Influxdata

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 5
    Known Exploited: 0
    4
    Critical Level Threats
    0
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-30896

    InfluxDB: Privilege Escalation via Authorization Token in InfluxDB

    Last Modified: Apr 15, 2026
    Published: Nov 21, 2024

    CVE-2022-36640

    influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's documentation states "If InfluxDB is being deployed on a publicly accessible endpoint, we strongly recommend authentication be enabled. Otherwise the data will be publicly available to any unauthenticated user. The default settings do NOT enable authentication and authorization."

    Last Modified: Jul 05, 2026
    Published: Sep 02, 2022

    CVE-2020-35187

    The official telegraf docker images before 1.9.4-alpine (Alpine specific) contain a blank password for a root user. System using the telegraf docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

    Last Modified: Nov 21, 2024
    Published: Dec 17, 2020

    CVE-2019-20933

    influxdb: authentication bypass because a JWT token may have an empty SharedSecret

    Last Modified: Nov 21, 2024
    Published: Mar 27, 2019

    CVE-2018-17572

    influxdb: Reflected cross-site-scripting in the Write Data module

    Last Modified: Nov 21, 2024
    Published: Dec 08, 2015
    Items Per Page
    Influxdata Vulnerabilities & Security CVEs | CVE-DB