Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

PingCAP (US), Inc.

First CVE: May 31, 2022Active for: 4 yearsTotal CVEs: 7

PingCAP develops TiDB, a distributed SQL database platform that is gaining traction in mission-critical deployments despite a narrow product footprint. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through weakness classes including buffer overflows, NULL-pointer dereferences, improper authentication, resource-consumption flaws, and format-string issues that are characteristic of systems-level database implementations. Defenders should prioritize patches for this vendor given the severity profile and the elevated risk posed by database-tier exposure; live exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
3.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by PingCAP (US), Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 31, 2022
4 years ago
Most Recent CVE
Sep 3, 2024
689 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-3023CRITICAL
Use of Externally-Controlled Format String in GitHub repository pingcap/tidb prior to 6.4.0, 6.1.3.
Nov 4, 20229.830NONO
CVE-2024-41433CRITICAL
PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList. This vulnerability allows attackers to cause a Denial of Service
Sep 3, 20249.827NONO
CVE-2022-31011HIGH
TiDB is an open-source NewSQL database that supports Hybrid Transactional and Analytical Processing (HTAP) workloads. Under certain conditions, an attacker can construct malicious
May 31, 20227.825NONO
CVE-2022-34969HIGH
PingCAP TiDB v6.1.0 was discovered to contain a NULL pointer dereference.
Aug 3, 20227.524NONO
CVE-2024-35618HIGH
PingCAP TiDB v7.5.1 was discovered to contain a NULL pointer dereference via the component SortedRowContainer.
May 24, 20247.521NONO
CVE-2024-33809MEDIUM
PingCAP TiDB v7.5.1 was discovered to contain a buffer overflow vulnerability, which could lead to database crashes and denial of service attacks.
May 24, 20246.519NONO
CVE-2024-41434MEDIUM
PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a Denial of Service (DoS) via a crafted input
Sep 3, 20244.315NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
29%
43%
29%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (14.3%)
Network6 (85.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (42.9%)
High0 (0.0%)
None4 (57.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by PingCAP (US), Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by PingCAP (US), Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For PingCAP (US), Inc.'s Products

View all 3 CNAs →

Top CWEs