Server
This hub aggregates every CVE we track for Server, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
248
CVEs tracked
37
Critical
87
High
0
In CISA KEV
Severity distribution
MEDIUM100HIGH87CRITICAL37LOW24
Monthly trend
0
0
3
0
1
5
0
3
3
4
0
0
3
6
2
2
3
8
10
19
19
11
16
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Server.
- CVE-2026-82245Budibase before 3.41.3 Missing Authorization License Management8.1
- CVE-2026-82246Budibase Server before 3.41.3 SSRF via Query Import7.1
- CVE-2026-82244Budibase before 3.41.3 Remote Code Execution via Plugin eval()9.1
- CVE-2026-82243Budibase Server before 3.41.3 SSRF with Credential Leakage7.6
- CVE-2026-82242Budibase before 3.41.3 Cross-Application Resource Injection via Missing Authorization7.7
- CVE-2026-82241Budibase backend-core SSRF via incomplete default blacklist7.1
- CVE-2026-82239Budibase before 3.41.3 Authorization Bypass via datasources/query8.1
- CVE-2026-82240Budibase before 3.41.3 Privilege Escalation via User Update API8.1
- CVE-2026-72859Budibase 3.39.4 before 3.40.0 Authorization Regression via S3 Presigned URL7.7
- CVE-2026-72855Budibase before 3.40.0 DNS Rebinding SSRF via OpenAPI and REST8.5
- CVE-2026-72851Budibase before 3.40.0 SQL Injection via Unauthenticated Webhook10.0
- CVE-2026-72850Budibase before 3.40.0 Arbitrary File Write via Path Traversal9.1
- CVE-2026-72849Budibase before 3.40.0 Identity Confusion via Chat-Link Handoff CSRF7.7
- CVE-2026-73617Budibase before 3.40.0 NoSQL Injection via MongoDB datasource7.1
- CVE-2026-73618Budibase Server before 3.40.0 NoSQL Injection via JSON Parameter8.3
Product normalization is registry-driven with AI assist and human review. How it works