Ignite
Vendor:
First CVE: Apr 7, 2017 · Active for 9 years
9
Total CVEs
More Total CVEs than 86% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 63% of tracked products
11.1%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Ignite over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 7, 2017
9 years ago
Most Recent CVE
May 28, 2026
57 days ago
CVE Severity & Scoring
Ignite9 CVEs
11%
22%
11%
56%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (77.8%)
High2 (22.2%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (11.1%)
High1 (11.1%)
None7 (77.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1273CRITICAL Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of s | Apr 11, 2018 | 9.8 | 98 | YES | YES |
CVE-2018-8018CRITICAL In Apache Ignite before 2.4.8 and 2.5.x before 2.5.3, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible | Jul 20, 2018 | 9.8 | 33 | NO | NO |
CVE-2018-1295CRITICAL In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary cod | Apr 2, 2018 | 9.8 | 33 | NO | NO |
CVE-2024-52577CRITICAL In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerability could be exploited if an att | Feb 14, 2025 | 9.0 | 30 | NO | NO |
CVE-2025-48977MEDIUM Relative Path Traversal vulnerability in Apache Ignite REST API.
Authenticated REST API users can read any file on the server with "cmd=log" command and a log path crafted in a ce | May 28, 2026 | 6.5 | 27 | NO | NO |
CVE-2017-7686HIGH Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixes and performance imp | Jun 28, 2017 | 7.5 | 25 | NO | NO |
CVE-2020-1963CRITICAL Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a filesystem. | Jun 3, 2020 | 9.1 | 24 | NO | NO |
CVE-2016-6805MEDIUM Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents. | Apr 7, 2017 | 5.9 | 22 | NO | NO |
In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory i | Apr 1, 2021 | 2.7 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
1 CVE
11.1% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
11.1% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Ignite
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0.0 | 1 | 7.5 | 3.0% | 0 | 0 |
| 1.9.0 | 1 | 7.5 | 3.0% | 0 | 0 |
| 1.8.0 | 1 | 7.5 | 3.0% | 0 | 0 |
| 1.7.0 | 1 | 7.5 | 3.0% | 0 | 0 |
| 1.6.0 | 1 | 7.5 | 3.0% | 0 | 0 |
| 1.5.0 | 1 | 7.5 | 3.0% | 0 | 0 |
| 1.4.0 | 1 | 7.5 | 3.0% | 0 | 0 |
| 1.3.0 | 1 | 7.5 | 3.0% | 0 | 0 |
| 1.2.0 | 1 | 7.5 | 3.0% | 0 | 0 |
| 1.1.0 | 1 | 7.5 | 3.0% | 0 | 0 |
| 1.0.0 | 2 | 8.7 | 49.3% | 1 | 1 |