Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2026-63763
SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileged users (e.g., those with th…
Surrealdb
2.5.0+
HIGH 7.5
CVE-2026-63760
SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested braces, brackets, or…
Surrealdb
3.1.0+
MEDIUM 6.5
CVE-2026-63759
SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annotations. Authenticated attacke…
Surrealdb
3.1.0+
MEDIUM 6.5
CVE-2026-63762
SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded JavaScript scripting engine, which is e…
Surrealdb
2.6.1+
HIGH 8.8
CVE-2026-63757
SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns attached session UUIDs without …
Surrealdb
3.1.0+
HIGH 8.1
CVE-2026-63756
SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows unauthenticated requests to …
Surrealdb
3.1.0+
MEDIUM 6.5
CVE-2026-63754
SurrealDB versions before 3.1.0 contain a denial of service vulnerability where malicious LIVE queries with WHERE clauses that evaluate to errors cau…
Surrealdb
3.1.0+
MEDIUM 6.5
CVE-2026-63755
SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statements (and SET/MERGE/CONTENT/PATCH clauses in UPDATE, UPSERT, INSERT ON D…
Surrealdb
3.1.0+
MEDIUM 5.4
CVE-2026-63758
SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenticated database users to termi…
Surrealdb
3.1.0+
HIGH 7.5
CVE-2026-63747
SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is set without a namespace. Unau…
Surrealdb
3.1.0+
HIGH 7.5
CVE-2026-63750
SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket connections, allowing attacker…
Surrealdb
3.1.0+
MEDIUM 6.5
CVE-2026-63746
SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references. Authenticated users can read…
Surrealdb
3.1.0+
MEDIUM 5.4
CVE-2026-63745
SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof composite record-id field values by…
Surrealdb
3.1.0+
HIGH 7.7
CVE-2026-63739
SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows database users with EDITOR or O…
Surrealdb
3.1.5+
MEDIUM 6.5
CVE-2026-63740
SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users, leaking denied array elemen…
Surrealdb
3.1.4+
MEDIUM 6.5
CVE-2026-63741
SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processing USE NS and USE DB statements. Unauth…
Surrealdb
3.1.0+
MEDIUM 6.4
CVE-2026-63743
SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redirect handling that allows authenticated users to circumvent port-scoped…
Surrealdb
3.1.0+
HIGH 8.1
CVE-2026-63735
SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing authenticated users to invoke endpoints …
Surrealdb
3.2.0+
MEDIUM 6.5
CVE-2026-63737
SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server with queries containing long…
Surrealdb
3.1.5+
MEDIUM 6.5
CVE-2026-63733
SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMISSIONS clauses execute with en…
Surrealdb
3.2.0+
MEDIUM 6.5
CVE-2025-71397
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permissions (at the root, namespac…
Surrealdb
2.0.5 / 2.1.5+
MEDIUM 6.5
CVE-2025-71396
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on embedded JavaScript scripting f…
Surrealdb
2.0.5 / 2.1.5+
HIGH 8.8
CVE-2025-71390
SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames against --deny-net network access r…
Surrealdb
2.1.8 / 2.2.6+
HIGH 8.0
CVE-2025-71392
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command.…
Surrealdb
2.0.5 / 2.1.5+
MEDIUM 6.5
CVE-2024-58369
SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server p…
Surrealdb
1.1.1+
MEDIUM 6.5
CVE-2025-71391
SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated users to crash the database. …
Surrealdb
2.2.2+
MEDIUM 6.5
CVE-2025-71393
SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain embedded JavaScript that issue…
Surrealdb
2.0.5 / 2.1.5+
HIGH 8.8
CVE-2024-58362
SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without re…
Surrealdb
1.5.5+
HIGH 7.5
CVE-2024-58368
SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing special characters. Unauthenti…
Surrealdb
1.1.0+
MEDIUM 6.5
CVE-2024-58364
SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing queries with errors on line termi…
Surrealdb
1.2.1+