Solution sectors / databases
Databases
Databases, caches and message queues hold an organization's most valuable asset — its data. This hub tracks CVE trends across relational and NoSQL engines, data warehouses and queuing systems.
Cumulative CVEs
14,997
across 283 monthly snapshots
Latest month
418 · proj
-55.3% MoM · +895.2% YoY
Peak month
1,091
Jul 26
KEV this month
0
23 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem96%
- SaaS4%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Databases.
- CVE-2026-15955IBM® Data Server driver for JDBC and SQLJ could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths7.5
- CVE-2026-16702IBM® Db2® federated server could allow a remote authenticated attacker to cause a denial of service due to a null pointer dereference6.5
- CVE-2026-17047IBM Db2 Mirror for i is vulnerable to Cross-Site Request Forgery []5.4
- CVE-2026-17463IBM® Db2® could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption6.5
- CVE-2026-55837dbt-mcp: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens6.8
- CVE-2026-68570Apache Doris: Authorization bypass leading to unauthorized data access6.5
- CVE-2026-72524Apache Doris: Authorization bypass allowing a low-privilege user to read/write/drop arbitrary tables8.8
- CVE-2026-90775PostGIS address_standardizer through 3.7.0 Out-of-Bounds Read via Unvalidated Rule Weight6.5
- CVE-2026-18495Libtiff: libtiff: heap-buffer overflow via numeric truncation in the jpeg raw passthrough6.1
- CVE-2026-89099Race Condition in MongoDB Server Document Value Layer Leads to Memory Corruption7.5
- CVE-2026-86087IBM® Db2® could allow an authenticated user to send a specially crafted request to write arbitrary files on the system4.3
- CVE-2026-86093IBM® Db2® federated server could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands under certain conditions7.5
- CVE-2026-87958IBM® Db2® is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions8.1
- CVE-2026-88036GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C Driver8.3
- CVE-2026-88035Heap buffer overflow via wrapped size check during SASL username canonicalization in MongoDB C Driver4.7
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| relational | 74 | 3 | · | 4 | — | microsoft sql server 2025 for x64-based systems (gdr) (56) · microsoft sql server 2019 (cu 32) (52) · microsoft sql server 2019 (gdr) (52) |
| — | 54 | · | · | 2 | — | kibana (30) · c driver (6) · elasticsearch (4) |
| nosql | 42 | · | · | 2 | — | mongodb server (25) · c++ driver (3) · laravel mongodb (php) (3) |
| cache-message-queue | 14 | 3 | · | 4 | — | apache activemq artemis (7) · red hat ceph storage 9 (3) · valkey (2) |
| data-warehouse-analytics | 14 | 2 | · | 6 | — | apache impala (4) · impala (4) · snowflake jdbc driver (4) |
| db-tooling | 11 | 1 | · | 5 | — | red hat directory server 11.9 for rhel 8 (5) · postgresql anonymizer (3) · dbgate (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification