Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Opentsdb

First CVE: Jun 29, 2018Active for: 8 yearsTotal CVEs: 7

OpenTSDB is a distributed time-series database designed for monitoring and metrics collection at scale, presenting a narrowly scoped but high-value attack surface centered on data ingestion and retrieval endpoints. Vulnerabilities affecting the product skew strongly toward critical severity and frequently acquire public exploit code, with the recurring exposure pattern driven by input-handling weaknesses including cross-site scripting, OS command injection, and broader injection flaws that affect web interfaces and command processing. Defenders should prioritize remediation of internet-reachable instances given the product's operational role and the severity tendency of its disclosures; live exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Opentsdb over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 29, 2018
8 years ago
Most Recent CVE
Jun 30, 2023
1,120 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-35476CRITICAL
A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. The yrange value is written to a gnuplot file in the /tmp dire
Dec 16, 20209.888NOYES
CVE-2023-25826CRITICAL
Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code o
May 3, 20239.854NOYES
CVE-2023-36812CRITICAL
OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Execution vulnerability by writing user-controlled input to Gnup
Jun 30, 20239.849NOYES
CVE-2018-12972CRITICAL
An issue was discovered in OpenTSDB 2.3.0. Many parameters to the /q URI can execute commands, including o, key, style, and yrange and y2range and their JSON input.
Jun 29, 20189.830NONO
CVE-2018-12973MEDIUM
An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter 'json' to the /q URI.
Jun 29, 20186.122NONO
CVE-2023-25827MEDIUM
Due to insufficient validation of parameters reflected in error messages by the legacy HTTP query API and the logging endpoint, it is possible to inject and execute malicious Java
May 3, 20236.121NONO
CVE-2018-13003MEDIUM
An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter 'type' to the /suggest URI.
Jun 29, 20186.121NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
43%
57%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (57.1%)
Unknown0 (0.0%)
Required3 (42.9%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
42.9% of CVEs· 99th percentile
Nuclei
1 CVE
14.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Opentsdb.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Opentsdb — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Opentsdb's Products

View all 3 CNAs →

Top CWEs