Vulnerability Directory

If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.

Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.

Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.

Codey gradient
Filtering by:
Severity
=
Text for Severity
Close icon
Clear Filters
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
High
Angular
Angular
Cache Poisoning
>=22.0.0-next.0 <22.0.2, >=21.0.0-next.0 <21.2.19, >=20.0.0-next.0 <20.3.27, <=19.2.25
Aug 10, 2026
High
Angular
Angular
Cross-Site Scripting
<=19.2.25, >=20.0.0-next.0 <20.3.27, >=21.0.0-next.0 <21.2.19, >=22.0.0-next.0 <22.0.1
Aug 10, 2026
High
JSON-java
Denial of Service
<=20230618
Aug 10, 2026
Medium
Spring
Spring Security
Authorization Bypass
>=4.2.0 <=4.2.20, >=5.5.0 <=5.5.8, >=5.7.0 <=5.7.24, >=5.8.0 <=5.8.26, >=6.0.0 <=6.0.8, >=6.1.0 <=6.1.9, >=6.2.0 <=6.2.8, >=6.3.0 <=6.3.17, >=6.4.0 <=6.4.17, >=6.5.0 <=6.5.10
Aug 10, 2026
High
.NET
.NET
Uncontrolled Resource Consumption
Improper Input Validation (4.16)
System.Security.Cryptography.Xml >= 6.0.0 <= 6.0.2
Aug 10, 2026
High
.NET
.NET
Improper Input Validation (4.16)
Stack-based Buffer Overflow
System.Security.Cryptography.Xml >= 6.0.0 <= 6.0.2
Aug 10, 2026
Critical
Rails
Rails
Information Exposure
activestorage < 7.2.3.2; >= 8.0, < 8.0.5.1; >= 8.1, < 8.1.3.1
Aug 10, 2026
Low
Apache Tomcat
Apache Tomcat
Incorrectly Configured Access Control
>=8.5.0 <=8.5.100, >=9.0.0.M1 <9.0.119, >=10.1.0-M1 <10.1.56, >=11.0.0-M1 <11.0.23
Aug 7, 2026
High
Hazelcast
Hazelcast Platform
Authorization Bypass
>=5.0 <=5.1.7, >=5.2.0 <5.2.5, >=5.3.0 <5.3.5
Aug 7, 2026
High
Hazelcast
Hazelcast Platform
Authorization Bypass
<=5.1.7, >=5.2.0 <5.2.5, >=5.3.0 <5.3.5
Aug 7, 2026
High
.NET
ASP.NET Core / SignalR MessagePack Protocol
Uncontrolled Resource Consumption
>= 6.0.0 <= 6.0.40 (Blazor Server) · >= 6.0.0 <= 6.0.41 (SignalR.Protocols.MessagePack)
Aug 7, 2026
High
.NET
.NET SDK
Authorization Bypass
>= 6.0.100 <= 6.0.431
Aug 7, 2026
High
.NET
.NET Desktop Runtime / Windows Presentation Foundation (WPF)
Improper Input Validation (4.16)
Heap-based Buffer Overflow
>= 6.0.0 <= 6.0.40
Aug 7, 2026
High
.NET
.NET Desktop Runtime / Windows Presentation Foundation (WPF)
Heap-based Buffer Overflow
Improper Input Validation (4.16)
>= 6.0.0 <= 6.0.40
Aug 7, 2026
High
Angular
Angular
Cross-Site Scripting
<=19.2.25, >=20.0.0-next.0 <20.3.27, >=21.0.0-next.0 <21.2.19, >=22.0.0-next.0 <22.0.7
Aug 6, 2026
Exclamation icon
No results found

Please enter a valid Vulnerability ID number or Technology name.

Sign up for the latest vulnerability alerts
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.