Iotdb
This hub aggregates every CVE we track for Iotdb, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
20
CVEs tracked
9
Critical
10
High
0
In CISA KEV
Severity distribution
HIGH10CRITICAL9MEDIUM1
Monthly trend
0
0
0
0
0
0
0
0
3
0
0
0
2
0
0
0
0
0
2
0
0
0
3
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Iotdb.
- CVE-2026-24013Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC9.1
- CVE-2026-24012Apache IoTDB: Denial of Service via Resource Exhaustion in Aggregation Query7.5
- CVE-2026-24014Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write9.8
- CVE-2026-24713Apache IoTDB: JEXL Expression Injection Vulnerability9.8
- CVE-2026-24015Apache IoTDB: Insecure Default Configuration Vulnerability9.8
- CVE-2025-48392Apache IoTDB: DoS Vulnerability7.5
- CVE-2025-48459Apache IoTDB: Deserialization of untrusted Data5.3
- CVE-2025-26864Apache IoTDB: Exposure of Sensitive Information in IoTDB OpenID Authentication7.5
- CVE-2025-26795Apache IoTDB JDBC driver: Exposure of Sensitive Information in IoTDB JDBC driver7.5
- CVE-2024-24780Apache IoTDB: Remote Code Execution with untrusted URI of User-defined function9.8
- CVE-2023-46226Apache IoTDB: Remote Code Execution (RCE) risk via the UDF9.8
- CVE-2023-51656Apache IoTDB: Unsafe deserialize map in Sync Tool9.8
- CVE-2023-24831Apache IoTDB grafana-connector Login Bypass Vulnerability9.8
- CVE-2023-24829Apache IoTDB Workbench: apache/iotdb-web-workbench: forge the JWTToken to access workbench8.8
- CVE-2023-24830Apache IoTDB Workbench: apache/iotdb-web-workbench: create a user without authorization7.5
Product normalization is registry-driven with AI assist and human review. How it works