Vulnerability Directory

If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.

Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.

Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.

Codey gradient
Filtering by:
Severity
=
Text for Severity
Close icon
Clear Filters
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Medium
Node.js
Node.js
Information Exposure
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <16.19.1 >=17.0.0 <=17.9.1 >=18.0.0 <18.14.1 >=19.0.0 <19.6.1
Oct 2, 2026
Medium
Node.js
Node.js
Buffer Over-read
>=17.0.0 <=17.9.1; >=18.0.0 <18.14.1; >=19.0.0 <19.6.1
Oct 2, 2026
Medium
Node.js
Node.js
Cryptographic Weakness
>=10.16.0 <=10.24.1; >=11.9.0 <=11.15.0; >=12.0.0 <=12.22.12; >=13.0.0 <=13.14.0; >=14.0.0 <14.20.0; >=15.0.0 <=15.14.0; >=16.0.0 <16.16.0; >=17.0.0 <=17.9.1; >=18.0.0 <18.5.0
Oct 2, 2026
High
Node.js
Node.js
Command Injection
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <14.20.0 >=15.0.0 <=15.14.0 >=16.0.0 <16.16.0 >=17.0.0 <=17.9.1 >=18.0.0 <18.5.0
Oct 2, 2026
Medium
Quarkus
Quarkus
Cross-Site Scripting
<3.27.5.3, >=3.28.0 <3.33.3.3, >=3.34.0 <3.39.5
Oct 1, 2026
High
Node.js
Node.js
Uncontrolled Resource Consumption
>=17.0.0 <17.9.1 >=18.0.0 <18.2.0
Oct 1, 2026
Medium
Node.js
Node.js
Cryptographic Weakness
>=17.0.0 <17.9.1 >=18.0.0 <18.2.0
Oct 1, 2026
High
Node.js
Node.js
Command Injection
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <14.19.3 >=15.0.0 <=15.14.0 >=16.0.0 <16.15.1 >=17.0.0 <17.9.1 >=18.0.0 <18.2.0
Oct 1, 2026
High
Node.js
Node.js
Denial of Service
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.0.0 <=10.24.1 >=11.0.0 <=11.15.0 >=12.0.0 <12.22.11 >=13.0.0 <=13.14.0 >=14.0.0 <14.19.1 >=15.0.0 <=15.14.0 >=16.0.0 <16.14.2 >=17.0.0 <17.7.2
Oct 1, 2026
High
Node.js
Node.js
Improper Link Resolution Before File Access ('Link Following')
>=12.0.0 <12.22.6 >=14.0.0 <14.17.6 >=15.0.0 <=15.14.0 >=16.0.0 <16.8.0
Oct 1, 2026
High
Node.js
Node.js
Improper Link Resolution Before File Access ('Link Following')
>=12.0.0 <12.22.6 >=14.0.0 <14.17.6 >=15.0.0 <=15.14.0 >=16.0.0 <16.8.0
Oct 1, 2026
Medium
Node.js
Node.js
Cryptographic Weakness
>=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <12.22.8 >=13.0.0 <=13.14.0 >=14.0.0 <14.19.0 >=15.0.0 <=15.14.0 >=16.0.0 <16.14.0 >=17.0.0 <17.3.0
Oct 1, 2026
High
Apache CXF
Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2)
Authorization Bypass
<3.6.12, >=4.0.0 <4.1.8, >=4.2.0 <4.2.3
Oct 1, 2026
High
Apache CXF
Apache CXF (org.apache.cxf:cxf-core)
Denial of Service
<3.5.10, >=3.6.0 <3.6.5, >=4.0.0 <4.0.6
Oct 1, 2026
Medium
Apache CXF
Apache CXF (org.apache.cxf:cxf-rt-rs-security-jose)
Denial of Service
<3.5.9, >=3.6.0 <3.6.4, >=4.0.0 <4.0.5
Oct 1, 2026
Exclamation icon
No results found

Please enter a valid Vulnerability ID number or Technology name.

Sign up for the latest vulnerability alerts
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.