Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26383
Total
1955
Critical
7969
High
8219
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-48128 | UNKNOWN | — | Budibase is an open-source low-code platform. Prior to 3.39.0, the executeQuery automation step in Budibase accepts a queryId from automation step inputs and passes it … | May 27, 2026 |
| CVE-2026-46427 | HIGH | 7.7 | Budibase is an open-source low-code platform. Prior to 3.38.3, removeSecrets at packages/server/src/sdk/workspace/datasources/datasources.ts masks only datasource config fields whose schema type is DatasourceFieldType.PASSWORD. The Snowflake integration … | May 27, 2026 |
| CVE-2026-46426 | HIGH | 7.6 | Budibase is an open-source low-code platform. Prior to 3.38.2, the file upload endpoint POST /api/attachments/process does not enforce active-content restrictions for authenticated users. The checks … | May 27, 2026 |
| CVE-2026-46425 | CRITICAL | 9.9 | Budibase is an open-source low-code platform. Prior to 3.38.2, packages/worker/src/api/routes/global/scim.ts attaches only two middlewares to the SCIM router: requireSCIM (checks the Enterprise feature flag and … | May 27, 2026 |
| CVE-2026-46424 | MEDIUM | 4.2 | Budibase is an open-source low-code platform. Prior to 3.38.2, the public API role unassignment endpoint (POST /api/public/v1/roles/unassign) updates user documents in CouchDB but does not … | May 27, 2026 |
| CVE-2026-45719 | MEDIUM | 6.5 | Budibase is an open-source low-code platform. Prior to 3.38.1, the V1 Views API (POST /api/views) accepts a calculation parameter from the request body that is … | May 27, 2026 |
| CVE-2026-45718 | MEDIUM | 5.4 | Budibase is an open-source low-code platform. Prior to 3.38.1, the row action trigger endpoint (POST /api/tables/:sourceId/actions/:actionId/trigger) fails to validate that the user-supplied rowId is within … | May 27, 2026 |
| CVE-2026-45717 | HIGH | 8.8 | Budibase is an open-source low-code platform. Prior to 3.38.1, Budibase exposes a REST API for datasource management. The route PUT /api/datasources/:datasourceId is registered in the … | May 27, 2026 |
| CVE-2026-45716 | HIGH | 8.8 | Budibase is an open-source low-code platform. Prior to 3.38.1, the POST /api/global/users/onboard endpoint is protected by workspaceBuilderOrAdmin middleware, allowing any user with builder permissions to … | May 27, 2026 |
| CVE-2026-45715 | HIGH | 7.7 | Budibase is an open-source low-code platform. Prior to 3.38.1, the REST datasource integration (packages/server/src/integrations/rest.ts) follows HTTP redirects without re-checking the IP blacklist, allowing an authenticated … | May 27, 2026 |
| CVE-2026-45548 | HIGH | 7.7 | Budibase is an open-source low-code platform. Prior to 3.34.8, the processUrlFile function in packages/server/src/automations/steps/ai/extract.ts uses fetch(fileUrl) directly without the IP blacklist validation that is consistently … | May 27, 2026 |
| CVE-2026-45090 | HIGH | 7.5 | Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, ParameterAnalysis in pkg/scanning/parameterAnalysis.go runs two sequential worker stages that both … | May 27, 2026 |
| CVE-2026-45089 | HIGH | 8.2 | Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the … | May 27, 2026 |
| CVE-2026-45088 | HIGH | 7.5 | Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the … | May 27, 2026 |
| CVE-2026-45087 | CRITICAL | 10.0 | Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalfox … | May 27, 2026 |
| CVE-2026-45081 | MEDIUM | 6.5 | Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.5.0, authenticated employees could access other employees’ leave details due to improper authorization … | May 27, 2026 |
| CVE-2026-45061 | HIGH | 7.7 | Budibase is an open-source low-code platform. Prior to 3.35.10, the Plugin URL upload endpoint (POST /api/plugin) validates the submitted URL with a single substring check: … | May 27, 2026 |
| CVE-2026-45047 | HIGH | 7.5 | bird-lg-go is a BIRD looking glass in Go. Prior to 1.4.5, the apiHandler (and similarly webHandlerTelegramBot) processes user-provided JSON payloads by directly using json.NewDecoder(r.Body).Decode(&request) without … | May 27, 2026 |
| CVE-2026-44521 | HIGH | 8.8 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability in the elFinder … | May 27, 2026 |
| CVE-2026-44460 | HIGH | 7.4 | FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 3.12.0, /api/totp_setup.php is callable from a session that has … | May 27, 2026 |
| CVE-2026-44378 | UNKNOWN | — | Botan is a C++ cryptography library. Prior to 3.12.0, certain patterns of indefinite length encodings in BER data could cause quadratic behavior in the parser, … | May 27, 2026 |
| CVE-2026-44346 | HIGH | 8.8 | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, a malicious bentofile.yaml containing a … | May 27, 2026 |
| CVE-2026-44345 | HIGH | 8.8 | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, src/bentoml/_internal/container/frontend/dockerfile/templates/base_v2.j2 interpolates docker.base_image raw with … | May 27, 2026 |
| CVE-2026-42553 | UNKNOWN | — | Cinny is a Matrix client. Prior to 4.10.3, A remote authenticated attacker who shares a room with a victim and has permissions to create room … | May 27, 2026 |
| CVE-2026-42328 | MEDIUM | 6.2 | go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for CBOR and JSON, and tooling for … | May 27, 2026 |