CVE Vulnerability Database

Search and browse 389,918 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-16123MEDIUM6.3A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is the function ToolsInvo...
CVE-2026-16122MEDIUM4.3A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the funct...
CVE-2026-16121MEDIUM6.3A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2. Affected is the function isSafeBin of the file i...
CVE-2026-9323CRITICAL9.2The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by c...
CVE-2026-16120MEDIUM6.3A vulnerability was determined in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This impacts the function matchesAllowlis...
CVE-2026-16119MEDIUM6.3A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2. This affects the function RequestApproval of the file...
CVE-2026-16117CRITICAL10Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segme...
CVE-2026-11826HIGH8.8OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_master.cpp. getData(...
CVE-2025-71398HIGH7.6SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-n...
CVE-2025-71397MEDIUM6.5SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permi...
CVE-2025-71396MEDIUM6.5SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on em...
CVE-2025-71395MEDIUM6.5SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to ...
CVE-2025-71394MEDIUM4.3SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows aut...
CVE-2025-71393MEDIUM6.5SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain e...
CVE-2025-71392HIGH8SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the...
CVE-2025-71391MEDIUM6.5SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated ...
CVE-2025-71390HIGH8.8SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames agains...
CVE-2024-58370MEDIUM6.5SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements includin...
CVE-2024-58369HIGH7.1SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or names...
CVE-2024-58368HIGH8.7SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing s...
CVE-2024-58367MEDIUM6.5SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations,...
CVE-2024-58366HIGH8.8SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when script...
CVE-2024-58365HIGH7.1SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls ...
CVE-2024-58364HIGH7.1SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing quer...
CVE-2024-58363MEDIUM6.3SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clau...