NEO4J
1 CVEs tracked since 2014. Since Apr 2014, none of them reached CISA KEV.
NEO4J CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2014-04 | 1 | 0 |
Products
The products that kept showing up in NEO4J's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting NEO4J.
- CVE-2026-19869Privilege Escalation via Dropped Field-Level @authentication—
- CVE-2026-5423Subscription Authentication Bypass via Unverified connectionParams.jwt—
- CVE-2026-14587Unathenticated connection can hold Bolt channel open7.5
- CVE-2026-1471Caching of authentication context—
- CVE-2026-1524Auth misconfiguration when multiple providers enabled9.8
- CVE-2026-1497Incorrect privilege assignment in composite databases7.2
- CVE-2026-1337Insufficient escaping of unicode characters in query log5.4
- CVE-2026-1622Unredacted data exposure in query.log—
- CVE-2025-12738Enumeration of restricted property value—
- CVE-2025-11602Untargeted information leak in Bolt protocol handshake—
- CVE-2025-10193Neo4j Cypher MCP server is vulnerable to DNS rebinding attacks—
- CVE-2024-34517The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.6.5
- CVE-2023-23926APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j. An XML External Entity (XXE) vulnerability found in the apoc.import.graphml procedure of APOC core plugin prior to version 5.5.0 ...5.9
- CVE-2022-23532neo4j-apoc-procedures is vulnerable to path traversal7.1
- CVE-2022-37423Neo4j APOC (Awesome Procedures on Cypher) before 4.3.0.7 and 4.x before 4.4.0.8 allows Directory Traversal to sibling directories via apoc.log.stream.7.5
The record
- Peak rank
- #183 in Apr 2014
- Busiest month shown
- Apr 2014, 1 CVEs
- Months with a KEV entry
- 0 since Apr 2014
- Monthly snapshots
- 1 since 2014