2026 CVE Vulnerabilities

65,537 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-100687MEDIUM5.5Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before broadcasting external table update...
CVE-2026-100686HIGH8.1Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endp...
CVE-2026-100685HIGH7.7Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enume...
CVE-2026-100684HIGH8.1Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. ...
CVE-2026-100683HIGH8Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlT...
CVE-2026-100682HIGH8.8Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extrac...
CVE-2026-100681MEDIUM5.4Budibase before 3.45.0 contains an unauthenticated server-side request forgery and credential exfiltration vulnerability...
CVE-2026-100680HIGH8.1Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validat...
CVE-2026-100679HIGH8.8stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypas...
CVE-2026-100678MEDIUM6.5stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who kn...
CVE-2026-100677MEDIUM5.3stoatchat before 0.15.5 contains an account enumeration vulnerability in the login endpoint that exposes source file loc...
CVE-2026-100676HIGH8.2January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly resolves SVG...
CVE-2026-100675MEDIUM6.5stoatchat versions before 0.15.5 contain a denial of service vulnerability in the acknowledgement worker that processes ...
CVE-2026-100674MEDIUM4.3stoatchat before 0.15.5 fails to revalidate usernames after Unicode sanitization, allowing attackers to create usernames...
CVE-2026-100673HIGH8.2The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries i...
CVE-2026-100672HIGH7.5The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an admin handler that r...
CVE-2026-100671HIGH8Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 through 2.0.18 and 1.7.x only where content Tw...
CVE-2026-100670HIGH8.8Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The ac...
CVE-2026-100669HIGH7.5Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. ...
CVE-2026-100668MEDIUM6.5Grav 2.0.0 through 2.0.24 contain a Twig content sandbox escape. The `array` filter (and its identical function form) is...
CVE-2026-100667MEDIUM5.3grav-plugin-login (the Grav CMS Login plugin) versions >= 3.8.7 and < 3.9.7 allow the two-factor authentication challeng...
CVE-2026-100666HIGH7.3Netty's HttpServerCodec (io.netty:netty-codec-http) in versions 4.2.0.Final through 4.2.16.Final and in versions up to a...
CVE-2026-100665HIGH7.5Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certifi...
CVE-2026-100664HIGH7.5Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.2.Final through 4.2.17.Final builds the HTTP/3 :authority...
CVE-2026-100663HIGH7.5Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.17.Final does not special-case HTTP/1 CON...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now