Server
This hub aggregates every CVE we track for Server, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
275
CVEs tracked
37
Critical
95
High
0
In CISA KEV
Severity distribution
MEDIUM112HIGH95CRITICAL37LOW25
Monthly trend
0
0
3
0
1
5
0
3
3
5
2
0
3
6
2
2
3
9
10
19
19
12
16
22
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Server.
- CVE-2026-100688Budibase server before 3.45.0 Cross-Tenant Information Disclosure6.5
- CVE-2026-100687Budibase Server before 3.45.0 Credential Exposure via External Table Broadcast5.5
- CVE-2026-100686Budibase before 3.45.0 Cross-Workspace Privilege Escalation via POST /api/global/groups/:groupId/apps8.1
- CVE-2026-100684Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC8.1
- CVE-2026-100685Budibase before 3.45.0 Information Disclosure via Chat Links7.7
- CVE-2026-100683Budibase before 3.45.0 SQL Injection via column-rename DDL8.0
- CVE-2026-100681Budibase before 3.45.0 SSRF and OAuth Token Exfiltration via Teams Webhook5.4
- CVE-2026-100682Budibase Server before 3.45.0 Arbitrary File Write via ZIP Symlink8.8
- CVE-2026-100680Budibase before 3.45.0 Arbitrary Local File Read via OpenAPI Import8.1
- CVE-2026-58272Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory)5.3
- CVE-2026-58270Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters`6.5
- CVE-2026-58269Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token`8.1
- CVE-2026-58271@sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register`6.8
- CVE-2026-77165File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.6.5
- CVE-2026-77164Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this re...6.2
Product normalization is registry-driven with AI assist and human review. How it works