CVE Vulnerability Database

Search and browse 389,905 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-63749MEDIUM5.3SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions where permis...
CVE-2026-63748MEDIUM5.3SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE ac...
CVE-2026-63747HIGH8.7SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is ...
CVE-2026-63746HIGH7.1SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references....
CVE-2026-63745MEDIUM5.4SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof compos...
CVE-2026-63744MEDIUM5.1SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redire...
CVE-2026-63743MEDIUM6.4SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redirect handling that allows authenticated us...
CVE-2026-63742MEDIUM5.3SurrealDB versions before 3.1.0 contain a field-level SELECT permission bypass vulnerability in indexed COUNT fast paths...
CVE-2026-63741MEDIUM6.9SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processing USE NS ...
CVE-2026-63740HIGH7.1SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users...
CVE-2026-63739HIGH8.3SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows da...
CVE-2026-63738MEDIUM5.3SurrealDB versions 3.1.0 before 3.1.5 fail to enforce field-level SELECT permissions when records are accessed through g...
CVE-2026-63737HIGH7.1SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server...
CVE-2026-63736MEDIUM5.1SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in the JWKS fetcher that validates only the ...
CVE-2026-63735HIGH8.6SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing authenticat...
CVE-2026-63734MEDIUM6.9SurrealDB versions before 3.2.0 contain a denial of service vulnerability in the SurrealML header parser that allows aut...
CVE-2026-63733MEDIUM6.5SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMIS...
CVE-2026-16254MEDIUM4.3A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can cause an o...
CVE-2026-16247HIGH7.3In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this proces...
CVE-2026-16246HIGH7.3In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows g...
CVE-2026-15813MEDIUM6.5A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The int...
CVE-2026-15588MEDIUM5.3A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` a...
CVE-2026-14448HIGH8.6An high privileged remote attacker can exploit an authenticated OS command injection vulnerability in the system_certifi...
CVE-2026-2445MEDIUM6.1The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encod...
CVE-2026-16242CRITICAL9.4A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was...