Redis

Vendor:

First CVE: Oct 4, 2021 · Active for 4 years

47
Total CVEs
More Total CVEs than 97% of tracked products
7.8
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 45% of tracked products
2.1%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Redis over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 4, 2021
4 years ago
Most Recent CVE
May 5, 2026
81 days ago

CVE Severity & Scoring

Redis47 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local14 (29.8%)
Network32 (68.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (2.1%)
Attack Complexity
Low40 (85.1%)
High7 (14.9%)
Unknown0 (0.0%)
User Interaction
None45 (95.7%)
Unknown0 (0.0%)
Required2 (4.3%)
Privileges Required
Low32 (68.1%)
High2 (4.3%)
None13 (27.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (47 CVEs).

47 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code exec
Feb 18, 202210.098YESYES
Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garb
Oct 3, 20259.983NONO
Redis is an in-memory database that persists on disk. In Redit 7.0 prior to 7.0.12, extracting key names from a command and a list of arguments may, in some cases, trigger a heap o
Jul 11, 20238.869NONO
Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted arguments to trigger a denial-of-
Jan 20, 20235.558NONO
Redis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson library, and result with heap corru
Jul 13, 20238.850NONO
Redis is an in-memory database that persists on disk. Authenticated users can use string matching commands (like `SCAN` or `KEYS`) with a specially crafted pattern to trigger a den
Mar 1, 20235.550NONO
Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticated users can use the MSETNX command to trigger a runtime ass
Mar 20, 20235.549NONO
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when
May 5, 20268.845NONO
Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker wit
May 5, 20268.842NONO
Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use a specially crafted string to
Jul 7, 20257.840NOYES

Exploit Exposure

Signals from CVEs in this product scope (47 CVEs).

CISA KEV
1 CVE
2.1% of CVEs· 96th percentile
Metasploit
1 CVE
2.1% of CVEs· 96th percentile
Nuclei
1 CVE
2.1% of CVEs· 96th percentile
ExploitDB
1 CVE
2.1% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (47 CVEs).

Media Mentions

Signals from CVEs in this product scope (47 CVEs).

Top CNAs Publishing CVEs For Redis

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.4.037.22.4%00
7.2.013.30.3%00
7.0.1017.51.0%00
7.036.82.1%00
2.6.013.60.4%00