low32 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None32 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low15 (46.9%)
High1 (3.1%)
None16 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32966CRITICAL DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler.
This issue affects Apache DolphinScheduler: before 3.4.2. | Jun 17, 2026 | 9.8 | 36 | NO | NO |
CVE-2024-30188HIGH File read and write vulnerability in Apache DolphinScheduler , authenticated users can illegally access additional resource files.
This issue affects Apache DolphinScheduler: from | Aug 12, 2024 | 8.1 | 36 | NO | YES |
CVE-2026-32967CRITICAL Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler.
This issue affects Apache DolphinScheduler: before 3.4.2.
Users are recommended | Jun 17, 2026 | 9.1 | 34 | NO | NO |
CVE-2024-43166CRITICAL Incorrect Default Permissions vulnerability in Apache DolphinScheduler.
This issue affects Apache DolphinScheduler: before 3.2.2.
Users are recommended to upgrade to version 3.3. | Sep 3, 2025 | 9.8 | 34 | NO | NO |
CVE-2020-11974CRITICAL In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database. | Dec 18, 2020 | 9.8 | 33 | NO | NO |
CVE-2024-43202CRITICAL Exposure of Remote Code Execution in Apache Dolphinscheduler.
This issue affects Apache DolphinScheduler: before 3.2.2.
We recommend users to upgrade Apache DolphinScheduler to | Aug 20, 2024 | 9.8 | 32 | NO | NO |
CVE-2022-45875CRITICAL Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects Apache DolphinScheduler versio | Jan 4, 2023 | 9.8 | 32 | NO | NO |
CVE-2022-45462CRITICAL Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade to version 2.0.6 or higher | Nov 23, 2022 | 9.8 | 32 | NO | NO |
CVE-2023-49109CRITICAL Exposure of Remote Code Execution in Apache Dolphinscheduler.
This issue affects Apache DolphinScheduler: before 3.2.1.
We recommend users to upgrade Apache DolphinScheduler to | Feb 20, 2024 | 9.8 | 31 | NO | NO |
CVE-2024-43115HIGH Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script.
This issue affects Apache DolphinSc | Sep 3, 2025 | 8.8 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (32 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.1% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (32 CVEs).
Media Mentions
Signals from CVEs in this product scope (32 CVEs).
Top CNAs Publishing CVEs For Dolphinscheduler
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.1.0 | 1 | 9.8 | 2.5% | 0 | 0 |
| 1.3.1 | 1 | 6.5 | 1.7% | 0 | 0 |
| 1.2.1 | 2 | 8.2 | 4.7% | 0 | 0 |
| 1.2.0 | 2 | 8.2 | 4.7% | 0 | 0 |