Solution sectors / databases
Databases
Databases, caches and message queues hold an organization's most valuable asset — its data. This hub tracks CVE trends across relational and NoSQL engines, data warehouses and queuing systems.
Cumulative CVEs
13,889
across 282 monthly snapshots
Latest month
96 · proj
-91.2% MoM · +209.7% YoY
Peak month
1,091
Jul 26
KEV this month
0
9 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem100%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Databases.
- CVE-2026-18663389-ds-base: 389-ds-base: pre-authentication double-free in get_ldapmessage_controls_ext() via critical session tracking control5.9
- CVE-2026-19594Path Traversal and HTTP Parameter Pollution in Snowflake Python API (snowflake.core) Allow Confused-Deputy Privilege Escalation8.1
- CVE-2026-18710Cleartext Storage of Sensitive Information in MongoDB Driver Logging During Client Initialization6.5
- CVE-2026-18712Improper Authorization in MongoDB Queryable Encryption Maintenance Operations Allows Unauthorized Modification of Other Collections8.1
- CVE-2026-18711Use-After-Free in MongoDB Query Execution Engine Leads to Denial of Service and Potential Memory Disclosure7.1
- CVE-2026-18709Missing Authorization in MongoDB Sharded Transaction Commit/Abort Handling Leads to Cross-Shard Data Inconsistency6.4
- CVE-2026-18698Improper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections via the validate Command5.4
- CVE-2026-18690Improper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections8.1
- CVE-2026-18699Improper Input Validation in MongoDB Query Planner Leads to Denial of Service6.5
- CVE-2026-18691Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure8.8
- CVE-2026-18702Improper Authorization in MongoDB profile Command Allows Unauthorized Modification of Server-Wide Diagnostic Settings6.4
- CVE-2026-18694Out-of-Bounds Read in MongoDB Geospatial Query Processing Leads to Denial of Service and Potential Memory Disclosure7.1
- CVE-2026-18708Improper Neutralization of Input in MongoDB Server's JavaScript Scripting Engine Leads to Unauthorized Code Execution Within Query Scopes6.4
- CVE-2026-18696Improper Authorization in MongoDB applyOps Command Handling Allows Unauthorized DDL Operations on Collections6.5
- CVE-2026-18700Use-After-Free in MongoDB Geospatial Validation Leads to Denial of Service6.5
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| arcadedata | 8 | 3 | · |
| timescale | 3 | · | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| cache-message-queue | 21 | 2 | · | 3 | — | red hat data grid 8 (11) · qpid broker-j (7) · apache fory (3) |
| nosql | 9 | 3 | · | 2 | — | arcadedb (8) · dgraph (1) |
| relational | 7 | · | · | 4 | — | timescaledb (3) · community edition (1) · duckdb-aws (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification