Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,720
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 6,641 - 6,660 of 35,133 CVEs

Budibase is an open-source low-code platform. Prior to 3.35.3, the VectorDB configuration endpoint in Budibase accepts a host parameter that undergoes no validation against internal IP ranges, reserved hostnames, or URL schemes. Any authenticated user with builder-level access can supply an arbitra...

Vendor: Budibase
Product: budibase
Published: May 27, 2026
Source: NVD
CVE-2026-48147 MEDIUM - 6.5

Budibase is an open-source low-code platform. Prior to 3.35.4, the buildMatcherRegex() / matches() functions in packages/backend-core/src/middleware/matchers.ts route patterns are compiled into unanchored regular expressions and tested against ctx.request.url, which includes the full query string. T...

Vendor: Budibase
Product: budibase
Published: May 27, 2026
Source: NVD
CVE-2026-48146 HIGH - 7.7

Budibase is an open-source low-code platform. Prior to 3.39.0, the OAuth2 token fetch function in packages/server/src/sdk/workspace/oauth2/utils.ts uses raw fetch(config.url) with no SSRF protection. The safe wrapper fetchWithBlacklist() exists in the same codebase and is used in every other outboun...

Vendor: Budibase
Product: budibase
Published: May 27, 2026
Source: NVD

Budibase is an open-source low-code platform. Prior to 3.39.0, the executeQuery automation step in Budibase accepts a queryId from automation step inputs and passes it directly to the query execution controller without additional validation. When combined with a REST datasource configured to target ...

Vendor: Budibase
Product: budibase
Published: May 27, 2026
Source: NVD
CVE-2026-46427 HIGH - 7.7

Budibase is an open-source low-code platform. Prior to 3.38.3, removeSecrets at packages/server/src/sdk/workspace/datasources/datasources.ts masks only datasource config fields whose schema type is DatasourceFieldType.PASSWORD. The Snowflake integration types its privateKey field as SENSITIVE_LONGFO...

Vendor: Budibase
Product: budibase
Published: May 27, 2026
Source: NVD
CVE-2026-46425 CRITICAL - 9.9

Budibase is an open-source low-code platform. Prior to 3.38.2, packages/worker/src/api/routes/global/scim.ts attaches only two middlewares to the SCIM router: requireSCIM (checks the Enterprise feature flag and SCIM config) and doInScimContext (sets the SCIM request context). There is no role check....

Vendor: Budibase
Product: budibase
Published: May 27, 2026
Source: NVD
CVE-2026-45081 MEDIUM - 6.5

Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.5.0, authenticated employees could access other employees’ leave details due to improper authorization checks. This vulnerability is fixed in 16.5.0.

Vendor: frappe
Product: hrms
Published: May 27, 2026
Source: NVD
CVE-2026-44460 HIGH - 7.4

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 3.12.0, /api/totp_setup.php is callable from a session that has only passed the password check (state pending_login_user). When the target account already has TOTP configured, the endpoin...

Vendor: error311
Product: FileRise
Published: May 27, 2026
Source: NVD
CVE-2026-44378 HIGH - 7.5

Botan is a C++ cryptography library. Prior to 3.12.0, certain patterns of indefinite length encodings in BER data could cause quadratic behavior in the parser, resulting in a denial of service. Such BER encodings were accepted even in structures which are required to be encoded as DER, which prohibi...

Vendor: randombit
Product: botan
Published: May 27, 2026
Source: NVD
CVE-2026-38808 MEDIUM - 5.3

SQL Injection vulnerability in uzy-ssm-mall v1.1.0 allows a remote attacker to obtain sensitive information via the ProductMapper.xml and /OrderUtil.java components

Published: May 27, 2026
Source: NVD
CVE-2026-38807 HIGH - 8.8

Insecure Permissions vulnerability in kvf-admin v1.0.0 allows a remote attacker to escalate privileges via the UserController.java component

Published: May 27, 2026
Source: NVD
CVE-2025-69600 HIGH - 7.8

Command injection in Raynet rvia 12.6.4392.49-amd64.deb allows adversaries to execute commands via getconfig, and upload through the URL argument, and oracle through the -o flag The Supplier's perspective is that this is caused by Argument Injection in the find command query in rvia 12.6.4392.4...

Published: May 27, 2026
Source: NVD
CVE-2025-67903 MEDIUM - 5.3

Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass.

Published: May 27, 2026
Source: NVD
CVE-2026-45617 HIGH - 7.5

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the built-in strip_html filter uses a regex containing four flawed lazy-quantified alternatives, leading to ReDoS via quadratic backtracking. When the input contains many <scri...

Vendor: npm
Product: liquidjs
Published: May 27, 2026
Source: GitHub

Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend

Vendor: composer
Product: getkirby/cms
Published: May 27, 2026
Source: GitHub
CVE-2026-45357 HIGH - 7.5

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the date filter's strftime implementation parses width specifiers like %9999999d and forwards the captured width unchecked into pad()/padStart(), leading to memory and render...

Vendor: npm
Product: liquidjs
Published: May 27, 2026
Source: GitHub

Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions

Vendor: composer
Product: getkirby/cms
Published: May 27, 2026
Source: GitHub
CVE-2026-45260 HIGH - 8.1

Pimcore: Missing Authorization in WebDAV MOVE via unchecked asset move handling

Vendor: composer
Product: pimcore/pimcore
Published: May 27, 2026
Source: GitHub
CVE-2026-49054 MEDIUM - 4.3

Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Post Grid: from n/a through 7.9.2.

Vendor: Mamunur Rashid
Product: The Post Grid
Published: May 27, 2026
Source: NVD
CVE-2026-48027 CRITICAL - 9.8

Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and t...

Vendor: nrwl
Product: nx-console
Published: May 27, 2026
Source: NVD