Iotdb
Vendor:
First CVE: Apr 27, 2020 · Active for 6 years
20
Total CVEs
More Total CVEs than 94% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
8.5
Avg CVSS
Higher Avg CVSS than 76% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Iotdb over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 27, 2020
6 years ago
Most Recent CVE
Jul 6, 2026
18 days ago
CVE Severity & Scoring
Iotdb20 CVEs
50%
45%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network20 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None19 (95.0%)
Unknown0 (0.0%)
Required1 (5.0%)
Privileges Required
Low1 (5.0%)
High0 (0.0%)
None19 (95.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-24014CRITICAL Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal | Jul 6, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-24013CRITICAL Authentication Bypass by Spoofing vulnerability in Apache IoTDB.
Certain Thrift RPC query handlers lack strict validation of the sessionId
parameter. An attacker can construct requ | Jul 6, 2026 | 9.1 | 39 | NO | NO |
CVE-2026-24012HIGH Uncontrolled Resource Consumption vulnerability in Apache IoTDB.
Some interface fails to impose reasonable
limits on the time span and aggregation interval of the query. An attac | Jul 6, 2026 | 7.5 | 34 | NO | NO |
CVE-2020-25649HIGH A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The hi | Dec 3, 2020 | 7.5 | 33 | NO | NO |
CVE-2026-24713CRITICAL Improper Input Validation vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7.
Users are recommended to upgrade to ve | Mar 9, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-24015CRITICAL A vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7.
Users are recommended to upgrade to version 1.3.7 or 2.0.7, wh | Mar 9, 2026 | 9.8 | 32 | NO | NO |
CVE-2023-24831CRITICAL Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana Connector: from 0.13.0 through 0.13.3.
Attackers could log | Apr 17, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-46226CRITICAL Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2.
Users are recommended to upgrade to version 1.3.0, which fixes the i | Jan 15, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-24780CRITICAL Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI.
Thi | May 14, 2025 | 9.8 | 28 | NO | NO |
CVE-2023-24829HIGH Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component from 0.13.0 before 0.13.3. iotdb-web-workbench | Jan 31, 2023 | 8.8 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (20 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (20 CVEs).
Media Mentions
Signals from CVEs in this product scope (20 CVEs).
Top CNAs Publishing CVEs For Iotdb
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0.1 | 1 | 7.5 | 0.7% | 0 | 0 |
| 0.13.0 | 2 | 8.2 | 1.1% | 0 | 0 |