Arcadedata
34 CVEs tracked since 2026. Since Aug 2026, none of them reached CISA KEV.
Arcadedata CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2026-08 | 25 | 0 |
| 2026-09 | 9 | 0 |
Products
The products that kept showing up in Arcadedata's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Arcadedata.
- CVE-2026-93598ArcadeDB before 26.9.1 Classpath Credential Disclosure via ResourceBundle—
- CVE-2026-93597ArcadeDB before 26.9.1 SSRF via IPv6 transition addresses7.7
- CVE-2026-93596ArcadeDB before 26.9.1 Authorization Bypass via Batch Edge Connect4.3
- CVE-2026-93595ArcadeDB before 26.9.1 ACL Bypass via query_database Tool6.5
- CVE-2026-93594ArcadeDB before 26.9.1 ACL Bypass via Index and TimeSeries8.1
- CVE-2026-93593ArcadeDB before 26.9.1 TimeSeries ACL Bypass via Type Permission8.1
- CVE-2026-65831ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read7.7
- CVE-2026-54077ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users7.1
- CVE-2026-54076ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221)8.1
- CVE-2026-76224ArcadeDB before 26.8.1 Remote Code Execution via Groovy Fallback8.8
- CVE-2026-76225ArcadeDB before 26.8.1 Server-Side Request Forgery via LOAD CSV7.7
- CVE-2026-76223ArcadeDB before 26.8.1 Permission Bypass via DEFINE FUNCTION7.1
- CVE-2026-75855ArcadeDB before 26.8.1 Path Traversal via create/drop database8.7
- CVE-2026-75854ArcadeDB Redis Wire-Protocol Plugin Missing Authentication9.8
- CVE-2026-75853ArcadeDB Gremlin Wire Protocol Authorization Bypass Cross-Database8.8
The record
- Peak rank
- #55 in Aug 2026
- Busiest month shown
- Aug 2026, 25 CVEs
- Months with a KEV entry
- 0 since Aug 2026
- Monthly snapshots
- 2 since 2026