Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Server — Vulnerabilities & Security Advisories 174

All 174 CVE vulnerabilities found in Server, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security weaknesses for vendor products identified by the tag "Server". It collects publicly reported vulnerabilities affecting server-class systems, covering advisories published over the recent multi-year timeframe. Visitors can track a vendor's latest security notices, understand specific weakness classes such as buffer overflows or authentication flaws, and review the historical vulnerability landscape for a particular server product. The data is organized to support threat modeling, patch management, and risk assessment for infrastructure components. No specific CVE identifiers are listed in the introductory text; instead, the page provides links to detailed records where individual cases are documented with timestamps, severity ratings, and affected versions. This aggregation helps security teams identify patterns in how server vulnerabilities emerge and are resolved. The scope includes both critical and moderate-severity issues, ensuring a comprehensive view of the server ecosystem's security posture.

Vendor: FileZilla

CVE ID Title CVSS Severity Published
CVE-2026-100688 Budibase server before 3.45.0 Cross-Tenant Information Disclosure CWE-639 6.5 Medium 2026-09-26
CVE-2026-100686 Budibase before 3.45.0 Cross-Workspace Privilege Escalation via POST /api/global/groups/:groupId/apps CWE-269 8.1 High 2026-09-26
CVE-2026-100687 Budibase Server before 3.45.0 Credential Exposure via External Table Broadcast CWE-200 5.5 Medium 2026-09-26
CVE-2026-100685 Budibase before 3.45.0 Information Disclosure via Chat Links CWE-863 7.7 High 2026-09-26
CVE-2026-100683 Budibase before 3.45.0 SQL Injection via column-rename DDL CWE-89 8.0 High 2026-09-26
CVE-2026-100684 Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC CWE-287 8.1 High 2026-09-26
CVE-2026-100682 Budibase Server before 3.45.0 Arbitrary File Write via ZIP Symlink CWE-22 8.8 High 2026-09-26
CVE-2026-100681 Budibase before 3.45.0 SSRF and OAuth Token Exfiltration via Teams Webhook CWE-918 5.4 Medium 2026-09-26
CVE-2026-100680 Budibase before 3.45.0 Arbitrary Local File Read via OpenAPI Import CWE-200 8.1 High 2026-09-26
CVE-2026-58272 Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory) CWE-208 5.3 Medium 2026-09-21
CVE-2026-58270 Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters` CWE-1333 6.5 Medium 2026-09-21
CVE-2026-58269 Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token` CWE-288 8.1 High 2026-09-21
CVE-2026-58271 @sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register` CWE-307 6.8 Medium 2026-09-21
CVE-2026-77165 TYPE_TOKEN锁导致文件永久锁定无恢复路径 CWE-284 - - 2026-09-21
CVE-2026-68493 用户猜测复杂ID可越权获取圈子成员列表 CWE-639 - - 2026-09-18
CVE-2026-82985 Nextcloud Photos智能相册共享文件泄露漏洞 CWE-284 - - 2026-09-18
CVE-2026-77164 Nextcloud Circles盲SSRF漏洞 CWE-918 - - 2026-09-18
CVE-2026-13327 Devolutions Server 2.16及以前LDAPS证书验证漏洞 CWE-295 - - 2026-09-15
CVE-2026-84850 Devolutions Server 2026.2.16证书验证漏洞 CWE-295 - - 2026-09-15
CVE-2026-90969 Devolutions Server 权限许可和访问控制问题漏洞 CWE-284 - - 2026-09-15
CVE-2026-90971 Devolutions Server 授权问题漏洞 CWE-863 - - 2026-09-15
CVE-2026-54047 Laci Synchroni Backend Vulnerable to Account Takeover / User Impersonation via Client-Side Configuration Manipulation CWE-287 9.2 Critical 2026-09-11
CVE-2026-82246 Budibase Server before 3.41.3 SSRF via Query Import CWE-918 7.1 High 2026-08-28
CVE-2026-82245 Budibase before 3.41.3 Missing Authorization License Management CWE-862 8.1 High 2026-08-28
CVE-2026-82243 Budibase Server before 3.41.3 SSRF with Credential Leakage CWE-918 7.6 High 2026-08-28
CVE-2026-82244 Budibase before 3.41.3 Remote Code Execution via Plugin eval() CWE-94 9.1 Critical 2026-08-28
CVE-2026-82242 Budibase before 3.41.3 Cross-Application Resource Injection via Missing Authorization CWE-862 7.7 High 2026-08-28
CVE-2026-82241 Budibase backend-core SSRF via incomplete default blacklist CWE-918 7.1 High 2026-08-28
CVE-2026-82240 Budibase before 3.41.3 Privilege Escalation via User Update API CWE-862 8.1 High 2026-08-28
CVE-2026-82239 Budibase before 3.41.3 Authorization Bypass via datasources/query CWE-862 8.1 High 2026-08-28

All 174 known CVE vulnerabilities affecting Server with full Chinese analysis, references, and POCs where available.