Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

80 CVEs · published 2026-07-18 to 2026-07-18

CVEs (80)

Showing 1–25 of 80

CVE ID Severity Patch CVSS Published Description
CVE-2025-71396 NONE Patched — 2026-07-18 SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on embedded JavaScript scripting functions when the scrip…
CVE-2025-71397 NONE Patched — 2026-07-18 SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permissions (at the root, namespace, or database level) t…
CVE-2025-71398 NONE Patched — 2026-07-18 SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-net restrictions by redirecting to blocked IP address…
CVE-2025-71390 NONE Patched — 2026-07-18 SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames against --deny-net network access restrictions in its http…
CVE-2025-71391 NONE Patched — 2026-07-18 SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated users to crash the database. Attackers can send craf…
CVE-2025-71392 NONE Patched — 2026-07-18 SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command. An authenticated Syste…
CVE-2025-71393 NONE Patched — 2026-07-18 SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain embedded JavaScript that issues new queries. Authenti…
CVE-2025-71394 NONE Patched — 2026-07-18 SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows authenticated users to read arbitrary files on the file…
CVE-2025-71395 NONE Patched — 2026-07-18 SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to restrict resulting string length when using regex pa…
CVE-2024-58367 NONE Patched — 2026-07-18 SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations, allowing authorized users to access unauthorized fi…
CVE-2024-58356 NONE Patched — 2026-07-18 SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ... OVERWRITE clause is used on tables defined with TYPE RELATION. Because table …
CVE-2026-16117 CRITICAL Patched 10.0 2026-07-18 Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes path…
CVE-2026-47865 CRITICAL Patched 9.8 2026-07-18 VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the …
CVE-2026-10130 HIGH 8.2 2026-07-18 QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid session tokens for existing accounts by submitting a signu…
CVE-2026-12228 HIGH 8.7 2026-07-18 A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The endpoint stores attacker-control…
CVE-2026-16152 HIGH 7.3 2026-07-18 A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_rooma.php. Performing a manipulation of…
CVE-2026-16154 HIGH 7.3 2026-07-18 A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerability is an unknown functionality of the file /edit_r…
CVE-2026-53994 HIGH 7.5 2026-07-18 ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user. The fxp_packet_read() function accepts the attacker-supplied 32-bit big-endi…
CVE-2026-16128 HIGH 7.3 2026-07-18 A security flaw has been discovered in zevorn rt-claw up to 0.2.0. This impacts the function receiver_thread of the file claw/services/swarm/swarm.c of the component http_r…
CVE-2026-16126 HIGH 7.3 2026-07-18 A vulnerability was determined in zevorn rt-claw up to 0.2.0. The impacted element is the function handle_rpc_request of the file claw/services/swarm/swarm.c of the compone…
CVE-2026-16127 HIGH 7.3 2026-07-18 A vulnerability was identified in zevorn rt-claw up to 0.2.0. This affects the function claw_net_get/claw_net_post of the file claw/tools/tool_net.c of the component http_r…
CVE-2026-16125 HIGH 7.3 2026-07-18 A vulnerability was found in zevorn rt-claw up to 0.2.0. The affected element is the function claw_net_get/claw_net_post of the file claw/services/tools/net.c of the compon…
CVE-2026-9323 HIGH 8.1 2026-07-18 The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that …
CVE-2026-11826 HIGH 8.8 2026-07-18 OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_master.cpp. getData() reads characters between two delimiters into a cal…
CVE-2024-58362 HIGH Patched 8.8 2026-07-18 SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without recursively validating it…