Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.9 CVE-2026-54698 Hasura is an open-source product that provides users GraphQL or REST APIs. Prior to 2.49.2 and 2.45.5, a user can use a where clause on a table compu… Graphql Engine after 2.49.2 Fix from $1,6002026-07-07 CRITICAL 9.8 CVE-2021-47748 Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell commands through SQL query manip… Graphql Engine Mitigation only Fix from $2,3002026-01-21 MEDIUM 5.3 CVE-2021-47715 Hasura GraphQL 1.3.3 contains a server-side request forgery vulnerability that allows attackers to inject arbitrary remote schema URLs through the ad… Graphql Engine No fix yet Fix from $1,6002025-12-22 HIGH 7.5 CVE-2021-47713 Hasura GraphQL 1.3.3 contains a denial of service vulnerability that allows attackers to overwhelm the service by crafting malicious GraphQL queries … Graphql Engine No fix yet Fix from $1,9502025-12-22 MEDIUM 5.5 CVE-2021-47714 Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoin… Graphql Engine No fix yet Fix from $1,6002025-12-22 HIGH 7.5 CVE-2023-27588 Hasura is an open-source product that provides users GraphQL or REST APIs. A path traversal vulnerability has been discovered within Hasura GraphQL E… Graphql Engine 1.3.4 / 2.11.5+ Fix from $1,9502023-03-14 HIGH 8.8 CVE-2022-46792 Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres backends. The fixed versions are 2.10.2, 2… Graphql Engine 2.10.2 / 2.11.3+ Fix from $1,9502022-12-08 HIGH 7.5 CVE-2019-1020015 graphql-engine (aka Hasura GraphQL Engine) before 1.0.0-beta.3 mishandles the audience check while verifying JWT. Graphql Engine 1.0.0+ Fix from $1,9502019-07-29