All verified exploits

CVE-2026-30240 PWA ZIP Path Traversal

Pentest critical Budibase Added cve-verified-cve-2026-30240

Reads arbitrary server files including /proc/1/environ through path traversal in the PWA ZIP processing endpoint, exfiltrating all secrets and credentials in a single request.

Is your app exploitable through CVE-2026-30240?

Scan your domain free