Vesoft's vulnerability footprint centers on NebulaGraph, its distributed graph database and associated studio interface, with recurring exposure patterns in authentication handling, code injection, and server-side request forgery. These weaknesses reflect the complexity of distributed database access control and query-execution surfaces. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vesoft over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-47218CRITICAL An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication. | Sep 22, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-47219CRITICAL An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection. | Sep 22, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-36088HIGH Server Side Request Forgery (SSRF) vulnerability in NebulaGraph Studio version 3.7.0, allows remote attackers to gain sensitive information. | Sep 1, 2023 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vesoft.
Media articles that mention a CVE ID that affects a product developed by Vesoft — matched by CVE ID, not by vendor name.