Exposição de Redis

Databases
76
score de exposição
58.175
sites usam
1
em exploração
2
críticos
Análise Vexday

Redis apresenta uma taxa de exploração ativa 4,0 vezes acima da média geral do catálogo CISA KEV, o que, dado o volume total de 56 CVEs catalogadas, indica uma proporção de risco elevada em relação ao tamanho do portfólio de vulnerabilidades. A CVE mais crítica em exploração ativa é a CVE-2022-0543, com score EPSS de 0,9967 — valor próximo ao máximo possível, sinalizando probabilidade altíssima de exploração em ambientes reais. O tipo de falha mais recorrente é CWE-190 (Integer Overflow), que merece atenção em processos de hardening e validação de entradas, especialmente em instâncias expostas em rede. O surgimento de 3 novas CVEs nos últimos 90 dias reforça a necessidade de monitoramento contínuo e aplicação ágil de patches em implantações Redis.

CVEs

57 resultados
CVE-2021-32687HIGHInteger overflow issue with intsets in RedisEPSS 4.1%CVE-2021-29477HIGHVulnerability in the STRALGO LCS commandEPSS 4.0%CVE-2025-32023HIGHRedis allows out of bounds writes in hyperloglog commands leading to RCEEPSS 4.0%CVE-2021-32627HIGHInteger overflow issue with Streams in RedisEPSS 4.0%CVE-2025-46817HIGHLua library commands may lead to integer overflow and potential RCEEPSS 3.7%CVE-2021-41099HIGHInteger overflow issue with strings in RedisEPSS 3.7%CVE-2021-29478HIGHVulnerability in the COPY command for large intsetsEPSS 3.6%CVE-2026-25243HIGHredis-server RESTORE invalid memory access may allow remote code executionEPSS 3.3%CVE-2022-31144HIGHPotential heap overflow in Redis EPSS 3.2%CVE-2022-35951HIGHRedis subject to Integer Overflow leading to Remote Code Execution via Heap OverflowEPSS 3.0%CVE-2026-23631MEDIUMredis-server Lua use-after-free may allow remote code executionEPSS 2.8%CVE-2021-32762HIGHInteger overflow that can lead to heap overflow in redis-cli, redis-sentinel on some platformsEPSS 2.7%CVE-2023-41056HIGHRedis vulnerable to integer overflow in certain payloadsEPSS 2.6%CVE-2022-24735LOWLua scripts can be manipulated to overcome ACL rules in RedisEPSS 2.3%CVE-2021-32672MEDIUMVulnerability in Lua Debugger in RedisEPSS 1.8%CVE-2022-24736LOWA Malformed Lua script can crash RedisEPSS 1.5%CVE-2026-23479HIGHredis-server use-after-free in unblock client flow may allow remote code executionEPSS 1.3%CVE-2021-3470A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jemEPSS 1.1%CVE-2025-46819MEDIUMRedis is vulnerable to DoS via specially crafted LUA scriptsEPSS 1.0%CVE-2024-31228MEDIUMDenial-of-service due to unbounded pattern matching in RedisEPSS 1.0%