Exposição de Redis

Databases
76
score de exposição
58.175
sites usam
1
em exploração
2
críticos
Análise Vexday

Redis apresenta uma taxa de exploração ativa 4,0 vezes acima da média geral do catálogo CISA KEV, o que, dado o volume total de 56 CVEs catalogadas, indica uma proporção de risco elevada em relação ao tamanho do portfólio de vulnerabilidades. A CVE mais crítica em exploração ativa é a CVE-2022-0543, com score EPSS de 0,9967 — valor próximo ao máximo possível, sinalizando probabilidade altíssima de exploração em ambientes reais. O tipo de falha mais recorrente é CWE-190 (Integer Overflow), que merece atenção em processos de hardening e validação de entradas, especialmente em instâncias expostas em rede. O surgimento de 3 novas CVEs nos últimos 90 dias reforça a necessidade de monitoramento contínuo e aplicação ágil de patches em implantações Redis.

CVEs

57 resultados
CVE-2022-0543CRITICALIt was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escapeEPSS 99.3%KEVCVE-2025-49844CRITICALRedis Lua Use-After-Free may lead to remote code executionEPSS 86.8%CVE-2023-36824HIGHHeap overflow in COMMAND GETKEYS and ACL evaluation in RedisEPSS 77.4%CVE-2023-22458MEDIUMInteger overflow in multiple Redis commands can lead to denial-of-serviceEPSS 72.0%CVE-2022-36021MEDIUMRedis string pattern matching can be abused to achieve Denial of ServiceEPSS 59.7%CVE-2023-28425MEDIUMSpecially crafted MSETNX command can lead to denial-of-serviceEPSS 55.0%CVE-2022-24834HIGHHeap overflow issue with the Lua cjson library used by RedisEPSS 41.4%CVE-2022-35977MEDIUMInteger overflow in certain command arguments can drive Redis to OOM panicEPSS 37.3%CVE-2021-32761HIGHInteger overflow issues with *BIT commands on 32-bit systemsEPSS 31.0%CVE-2019-10192HIGHA heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.xEPSS 26.0%CVE-2019-10193HIGHA stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.EPSS 23.7%CVE-2021-32675HIGHDoS vulnerability in RedisEPSS 16.9%CVE-2021-32626HIGHLua scripts can overflow the heap-based Lua stack in RedisEPSS 16.2%CVE-2016-8339MEDIUMA buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent. An out of bounds write vulneEPSS 14.8%CVE-2021-32628HIGHVulnerability in handling large ziplistsEPSS 13.5%CVE-2024-46981HIGHRedis' Lua library commands may lead to remote code executionEPSS 8.2%CVE-2025-62507HIGHRedis: Bug in XACKDEL may lead to stack overflow and potential RCEEPSS 6.8%CVE-2021-21309MEDIUMInteger overflow on 32-bit systemsEPSS 4.7%CVE-2024-31449HIGHLua library commands may lead to stack overflow and RCE in RedisEPSS 4.5%CVE-2021-32625HIGHRedis vulnerability in STRALGO LCS on 32-bit systemsEPSS 4.2%