Solution sectors / databases
Databases
Databases, caches and message queues hold an organization's most valuable asset — its data. This hub tracks CVE trends across relational and NoSQL engines, data warehouses and queuing systems.
Cumulative CVEs
12,861
across 281 monthly snapshots
Latest month
115 · proj
-55.8% MoM · -20.7% YoY
Peak month
285
Jan 25
KEV this month
0
25 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem88%
- SaaS12%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Databases.
- CVE-2026-66373Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by ...7.5
- CVE-2026-49326Apache HBase: Missing scanner instance owner check in thrift delegation service6.5
- CVE-2026-17059Keycloak-services: keycloak-services: information disclosure via role-users endpoint bypasses per-user view filter6.5
- CVE-2026-17048Keycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via admin rest api5.5
- CVE-2026-16870Multiple Security Vulnerabilities in Snowflake libsnowflakeclient8.8
- CVE-2026-47668DbGate: Unauthenticated Remote Code Execution via JSON Script Runner10.0
- CVE-2026-60455Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2...8.8
- CVE-2026-60439Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2...8.8
- CVE-2026-61246Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2...8.8
- CVE-2026-60371Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2...8.0
- CVE-2026-60373Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2...8.8
- CVE-2026-60372Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2...9.8
- CVE-2026-60369Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2...9.9
- CVE-2026-60370Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2...7.5
- CVE-2026-60368Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2...8.8
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| cache-message-queue | 35 | · | · | 3 | — | nats-server (12) · red hat data grid 8 (12) · rabbitmq-server (11) |
| — | 19 | 5 | · | 2 | — | apache iotdb (10) · kibana (4) · elasticsearch (3) |
| nosql | 16 | 4 | · | 7 | — | tdengine (6) · iotdb (3) · dgraph (2) |
| relational | 14 | 1 | · | 4 | — | microsoft sql server 2025 for x64-based systems (gdr) (7) · microsoft sql server 2016 service pack 3 (gdr) (4) · microsoft sql server 2016 service pack 3 azure connect feature pack (4) |
| data-warehouse-analytics | 11 | 5 | · | 4 | — | apache kylin (3) · dbt-mcp (3) · kylin (3) |
| db-tooling | 5 | · | · | 5 | — | postgresql jdbc driver (1) · queryweaver (1) · red hat directory server 11.9 for rhel 8 (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification