2026 CVE Vulnerabilities
64,596 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48148 | MEDIUM | 5.3 | 0.2% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.35.3, the VectorDB configuration endpoint in Budibase accepts ... |
| CVE-2026-48147 | MEDIUM | 6.5 | 0.1% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.35.4, the buildMatcherRegex() / matches() functions in packages... |
| CVE-2026-48146 | HIGH | 7.7 | 0.2% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.39.0, the OAuth2 token fetch function in packages/server/src/sd... |
| CVE-2026-48128 | MEDIUM | 5.1 | 0.3% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.39.0, the executeQuery automation step in Budibase accepts a qu... |
| CVE-2026-46427 | HIGH | 7.7 | 0.2% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.38.3, removeSecrets at packages/server/src/sdk/workspace/dataso... |
| CVE-2026-46426 | HIGH | 7.6 | 0.2% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.38.2, the file upload endpoint POST /api/attachments/process do... |
| CVE-2026-46425 | CRITICAL | 9.9 | 0.3% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.38.2, packages/worker/src/api/routes/global/scim.ts attaches on... |
| CVE-2026-46424 | MEDIUM | 4.2 | 0.2% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.38.2, the public API role unassignment endpoint (POST /api/publ... |
| CVE-2026-45719 | MEDIUM | 6.5 | 0.3% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.38.1, the V1 Views API (POST /api/views) accepts a calculation ... |
| CVE-2026-45718 | MEDIUM | 5.4 | 0.1% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.38.1, the row action trigger endpoint (POST /api/tables/:source... |
| CVE-2026-45717 | HIGH | 8.8 | 0.3% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.38.1, Budibase exposes a REST API for datasource management. Th... |
| CVE-2026-45716 | HIGH | 8.8 | 0.3% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.38.1, the POST /api/global/users/onboard endpoint is protected ... |
| CVE-2026-45715 | HIGH | 7.7 | 0.3% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.38.1, the REST datasource integration (packages/server/src/inte... |
| CVE-2026-45548 | HIGH | 7.7 | 0.3% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.34.8, the processUrlFile function in packages/server/src/automa... |
| CVE-2026-45090 | HIGH | 7.5 | 0.2% | May 27, 2026 | Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, ParameterAnalysis in pk... |
| CVE-2026-45089 | HIGH | 8.2 | 0.2% | May 27, 2026 | Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in R... |
| CVE-2026-45088 | HIGH | 7.5 | 0.3% | May 27, 2026 | Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in R... |
| CVE-2026-45087 | CRITICAL | 10 | 1.1% | May 27, 2026 | Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started ... |
| CVE-2026-45081 | MEDIUM | 6.5 | 0.2% | May 27, 2026 | Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.5.0, authenticated employees could a... |
| CVE-2026-45061 | HIGH | 7.7 | 0.3% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.35.10, the Plugin URL upload endpoint (POST /api/plugin) valida... |
| CVE-2026-45047 | HIGH | 7.5 | 0.4% | May 27, 2026 | bird-lg-go is a BIRD looking glass in Go. Prior to 1.4.5, the apiHandler (and similarly webHandlerTelegramBot) processes... |
| CVE-2026-44521 | HIGH | 8.8 | 0.2% | May 27, 2026 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticate... |
| CVE-2026-44460 | HIGH | 7.4 | 0.3% | May 27, 2026 | FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 3.12.0,... |
| CVE-2026-44378 | HIGH | 7.5 | 0.3% | May 27, 2026 | Botan is a C++ cryptography library. Prior to 3.12.0, certain patterns of indefinite length encodings in BER data could ... |
| CVE-2026-44346 | HIGH | 8.8 | 0.3% | May 27, 2026 | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now