Search
9,841 CVEs
CVEs (9,841, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 9,841 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71398 | NONE | Patched | — | 2026-07-18 | SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-net restrictions by redirecting to blocked IP address… |
| CVE-2025-71390 | NONE | Patched | — | 2026-07-18 | SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames against --deny-net network access restrictions in its http… |
| CVE-2025-71391 | NONE | Patched | — | 2026-07-18 | SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated users to crash the database. Attackers can send craf… |
| CVE-2025-71392 | NONE | Patched | — | 2026-07-18 | SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command. An authenticated Syste… |
| CVE-2025-71393 | NONE | Patched | — | 2026-07-18 | SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain embedded JavaScript that issues new queries. Authenti… |
| CVE-2025-71394 | NONE | Patched | — | 2026-07-18 | SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows authenticated users to read arbitrary files on the file… |
| CVE-2025-71395 | NONE | Patched | — | 2026-07-18 | SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to restrict resulting string length when using regex pa… |
| CVE-2024-58367 | NONE | Patched | — | 2026-07-18 | SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations, allowing authorized users to access unauthorized fi… |
| CVE-2024-58356 | NONE | Patched | — | 2026-07-18 | SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ... OVERWRITE clause is used on tables defined with TYPE RELATION. Because table … |
| CVE-2026-44979 | NONE | Patched | — | 2026-07-17 | @hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a different hostname, only the Authorization and Cookie headers are strip… |
| CVE-2026-54466 | NONE | Patched | — | 2026-07-17 | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length header t… |
| CVE-2026-54490 | NONE | Patched | — | 2026-07-17 | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, if this library is used with the permessage-deflate extension, a WebSocket server or cl… |
| CVE-2026-53727 | NONE | Patched | — | 2026-07-17 | css_parser is a Ruby CSS parser. From 2.2.0 until 3.0.0, CssParser::Parser#read_remote_file in lib/css_parser/parser.rb, and therefore load_uri! and the @import-following b… |
| CVE-2026-45784 | NONE | Patched | — | 2026-07-17 | rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incor… |
| CVE-2026-54463 | NONE | Patched | — | 2026-07-17 | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket protocol in websocket-driver include a length header th… |
| CVE-2026-54464 | NONE | Patched | — | 2026-07-17 | ### Impact If this library is used in tandem with the `permessage-deflate` extension, a WebSocket server or client can be made to accept messages that are larger than the … |
| CVE-2026-54465 | NONE | Patched | — | 2026-07-17 | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to implement a WebSocket server on top of a TCP server us… |
| CVE-2026-50197 | NONE | Patched | — | 2026-07-17 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.10, zalando/skipper's OpenPolicyAgent integration silently bypasses request-body inspecti… |
| CVE-2026-50289 | NONE | Patched | — | 2026-07-17 | systeminformation is a System and OS information library for node.js. Prior to 5.31.7, networkInterfaces() on Linux is vulnerable to OS command injection through the Debian… |
| CVE-2026-49852 | NONE | Patched | — | 2026-07-17 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to 1.6.8, joserfc.jwt.decode accepts attac… |
| CVE-2026-50162 | NONE | Patched | — | 2026-07-17 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, resolveWritePath() in content/file/file.go uses a lexical filepath.Rel check for workingDir and does not… |
| CVE-2026-48978 | NONE | Patched | — | 2026-07-17 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validatin… |
| CVE-2026-45704 | NONE | Patched | — | 2026-07-17 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses inconsistent authorization between the report listing… |
| CVE-2026-43636 | NONE | — | 2026-07-17 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-44974 | NONE | Patched | — | 2026-07-17 | @hapi/content provided HTTP Content-* headers parsing. Prior to 6.0.2, Content.disposition() retained the last occurrence of each duplicate parameter while Content.type() r… |