Vulnerability index

Browse CVEs

38 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Surrealdb MEDIUM 6.5
CVE-2024-58365

SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls to nonexistent built-in funct…

Fix: 1.2.0+
Fix from $1,600 2026-07-18
Surrealdb MEDIUM 6.5
CVE-2024-58367

SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations, allowing authorized users to…

Fix: 2.0.4+
Fix from $1,600 2026-07-18
Surrealdb MEDIUM 6.3
CVE-2024-58363

SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clause or use method. Attackers w…

Fix: 1.5.4+
Fix from $1,600 2026-07-18
Surrealdb MEDIUM 6.5
CVE-2024-58357

SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics when unwrap is called on a None …

Fix: 2.1.0+
Fix from $1,600 2026-07-18
Surrealdb MEDIUM 6.5
CVE-2024-58359

SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY rand() clause. Authorized clie…

Fix: 2.1.0+
Fix from $1,600 2026-07-18
Surrealdb MEDIUM 6.5
CVE-2024-58361

SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code when processing empty strings…

Fix: 2.0.4+
Fix from $1,600 2026-07-18
Surrealdb MEDIUM 6.3
CVE-2024-58356

SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ... OVERWRITE clause is used on tables defined with TYPE R…

Fix: 2.1.4+
Fix from $1,600 2026-07-18
Surrealdb HIGH 8.8
CVE-2023-54366

SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELETE operations on tables witho…

Fix: 1.0.1+
Fix from $1,950 2026-07-18