Vulnerability Directory

If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.

Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.

Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.

Codey gradient
Filtering by:
Severity
=
Text for Severity
Close icon
Clear Filters
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
High
SnakeYAML
SnakeYAML
Remote Code Execution
>=1.0, <=1.33
Dec 18, 2025
High
Spring
Apache Kafka
Remote Code Execution
>=2.3.0 <=3.3.2
Dec 16, 2025
Medium
Spring
Apache Kafka
No items found.
>=2.3.0 <=3.5.2 >=3.6.0 <=3.6.2 =3.7.0
Dec 16, 2025
High
Spring
Apache Kafka
Server-Side Request Forgery
>=3.1.0 <3.9.1
Dec 16, 2025
Medium
Spring
Apache Kafka
Incorrectly Configured Access Control
>=0.10.2.0 <3.7.2 =3.8.0
Dec 16, 2025
High
Struts
Apache Struts
Denial of Service
>=2.0.0 <=2.3.37, >=2.5.0 <=2.5.33, >=6.0.0 <6.8.0, >=7.0.0 <7.1.1, >=2.5.33-struts 2-2.5.34 <2.5.33-struts 2-2.5.38
Dec 15, 2025
High
Drupal 7
Facebook Pixel
Cross-Site Scripting
>= 7.0.x <=7.1.1
Dec 15, 2025
Medium
Drupal 7
Flag
Cross-Site Scripting
>=7.0.0 <=7.3.9
Dec 15, 2025
High
Vuetify
Vuetify
Prototype Pollution
>=2.2.0-beta.2 <3.0.0-alpha.10
Dec 11, 2025
Medium
Vuetify
Vuetify
Cross-Site Scripting
>=2.0.0 <3.0.0
Dec 11, 2025
Medium
Drupal 7
Coffee
Cross-Site Scripting
>=7.0.0 <=7.1.4
Dec 11, 2025
High
Struts
Apache Struts
Denial of Service
>=2.0.0 <=2.3.37, >=2.5.0 <=2.5.33, >=6.0.0 <6.8.0, >=7.0.0 <7.1.1
Dec 9, 2025
Low
Dojo
Dojo
Cross-Site Scripting
<1.11.10, >=1.12.0 <1.12.9, >=1.13.0 <1.13.8, >=1.14.0 <1.14.7, >=1.15.0 <1.15.4, >=1.16.0 <1.16.3
Dec 3, 2025
Medium
Dojo
Dojo
Cross-Site Scripting
<1.11.10, >=1.12.0 <1.12.8, >=1.13.0 <1.13.7, >=1.14.0 <1.14.6, >=1.15.0 <1.15.3, >=1.16.0 <1.16.1
Dec 3, 2025
Medium
Dojo
Dojo
Cross-Site Scripting
<1.10.10, >=1.11.0 <1.11.6, >=1.12.0 <1.12.4, >=1.13.0 <1.13.1
Dec 3, 2025
Exclamation icon
No results found

Please enter a valid Vulnerability ID number or Technology name.

Sign up for the latest vulnerability alerts
Rss feed icon
Subscribe via RSS
or
Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.