Vulnerability index

Browse CVEs

38 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2024-58365 SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls to nonexistent built-in funct… Surrealdb 1.2.0+ Fix from $1,6002026-07-18 MEDIUM 6.5 CVE-2024-58367 SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations, allowing authorized users to… Surrealdb 2.0.4+ Fix from $1,6002026-07-18 MEDIUM 6.3 CVE-2024-58363 SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clause or use method. Attackers w… Surrealdb 1.5.4+ Fix from $1,6002026-07-18 MEDIUM 6.5 CVE-2024-58357 SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics when unwrap is called on a None … Surrealdb 2.1.0+ Fix from $1,6002026-07-18 MEDIUM 6.5 CVE-2024-58359 SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY rand() clause. Authorized clie… Surrealdb 2.1.0+ Fix from $1,6002026-07-18 MEDIUM 6.5 CVE-2024-58361 SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code when processing empty strings… Surrealdb 2.0.4+ Fix from $1,6002026-07-18 MEDIUM 6.3 CVE-2024-58356 SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ... OVERWRITE clause is used on tables defined with TYPE R… Surrealdb 2.1.4+ Fix from $1,6002026-07-18 HIGH 8.8 CVE-2023-54366 SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELETE operations on tables witho… Surrealdb 1.0.1+ Fix from $1,9502026-07-18