← Back to Index
Vulnerabilities | Sonatype Guide | Sonatype Guide
Vulnerabilities
Total Vulnerabilities: 418,265
Severity Distribution
Critical : 70,098
High : 118,388
Medium : 146,520
Low : 11,048
CVE Listings
Severity : Medium
Published : Jul 25, 2026
Description : A vulnerability was identified in localstack serverless-localstack up to 1.4.0. An argument manipulation of custom.localstack.docker.compose_file leads to OS command injection. The exploit is publicly available.
Severity : High
Published : Jul 25, 2026
Description : In the Linux kernel, fixed UAF via mismatching bpf_prog/attachment RCU flavors. A non-sleepable BPF program attaching to a uprobe can cause UAF of the bpf_prog.
Severity : High
Published : Jul 25, 2026
Description : PhpSpreadsheet - XLS/OLE sector-chain loop causes memory exhaustion DoS.
Severity : Medium
Published : Jul 25, 2026
Description : A vulnerability in Ne-Lexa php-zip up to 4.0.2 allows path traversal via manipulation of entryName in ZipFile::extractTo.
Severity : High
Published : Jul 25, 2026
Description : libp2p - Uncontrolled Resource Consumption.
Severity : Medium
Published : Jul 25, 2026
Description : @frontmcp/adapters - Server-Side Request Forgery (SSRF).
Severity : High
Published : Jul 25, 2026
Description : @anephenix/hub - Uncontrolled Resource Consumption.
Severity : High
Published : Jul 25, 2026
Description : @budibase/server - Improper Authorization.
Severity : High
Published : Jul 25, 2026
Description : @budibase/server - SQL Injection.
Severity : High
Published : Jul 25, 2026
Description : @budibase/server - Improper Privilege Management.
Severity : High
Published : Jul 25, 2026
Description : @budibase/server - Exposure of Sensitive Information to an Unauthorized Actor.
Severity : Medium
Published : Jul 25, 2026
Description : @budibase/server - Exposure of Sensitive Information to an Unauthorized Actor.
Severity : High
Published : Jul 25, 2026
Description : @budibase/server - Generation of Error Message Containing Sensitive Information.
Severity : High
Published : Jul 25, 2026
Description : @budibase/server - Time-of-check Time-of-use (TOCTOU) Race Condition.
Severity : High
Published : Jul 25, 2026
Description : @budibase/server - Incorrect Authorization.
Severity : High
Published : Jul 25, 2026
Description : @budibase/server - Server-Side Request Forgery (SSRF).
Severity : Critical
Published : Jul 25, 2026
Description : @budibase/server - SQL Injection.
Severity : Medium
Published : Jul 25, 2026
Description : @budibase/server - Exposure of Sensitive Information to an Unauthorized Actor.
Severity : Medium
Published : Jul 25, 2026
Description : @budibase/server - Missing Authorization.
Severity : Medium
Published : Jul 25, 2026
Description : @budibase/server - Server-Side Request Forgery (SSRF).
Severity : Medium
Published : Jul 25, 2026
Description : @budibase/server - Observable Response Discrepancy.
Severity : Critical
Published : Jul 25, 2026
Description : @budibase/server - Improper Authentication.
Severity : High
Published : Jul 25, 2026
Description : @budibase/server - SQL Injection.
Severity : Medium
Published : Jul 25, 2026
Description : github.com/OpenListTeam/OpenList/v4 - Exposure of Sensitive Information to an Unauthorized Actor.
Severity : High
Published : Jul 25, 2026
Description : Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability due to improper validation of callable target functions.