2026 CVE Vulnerabilities

64,471 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48148MEDIUM5.3Budibase is an open-source low-code platform. Prior to 3.35.3, the VectorDB configuration endpoint in Budibase accepts ...
CVE-2026-48147MEDIUM6.5Budibase is an open-source low-code platform. Prior to 3.35.4, the buildMatcherRegex() / matches() functions in packages...
CVE-2026-48146HIGH7.7Budibase is an open-source low-code platform. Prior to 3.39.0, the OAuth2 token fetch function in packages/server/src/sd...
CVE-2026-48128MEDIUM5.1Budibase is an open-source low-code platform. Prior to 3.39.0, the executeQuery automation step in Budibase accepts a qu...
CVE-2026-46427HIGH7.7Budibase is an open-source low-code platform. Prior to 3.38.3, removeSecrets at packages/server/src/sdk/workspace/dataso...
CVE-2026-46426HIGH7.6Budibase is an open-source low-code platform. Prior to 3.38.2, the file upload endpoint POST /api/attachments/process do...
CVE-2026-46425CRITICAL9.9Budibase is an open-source low-code platform. Prior to 3.38.2, packages/worker/src/api/routes/global/scim.ts attaches on...
CVE-2026-46424MEDIUM4.2Budibase is an open-source low-code platform. Prior to 3.38.2, the public API role unassignment endpoint (POST /api/publ...
CVE-2026-45719MEDIUM6.5Budibase is an open-source low-code platform. Prior to 3.38.1, the V1 Views API (POST /api/views) accepts a calculation ...
CVE-2026-45718MEDIUM5.4Budibase is an open-source low-code platform. Prior to 3.38.1, the row action trigger endpoint (POST /api/tables/:source...
CVE-2026-45717HIGH8.8Budibase is an open-source low-code platform. Prior to 3.38.1, Budibase exposes a REST API for datasource management. Th...
CVE-2026-45716HIGH8.8Budibase is an open-source low-code platform. Prior to 3.38.1, the POST /api/global/users/onboard endpoint is protected ...
CVE-2026-45715HIGH7.7Budibase is an open-source low-code platform. Prior to 3.38.1, the REST datasource integration (packages/server/src/inte...
CVE-2026-45548HIGH7.7Budibase is an open-source low-code platform. Prior to 3.34.8, the processUrlFile function in packages/server/src/automa...
CVE-2026-45090HIGH7.5Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, ParameterAnalysis in pk...
CVE-2026-45089HIGH8.2Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in R...
CVE-2026-45088HIGH7.5Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in R...
CVE-2026-45087CRITICAL10Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started ...
CVE-2026-45081MEDIUM6.5Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.5.0, authenticated employees could a...
CVE-2026-45061HIGH7.7Budibase is an open-source low-code platform. Prior to 3.35.10, the Plugin URL upload endpoint (POST /api/plugin) valida...
CVE-2026-45047HIGH7.5bird-lg-go is a BIRD looking glass in Go. Prior to 1.4.5, the apiHandler (and similarly webHandlerTelegramBot) processes...
CVE-2026-44521HIGH8.8elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticate...
CVE-2026-44460HIGH7.4FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 3.12.0,...
CVE-2026-44378HIGH7.5Botan is a C++ cryptography library. Prior to 3.12.0, certain patterns of indefinite length encodings in BER data could ...
CVE-2026-44346HIGH8.8BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now