Ververica develops the Ververica Platform, a stream processing and data pipeline management system, with the durable signal centered on application-layer web vulnerabilities including direct-request access control bypass and cross-site scripting. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ververica over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-46690HIGH Ververica Platform 2.14.0 allows low-privileged users to access SQL connectors via a direct namespaces/default/formats request. | Apr 27, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-46689MEDIUM Ververica Platform 2.14.0 contain an Reflected XSS vulnerability via a namespaces/default/formats URI. | Apr 27, 2025 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ververica.
Media articles that mention a CVE ID that affects a product developed by Ververica — matched by CVE ID, not by vendor name.