VYPR
Vendor

Vesoft Inc

Products
2
CVEs
4
Across products
4
Status
Private

Products

2

Recent CVEs

4
  • CVE-2026-81032CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.00

    NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all interfaces, and registers routes for reading and writing gflags alongside status…

  • CVE-2023-36088HigSep 1, 2023
    risk 0.49cvss 7.5epss 0.01

    Server Side Request Forgery (SSRF) vulnerability in NebulaGraph Studio version 3.7.0, allows remote attackers to gain sensitive information.

  • CVE-2024-47219CriSep 22, 2024
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.

  • CVE-2024-47218CriSep 22, 2024
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.