Databases
15,398 CVEs tracked since 1999. In the last 12 months, 3,012, +205% on the 12 before.
Databases by subsector, Sep 2026 so far
- Relational37662% · 6 vendors
- NoSQL6511% · 6 vendors
- Caches & message queues549% · 6 vendors
- Not yet sub-classified54The tagger has not placed these yet
- Warehouses & analytics417% · 9 vendors
- Database tooling203% · 8 vendors
Month by month
Every monthly snapshot of Databases. A column is the CVEs published that month.
| Month | CVEs |
|---|---|
| 2021-09 | 29 |
| 2021-10 | 175 |
| 2021-11 | 29 |
| 2021-12 | 37 |
| 2022-01 | 214 |
| 2022-02 | 48 |
| 2022-03 | 58 |
| 2022-04 | 161 |
| 2022-05 | 32 |
| 2022-06 | 38 |
| 2022-07 | 118 |
| 2022-08 | 22 |
| 2022-09 | 20 |
| 2022-10 | 90 |
| 2022-11 | 35 |
| 2022-12 | 28 |
| 2023-01 | 115 |
| 2023-02 | 62 |
| 2023-03 | 0 |
| 2023-04 | 122 |
| 2023-05 | 74 |
| 2023-06 | 43 |
| 2023-07 | 88 |
| 2023-08 | 40 |
| 2023-09 | 21 |
| 2023-10 | 118 |
| 2023-11 | 42 |
| 2023-12 | 50 |
| 2024-01 | 72 |
| 2024-02 | 80 |
| 2024-03 | 49 |
| 2024-04 | 151 |
| 2024-05 | 65 |
| 2024-06 | 43 |
| 2024-07 | 106 |
| 2024-08 | 32 |
| 2024-09 | 19 |
| 2024-10 | 111 |
| 2024-11 | 25 |
| 2024-12 | 22 |
| 2025-01 | 285 |
| 2025-02 | 59 |
| 2025-03 | 54 |
| 2025-04 | 128 |
| 2025-05 | 43 |
| 2025-06 | 64 |
| 2025-07 | 145 |
| 2025-08 | 31 |
| 2025-09 | 42 |
| 2025-10 | 127 |
| 2025-11 | 43 |
| 2025-12 | 26 |
| 2026-01 | 89 |
| 2026-02 | 72 |
| 2026-03 | 61 |
| 2026-04 | 143 |
| 2026-05 | 122 |
| 2026-06 | 260 |
| 2026-07 | 1091 |
| 2026-08 | 936 |
| 2026-09 | 610 |
Vendors
Who shipped the most Databases CVEs in Sep 2026 so far, with their rank across all vendors.
Weaknesses
The weakness classes behind Databases CVEs in Sep 2026 so far.
Latest CVEs
The 15 most recently published vulnerabilities in Databases.
- CVE-2026-94408Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service4.9
- CVE-2026-94397Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service6.5
- CVE-2026-94396Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service6.5
- CVE-2026-94400Uncontrolled Resource Consumption in Kibana Leading to denial of service6.5
- CVE-2026-94399Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service6.5
- CVE-2026-94398Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service6.5
- CVE-2026-82300Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service6.5
- CVE-2026-82294Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service6.5
- CVE-2026-78582Missing Authorization in Kibana Leading to Unauthorized Deletion of Data6.5
- CVE-2026-72662Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of Data6.3
- CVE-2026-72668Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Privilege Escalation7.3
- CVE-2026-100698Adminer before 6.0.2 Privileged-Port SSRF via host_port Regex5.8
- CVE-2026-100697Adminer 6.0.0 Server-Side Request Forgery via ClickHouse driver8.6
- CVE-2026-100696Adminer before 6.0.2 Unauthenticated SSRF via Elasticsearch Driver5.8
- CVE-2026-100695Adminer before 6.0.2 XSS via CONNECTION_ID escalating to RCE6.1
The record
- Busiest month
- Jul 2026, 1,091 CVEs
- Sep 2026 so far
- 610 CVEs from 37 vendors
- Deployment
- On-prem, 98%
- Monthly snapshots
- 283 since 1999
Is your business exposed to threats like these?
Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.
Request an assessment