Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.7 HIGH
CVE-2026-46427 — Budibase: Snowflake private key returned unmasked from datasource API to BASIC users

Budibase is an open-source low-code platform. Prior to 3.38.3, removeSecrets at packages/server/src/sdk/workspace/datasources/datasources.ts masks only datasource config fields whose schema type is D…

budibase | Remote | Information Disclosure
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.6 HIGH
CVE-2026-46426 — Budibase: Unrestricted Upload of File with Dangerous Type

Budibase is an open-source low-code platform. Prior to 3.38.2, the file upload endpoint POST /api/attachments/process does not enforce active-content restrictions for authenticated users. The checks …

budibase | Remote | Cross-Site Scripting
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
9.9 CRITICAL
CVE-2026-46425 — Budibase: SCIM endpoints lack role-based authorization, BASIC users CRUD tenant users

Budibase is an open-source low-code platform. Prior to 3.38.2, packages/worker/src/api/routes/global/scim.ts attaches only two middlewares to the SCIM router: requireSCIM (checks the Enterprise featu…

budibase | Remote | Authorization
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
4.2 MEDIUM
CVE-2026-46424 — Budibase: Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users…

Budibase is an open-source low-code platform. Prior to 3.38.2, the public API role unassignment endpoint (POST /api/public/v1/roles/unassign) updates user documents in CouchDB but does not invalidate…

budibase | Remote | Authorization
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
6.5 MEDIUM
CVE-2026-45719 — Budibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API

Budibase is an open-source low-code platform. Prior to 3.38.1, the V1 Views API (POST /api/views) accepts a calculation parameter from the request body that is interpolated directly into a CouchDB re…

budibase | Remote | Injection
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
5.4 MEDIUM
CVE-2026-45718 — Budibase: Row Action Trigger Bypasses View Row Filter Security Boundary Allowing Action o…

Budibase is an open-source low-code platform. Prior to 3.38.1, the row action trigger endpoint (POST /api/tables/:sourceId/actions/:actionId/trigger) fails to validate that the user-supplied rowId is…

budibase | Remote | Authorization
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
8.8 HIGH
CVE-2026-45717 — Budibase: `PUT /api/datasources/:datasourceId` is protected only by `TABLE/READ` permissi…

Budibase is an open-source low-code platform. Prior to 3.38.1, Budibase exposes a REST API for datasource management. The route PUT /api/datasources/:datasourceId is registered in the authorizedRoute…

budibase | Remote | Server-Side Request Forgery
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
8.8 HIGH
CVE-2026-45716 — Budibase: Builder-to-Admin Privilege Escalation via onboardUsers Endpoint Without SMTP Co…

Budibase is an open-source low-code platform. Prior to 3.38.1, the POST /api/global/users/onboard endpoint is protected by workspaceBuilderOrAdmin middleware, allowing any user with builder permissio…

budibase | Remote | Authorization
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
7.7 HIGH
CVE-2026-45715 — Budibase: SSRF Bypass via HTTP Redirect in REST Datasource Integration

Budibase is an open-source low-code platform. Prior to 3.38.1, the REST datasource integration (packages/server/src/integrations/rest.ts) follows HTTP redirects without re-checking the IP blacklist, …

budibase | Remote | Server-Side Request Forgery
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.7 HIGH
CVE-2026-45548 — Budibase: SSRF in AI Extract File Automation Step via Missing IP Blacklist Validation

Budibase is an open-source low-code platform. Prior to 3.34.8, the processUrlFile function in packages/server/src/automations/steps/ai/extract.ts uses fetch(fileUrl) directly without the IP blacklist…

budibase | Remote | Server-Side Request Forgery
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
7.5 HIGH
CVE-2026-45090 — Dalfox: Unauthenticated Remote DoS via Closed-Channel Write in `ParameterAnalysis` (serve…

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, ParameterAnalysis in pkg/scanning/parameterAnalysis.go runs two sequential worker stages that both wri…

Remote | Denial of Service
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
8.2 HIGH
CVE-2026-45089 — Dalfox: Unauthenticated Arbitrary File Create/Append via `output` Option in Dalfox Server…

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the output, output-all, and debug fields in model.Options …

Remote | Path Traversal
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
7.5 HIGH
CVE-2026-45088 — Dalfox: Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-pay…

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the custom-payload-file field in model.Options is JSON-tag…

Remote | Cross-Site Scripting
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
10.0 CRITICAL
CVE-2026-45087 — Dalfox: Unauthenticated Remote Code Execution via `found-action` in Dalfox Server Mode

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalfox server), the server binds to 0.0.0.0:6664 by de…

Remote | Cross-Site Scripting
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
6.5 MEDIUM
CVE-2026-45081 — Frappe HR: Permission Bypass in HRMS Leave Details API

Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.5.0, authenticated employees could access other employees’ leave details due to improper authorization checks. This…

frappe_hr | Remote | Authorization
May 27, 2026 Jun 01, 2026
May 27, 2026
Jun 01, 2026
7.7 HIGH
CVE-2026-45061 — Budibase: SSRF via trivial `.tar.gz` substring bypass in Plugin URL upload (`/api/plugin`)

Budibase is an open-source low-code platform. Prior to 3.35.10, the Plugin URL upload endpoint (POST /api/plugin) validates the submitted URL with a single substring check: url.includes(".tar.gz"). A…

budibase | Remote | Server-Side Request Forgery
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.5 HIGH
CVE-2026-45047 — bird-lg-go: Fatal Out-of-Memory (OOM) Denial of Service via Unbounded JSON Decoding

bird-lg-go is a BIRD looking glass in Go. Prior to 1.4.5, the apiHandler (and similarly webHandlerTelegramBot) processes user-provided JSON payloads by directly using json.NewDecoder(r.Body).Decode(&…

bird-lg-go | Remote | Denial of Service
May 27, 2026 Jun 01, 2026
May 27, 2026
Jun 01, 2026
8.8 HIGH
CVE-2026-44521 — elFinder: SQL Injection MySQL Volume Driver (elFinderVolumeMySQL)

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability in the elFinder MySQL volume driver (elFinderVolu…

elfinder | Remote | Injection
May 27, 2026 Jun 01, 2026
May 27, 2026
Jun 01, 2026
7.4 HIGH
CVE-2026-44460 — FileRise: TOTP Bypass via Setup Endpoint Disclosing Existing Secret

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 3.12.0, /api/totp_setup.php is callable from a session that has only passed the passwo…

filerise | Remote | Authentication
May 27, 2026 Jun 01, 2026
May 27, 2026
Jun 01, 2026
7.5 HIGH
CVE-2026-44378 — Botan: Quadratic complexity decoding BER indefinite length encodings

Botan is a C++ cryptography library. Prior to 3.12.0, certain patterns of indefinite length encodings in BER data could cause quadratic behavior in the parser, resulting in a denial of service. Such …

botan | Remote | Denial of Service
May 27, 2026 Jun 02, 2026
May 27, 2026
Jun 02, 2026
Showing 20 of 7162 Results