authzed records
13 published records for vendor authzed.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-532 Insertion of Sensitive Information into Log File2
- CWE-190 Integer Overflow or Wraparound1
- CWE-20 Improper Input Validation1
- CWE-209 Generation of Error Message Containing Sensitive Information1
- CWE-269 Improper Privilege Management1
- CWE-277 Insecure Inherited Permissions1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2024-27101No exploit | Integer overflow in chunking helper causes dispatching to miss elements or panicauthzed · spicedb · CWE-190 | Critical9.1 | — | 0.5% | Mar 1, 2024 |
32Monitor | CVE-2022-21646No exploit | Lookup operations do not take into account wildcards in SpiceDBauthzed · spicedb · CWE-20 | High8.1 | — | 1.3% | Jan 11, 2022 |
30Monitor | CVE-2023-29193No exploit | SpiceDB binding metrics port to untrusted networks and can leak command-line flagsauthzed · spicedb · CWE-209 | High7.5 | — | 0.8% | Apr 14, 2023 |
26Monitor | CVE-2023-46255No exploit | `SPICEDB_DATASTORE_CONN_URI` is leaked when URI cannot be parsedauthzed · spicedb · CWE-532 | Medium6.5 | — | 0.4% | Oct 31, 2023 |
21Monitor | CVE-2023-35930No exploit | LookupResources may return partial results in spicedbauthzed · spicedb · CWE-913 | Medium5.3 | — | 0.4% | Jun 26, 2023 |
21Monitor | CVE-2024-38361No exploit | Permissions processing error in spacedbauthzed · spicedb · CWE-281 | Medium5.3 | — | 0.4% | Jun 20, 2024 |
21Monitor | CVE-2025-49011No exploit | SpiceDB checks involving relations with caveats can result in no permission when permission is expectedauthzed · spicedb · CWE-358 | Medium5.3 | — | 0.3% | Jun 6, 2025 |
21Monitor | CVE-2024-46989No exploit | Multiple caveats on resources of the same type can result in no permission when permission is expectedauthzed · spicedb · CWE-269 | Medium5.3 | — | 0.3% | Sep 18, 2024 |
17Monitor | CVE-2024-32001No exploit | SpiceDB: LookupSubjects may return partial results if a specific kind of relation is usedauthzed · spicedb · CWE-755 | Medium4.3 | — | 0.6% | Apr 10, 2024 |
17Monitor | CVE-2026-40091No exploit | SpiceDB: SPICEDB_DATASTORE_CONN_URI is leaked on startup logsauthzed · spicedb · CWE-532 | Medium4.4 | — | 0.2% | Apr 15, 2026 |
11Monitor | CVE-2025-65111No exploit | SpiceDB's LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Resultsauthzed · spicedb · CWE-277 | Low2.9 | — | 0.2% | Nov 21, 2025 |
10Monitor | CVE-2025-64529No exploit | SpiceDB's WriteRelationships fails silently if payload is too bigauthzed · spicedb · CWE-770 | Low2.7 | — | 0.2% | Nov 10, 2025 |
9Monitor | CVE-2024-48909No exploit | SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is notauthzed · spicedb · CWE-172 | Low2.4 | — | 0.3% | Oct 14, 2024 |
- CVE-2024-2710136Monitor
Integer overflow in chunking helper causes dispatching to miss elements or panic
CriticalCVSS 9.1No exploitEPSS 0%authzed · spicedbMar 1, 2024
- CVE-2022-2164632Monitor
Lookup operations do not take into account wildcards in SpiceDB
HighCVSS 8.1No exploitEPSS 1%authzed · spicedbJan 11, 2022
- CVE-2023-2919330Monitor
SpiceDB binding metrics port to untrusted networks and can leak command-line flags
HighCVSS 7.5No exploitEPSS 1%authzed · spicedbApr 14, 2023
- CVE-2023-4625526Monitor
`SPICEDB_DATASTORE_CONN_URI` is leaked when URI cannot be parsed
MediumCVSS 6.5No exploitEPSS 0%authzed · spicedbOct 31, 2023
- CVE-2023-3593021Monitor
LookupResources may return partial results in spicedb
MediumCVSS 5.3No exploitEPSS 0%authzed · spicedbJun 26, 2023
- CVE-2024-3836121Monitor
Permissions processing error in spacedb
MediumCVSS 5.3No exploitEPSS 0%authzed · spicedbJun 20, 2024
- CVE-2025-4901121Monitor
SpiceDB checks involving relations with caveats can result in no permission when permission is expected
MediumCVSS 5.3No exploitEPSS 0%authzed · spicedbJun 6, 2025
- CVE-2024-4698921Monitor
Multiple caveats on resources of the same type can result in no permission when permission is expected
MediumCVSS 5.3No exploitEPSS 0%authzed · spicedbSep 18, 2024
- CVE-2024-3200117Monitor
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used
MediumCVSS 4.3No exploitEPSS 1%authzed · spicedbApr 10, 2024
- CVE-2026-4009117Monitor
SpiceDB: SPICEDB_DATASTORE_CONN_URI is leaked on startup logs
MediumCVSS 4.4No exploitEPSS 0%authzed · spicedbApr 15, 2026
- CVE-2025-6511111Monitor
SpiceDB's LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results
LowCVSS 2.9No exploitEPSS 0%authzed · spicedbNov 21, 2025
- CVE-2025-6452910Monitor
SpiceDB's WriteRelationships fails silently if payload is too big
LowCVSS 2.7No exploitEPSS 0%authzed · spicedbNov 10, 2025
- CVE-2024-489099Monitor
SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not
LowCVSS 2.4No exploitEPSS 0%authzed · spicedbOct 14, 2024