CVE Vulnerability Database
Search and browse 389,905 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63749 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions where permis... |
| CVE-2026-63748 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE ac... |
| CVE-2026-63747 | HIGH | 8.7 | 0.4% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is ... |
| CVE-2026-63746 | HIGH | 7.1 | 0.3% | Jul 20, 2026 | SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references.... |
| CVE-2026-63745 | MEDIUM | 5.4 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof compos... |
| CVE-2026-63744 | MEDIUM | 5.1 | 0.2% | Jul 20, 2026 | SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redire... |
| CVE-2026-63743 | MEDIUM | 6.4 | 0.2% | Jul 20, 2026 | SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redirect handling that allows authenticated us... |
| CVE-2026-63742 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain a field-level SELECT permission bypass vulnerability in indexed COUNT fast paths... |
| CVE-2026-63741 | MEDIUM | 6.9 | 0.3% | Jul 20, 2026 | SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processing USE NS ... |
| CVE-2026-63740 | HIGH | 7.1 | 0.3% | Jul 20, 2026 | SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users... |
| CVE-2026-63739 | HIGH | 8.3 | 0.3% | Jul 20, 2026 | SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows da... |
| CVE-2026-63738 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB versions 3.1.0 before 3.1.5 fail to enforce field-level SELECT permissions when records are accessed through g... |
| CVE-2026-63737 | HIGH | 7.1 | 0.3% | Jul 20, 2026 | SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server... |
| CVE-2026-63736 | MEDIUM | 5.1 | 0.2% | Jul 20, 2026 | SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in the JWKS fetcher that validates only the ... |
| CVE-2026-63735 | HIGH | 8.6 | 0.3% | Jul 20, 2026 | SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing authenticat... |
| CVE-2026-63734 | MEDIUM | 6.9 | 0.3% | Jul 20, 2026 | SurrealDB versions before 3.2.0 contain a denial of service vulnerability in the SurrealML header parser that allows aut... |
| CVE-2026-63733 | MEDIUM | 6.5 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMIS... |
| CVE-2026-16254 | MEDIUM | 4.3 | — | Jul 20, 2026 | A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can cause an o... |
| CVE-2026-16247 | HIGH | 7.3 | 0.1% | Jul 20, 2026 | In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this proces... |
| CVE-2026-16246 | HIGH | 7.3 | 0.1% | Jul 20, 2026 | In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows g... |
| CVE-2026-15813 | MEDIUM | 6.5 | 0.3% | Jul 20, 2026 | A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The int... |
| CVE-2026-15588 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` a... |
| CVE-2026-14448 | HIGH | 8.6 | 0.8% | Jul 20, 2026 | An high privileged remote attacker can exploit an authenticated OS command injection vulnerability in the system_certifi... |
| CVE-2026-2445 | MEDIUM | 6.1 | 0.1% | Jul 20, 2026 | The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encod... |
| CVE-2026-16242 | CRITICAL | 9.4 | 0.8% | Jul 20, 2026 | A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was... |
