Server
275 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Server, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.
Server CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 3 |
| 2025-01 | 0 |
| 2025-02 | 1 |
| 2025-03 | 5 |
| 2025-04 | 0 |
| 2025-05 | 3 |
| 2025-06 | 3 |
| 2025-07 | 5 |
| 2025-08 | 2 |
| 2025-09 | 0 |
| 2025-10 | 3 |
| 2025-11 | 6 |
| 2025-12 | 2 |
| 2026-01 | 2 |
| 2026-02 | 3 |
| 2026-03 | 9 |
| 2026-04 | 10 |
| 2026-05 | 19 |
| 2026-06 | 19 |
| 2026-07 | 12 |
| 2026-08 | 16 |
| 2026-09 | 22 |
Severity
How the 275 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical37
- High95
- Medium112
- Low25
Latest CVEs
The 15 most recently published vulnerabilities affecting Server.
- CVE-2026-100688Budibase server before 3.45.0 Cross-Tenant Information Disclosure6.5
- CVE-2026-100687Budibase Server before 3.45.0 Credential Exposure via External Table Broadcast5.5
- CVE-2026-100686Budibase before 3.45.0 Cross-Workspace Privilege Escalation via POST /api/global/groups/:groupId/apps8.1
- CVE-2026-100684Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC8.1
- CVE-2026-100685Budibase before 3.45.0 Information Disclosure via Chat Links7.7
- CVE-2026-100683Budibase before 3.45.0 SQL Injection via column-rename DDL8.0
- CVE-2026-100681Budibase before 3.45.0 SSRF and OAuth Token Exfiltration via Teams Webhook5.4
- CVE-2026-100682Budibase Server before 3.45.0 Arbitrary File Write via ZIP Symlink8.8
- CVE-2026-100680Budibase before 3.45.0 Arbitrary Local File Read via OpenAPI Import8.1
- CVE-2026-58272Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory)5.3
- CVE-2026-58270Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters`6.5
- CVE-2026-58269Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token`8.1
- CVE-2026-58271@sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register`6.8
- CVE-2026-77165File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.6.5
- CVE-2026-77164Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this re...6.2
Product grouping is registry-driven, with AI assist and human review. How it works