yugabyte
Security Risk Profile
36
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 19 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from August 5, 2019 to present
19
Total CVEs
10
Critical+High
0
Exploited
6
Unpatched
Threat Assessment
Avg CVSS
6.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
6
Critical/High
Risk Level
36/100
low
Severity Distribution
Critical
4High
6Medium
8Low
1Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
8Age Distribution
Common Weaknesses (CWE)
1
Infoleak
3
2
Null Pointer Dereference
1
3
Buffer Overflow
1
4
XSS
1
5
Code Injection
1
Most Affected Products
1. Yugabyte YugabyteDB12
2. Yugabyte YugabyteDB Anywhere4
3. Yugabyte Yugabyte Platform3
4. Pivotal Application Service3
5. Pivotal Single Sign-on Cloud Foundry3
Recent Vulnerabilities
See more →CVE-2026-1966
CVSS 2.4low
YugabyteDB Anywhere Exposes LDAP Credentials in Cleartext in Web UI
2/5/2026🔧 No Patch
CVE-2025-8866
CVSS 5.1EPSS 0%medium
8/11/2025🔧 No Patch
CVE-2025-8865
CVSS 4.1EPSS 0%medium
8/11/2025🔧 No Patch
CVE-2025-8863
CVSS 7.0EPSS 0%high
8/11/2025🔧 No Patch
CVE-2025-8862
CVSS 7.0EPSS 0%high
8/11/2025🔧 No Patch
CVE-2024-11193
CVSS 6.5medium
11/13/2024🔧 No Patch
CVE-2024-11165
CVSS 5.7medium
11/13/2024🔧 No Patch
CVE-2024-41435
CVSS 7.5high
9/3/2024🔧 No Patch
CVE-2024-6908
CVSS 6.0EPSS 0%medium
Admin Can Escalate Privileges to SuperAdmin Using Manual PUT Request
7/19/2024🔧 No Patch
CVE-2024-6895
CVSS 6.1EPSS 0%medium
Insecure Account Profile Management
7/19/2024🔧 No Patch
Monitor yugabyte in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.