# Vulnerabilities

### Total Vulnerabilities: 418,265

#### Severity Distribution
- **Critical**: 70,098
- **High**: 118,388
- **Medium**: 146,520
- **Low**: 11,048

### CVE Listings

#### [CVE-2026-16763](https://guide.sonatype.com/vulnerability/CVE-2026-16763)
- **Severity**: Medium  
- **Published**: Jul 25, 2026  
- **Description**: A vulnerability was identified in localstack serverless-localstack up to 1.4.0. An argument manipulation of `custom.localstack.docker.compose_file` leads to OS command injection. The exploit is publicly available.

#### [CVE-2024-56675](https://guide.sonatype.com/vulnerability/CVE-2024-56675)
- **Severity**: High  
- **Published**: Jul 25, 2026  
- **Description**: In the Linux kernel, fixed UAF via mismatching bpf_prog/attachment RCU flavors. A non-sleepable BPF program attaching to a uprobe can cause UAF of the bpf_prog.

#### [CVE-2026-59933](https://guide.sonatype.com/vulnerability/CVE-2026-59933)
- **Severity**: High  
- **Published**: Jul 25, 2026  
- **Description**: PhpSpreadsheet - XLS/OLE sector-chain loop causes memory exhaustion DoS.

#### [CVE-2026-16767](https://guide.sonatype.com/vulnerability/CVE-2026-16767)
- **Severity**: Medium  
- **Published**: Jul 25, 2026  
- **Description**: A vulnerability in Ne-Lexa php-zip up to 4.0.2 allows path traversal via manipulation of `entryName` in `ZipFile::extractTo`.

#### [sonatype-2026-005086](https://guide.sonatype.com/vulnerability/sonatype-2026-005086)
- **Severity**: High  
- **Published**: Jul 25, 2026  
- **Description**: libp2p - Uncontrolled Resource Consumption.

#### [sonatype-2026-005085](https://guide.sonatype.com/vulnerability/sonatype-2026-005085)
- **Severity**: Medium  
- **Published**: Jul 25, 2026  
- **Description**: @frontmcp/adapters - Server-Side Request Forgery (SSRF).

#### [sonatype-2026-005084](https://guide.sonatype.com/vulnerability/sonatype-2026-005084)
- **Severity**: High  
- **Published**: Jul 25, 2026  
- **Description**: @anephenix/hub - Uncontrolled Resource Consumption.

#### [sonatype-2026-005083](https://guide.sonatype.com/vulnerability/sonatype-2026-005083)
- **Severity**: High  
- **Published**: Jul 25, 2026  
- **Description**: @budibase/server - Improper Authorization.

#### [sonatype-2026-005082](https://guide.sonatype.com/vulnerability/sonatype-2026-005082)
- **Severity**: High  
- **Published**: Jul 25, 2026  
- **Description**: @budibase/server - SQL Injection.

#### [sonatype-2026-005081](https://guide.sonatype.com/vulnerability/sonatype-2026-005081)
- **Severity**: High  
- **Published**: Jul 25, 2026  
- **Description**: @budibase/server - Improper Privilege Management.

#### [sonatype-2026-005080](https://guide.sonatype.com/vulnerability/sonatype-2026-005080)
- **Severity**: High  
- **Published**: Jul 25, 2026  
- **Description**: @budibase/server - Exposure of Sensitive Information to an Unauthorized Actor.

#### [sonatype-2026-005079](https://guide.sonatype.com/vulnerability/sonatype-2026-005079)
- **Severity**: Medium  
- **Published**: Jul 25, 2026  
- **Description**: @budibase/server - Exposure of Sensitive Information to an Unauthorized Actor.

#### [sonatype-2026-005078](https://guide.sonatype.com/vulnerability/sonatype-2026-005078)
- **Severity**: High  
- **Published**: Jul 25, 2026  
- **Description**: @budibase/server - Generation of Error Message Containing Sensitive Information.

#### [sonatype-2026-005077](https://guide.sonatype.com/vulnerability/sonatype-2026-005077)
- **Severity**: High  
- **Published**: Jul 25, 2026  
- **Description**: @budibase/server - Time-of-check Time-of-use (TOCTOU) Race Condition.

#### [sonatype-2026-005076](https://guide.sonatype.com/vulnerability/sonatype-2026-005076)
- **Severity**: High  
- **Published**: Jul 25, 2026  
- **Description**: @budibase/server - Incorrect Authorization.

#### [sonatype-2026-005075](https://guide.sonatype.com/vulnerability/sonatype-2026-005075)
- **Severity**: High  
- **Published**: Jul 25, 2026  
- **Description**: @budibase/server - Server-Side Request Forgery (SSRF).

#### [sonatype-2026-005074](https://guide.sonatype.com/vulnerability/sonatype-2026-005074)
- **Severity**: Critical  
- **Published**: Jul 25, 2026  
- **Description**: @budibase/server - SQL Injection.

#### [sonatype-2026-005073](https://guide.sonatype.com/vulnerability/sonatype-2026-005073)
- **Severity**: Medium  
- **Published**: Jul 25, 2026  
- **Description**: @budibase/server - Exposure of Sensitive Information to an Unauthorized Actor.

#### [sonatype-2026-005072](https://guide.sonatype.com/vulnerability/sonatype-2026-005072)
- **Severity**: Medium  
- **Published**: Jul 25, 2026  
- **Description**: @budibase/server - Missing Authorization.

#### [sonatype-2026-005071](https://guide.sonatype.com/vulnerability/sonatype-2026-005071)
- **Severity**: Medium  
- **Published**: Jul 25, 2026  
- **Description**: @budibase/server - Server-Side Request Forgery (SSRF).

#### [sonatype-2026-005070](https://guide.sonatype.com/vulnerability/sonatype-2026-005070)
- **Severity**: Medium  
- **Published**: Jul 25, 2026  
- **Description**: @budibase/server - Observable Response Discrepancy.

#### [sonatype-2026-005069](https://guide.sonatype.com/vulnerability/sonatype-2026-005069)
- **Severity**: Critical  
- **Published**: Jul 25, 2026  
- **Description**: @budibase/server - Improper Authentication.

#### [sonatype-2026-005068](https://guide.sonatype.com/vulnerability/sonatype-2026-005068)
- **Severity**: High  
- **Published**: Jul 25, 2026  
- **Description**: @budibase/server - SQL Injection.

#### [sonatype-2026-005067](https://guide.sonatype.com/vulnerability/sonatype-2026-005067)
- **Severity**: Medium  
- **Published**: Jul 25, 2026  
- **Description**: github.com/OpenListTeam/OpenList/v4 - Exposure of Sensitive Information to an Unauthorized Actor.

#### [CVE-2026-65608](https://guide.sonatype.com/vulnerability/CVE-2026-65608)
- **Severity**: High  
- **Published**: Jul 25, 2026  
- **Description**: Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability due to improper validation of callable target functions.
