CVE Tools

Databases

15,398 CVEs tracked since 1999. In the last 12 months, 3,012, +205% on the 12 before.

Databases by subsector, Sep 2026 so far

Sep 2026 so far: 610 CVEs across 6 subsectors. Area is each subsector's share; inside are the products it counted most. Point at one to read it.
  • Relational37662% · 6 vendors
  • NoSQL6511% · 6 vendors
  • Caches & message queues549% · 6 vendors
  • Not yet sub-classified54The tagger has not placed these yet
  • Warehouses & analytics417% · 9 vendors
  • Database tooling203% · 8 vendors

Month by month

Every monthly snapshot of Databases. A column is the CVEs published that month.

Sep 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Databases CVEs per month
MonthCVEs
2021-0929
2021-10175
2021-1129
2021-1237
2022-01214
2022-0248
2022-0358
2022-04161
2022-0532
2022-0638
2022-07118
2022-0822
2022-0920
2022-1090
2022-1135
2022-1228
2023-01115
2023-0262
2023-030
2023-04122
2023-0574
2023-0643
2023-0788
2023-0840
2023-0921
2023-10118
2023-1142
2023-1250
2024-0172
2024-0280
2024-0349
2024-04151
2024-0565
2024-0643
2024-07106
2024-0832
2024-0919
2024-10111
2024-1125
2024-1222
2025-01285
2025-0259
2025-0354
2025-04128
2025-0543
2025-0664
2025-07145
2025-0831
2025-0942
2025-10127
2025-1143
2025-1226
2026-0189
2026-0272
2026-0361
2026-04143
2026-05122
2026-06260
2026-071091
2026-08936
2026-09610

Vendors

Who shipped the most Databases CVEs in Sep 2026 so far, with their rank across all vendors.

  1. Oracle634#3
  2. Mongodb50#19
  3. Elastic42#24
  4. Mongodb Inc.14#86
  5. Rabbitmq11#112
  6. Arcadedata9#125

Weaknesses

The weakness classes behind Databases CVEs in Sep 2026 so far.

  1. CWE-284 Improper Access Control204
  2. CWE-269 Improper Privilege Mgmt89
  3. CWE-863 Incorrect Authorization27
  4. CWE-862 Missing Authorization25
  5. CWE-200 Information Exposure24
  6. CWE-125 Out-of-bounds Read22

Latest CVEs

The 15 most recently published vulnerabilities in Databases.

  1. CVE-2026-94408Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service4.9
  2. CVE-2026-94397Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service6.5
  3. CVE-2026-94396Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service6.5
  4. CVE-2026-94400Uncontrolled Resource Consumption in Kibana Leading to denial of service6.5
  5. CVE-2026-94399Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service6.5
  6. CVE-2026-94398Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service6.5
  7. CVE-2026-82300Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service6.5
  8. CVE-2026-82294Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service6.5
  9. CVE-2026-78582Missing Authorization in Kibana Leading to Unauthorized Deletion of Data6.5
  10. CVE-2026-72662Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of Data6.3
  11. CVE-2026-72668Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Privilege Escalation7.3
  12. CVE-2026-100698Adminer before 6.0.2 Privileged-Port SSRF via host_port Regex5.8
  13. CVE-2026-100697Adminer 6.0.0 Server-Side Request Forgery via ClickHouse driver8.6
  14. CVE-2026-100696Adminer before 6.0.2 Unauthenticated SSRF via Elasticsearch Driver5.8
  15. CVE-2026-100695Adminer before 6.0.2 XSS via CONNECTION_ID escalating to RCE6.1

The record

Busiest month
Jul 2026, 1,091 CVEs
Sep 2026 so far
610 CVEs from 37 vendors
Deployment
On-prem, 98%
Monthly snapshots
283 since 1999
All 15 sectors on one map

Is your business exposed to threats like these?

Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.

Request an assessment

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store