LIVE · cybersecurity feed
Live wire
vendor

Surrealdb

13 CVEs published in the last four months. Exploited flaws first.

Critical0
High13
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2023-543668.8highsurrealdbSurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, an49d ago
CVE-2024-583628.8highsurrealdbSurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup o49d ago
CVE-2025-713908.8highsurrealdbSurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames 49d ago
CVE-2026-637578.8highsurrealdbSurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method retu48d ago
CVE-2026-637638.8highsurrealdbSurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability.48d ago
CVE-2026-637568.1highsurrealdbSurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that 48d ago
CVE-2026-637358.1highsurrealdbSurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing authe48d ago
CVE-2025-713928highsurrealdbSurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names 49d ago
CVE-2026-637397.7highsurrealdbSurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that all48d ago
CVE-2025-713987.6highsurrealdbSurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass 49d ago
CVE-2024-583687.5highsurrealdbSurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests contai49d ago
CVE-2026-637607.5highsurrealdbSurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when pro48d ago
CVE-2026-637477.5highsurrealdbSurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when 48d ago

Filter the full tracker by Surrealdb