CVE Tools

Server

275 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Server, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.

Server CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Server CVEs per month
MonthCVEs
2024-100
2024-110
2024-123
2025-010
2025-021
2025-035
2025-040
2025-053
2025-063
2025-075
2025-082
2025-090
2025-103
2025-116
2025-122
2026-012
2026-023
2026-039
2026-0410
2026-0519
2026-0619
2026-0712
2026-0816
2026-0922

Severity

How the 275 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical3714%
  • High9535%
  • Medium11242%
  • Low259%

Latest CVEs

The 15 most recently published vulnerabilities affecting Server.

  1. CVE-2026-100688Budibase server before 3.45.0 Cross-Tenant Information Disclosure6.5
  2. CVE-2026-100687Budibase Server before 3.45.0 Credential Exposure via External Table Broadcast5.5
  3. CVE-2026-100686Budibase before 3.45.0 Cross-Workspace Privilege Escalation via POST /api/global/groups/:groupId/apps8.1
  4. CVE-2026-100684Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC8.1
  5. CVE-2026-100685Budibase before 3.45.0 Information Disclosure via Chat Links7.7
  6. CVE-2026-100683Budibase before 3.45.0 SQL Injection via column-rename DDL8.0
  7. CVE-2026-100681Budibase before 3.45.0 SSRF and OAuth Token Exfiltration via Teams Webhook5.4
  8. CVE-2026-100682Budibase Server before 3.45.0 Arbitrary File Write via ZIP Symlink8.8
  9. CVE-2026-100680Budibase before 3.45.0 Arbitrary Local File Read via OpenAPI Import8.1
  10. CVE-2026-58272Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory)5.3
  11. CVE-2026-58270Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters`6.5
  12. CVE-2026-58269Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token`8.1
  13. CVE-2026-58271@sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register`6.8
  14. CVE-2026-77165File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.6.5
  15. CVE-2026-77164Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this re...6.2

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store