Vulnerability Directory
If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.
Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.
Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Medium
Quarkus
io.quarkus:quarkus-oidc
Authorization Bypass
<3.39.2
Sep 17, 2026
High
Angular
Angular
Cross-Site Scripting
>=5.0.0-beta.6 <=19.2.25, >=20.0.0 <20.3.30, >=21.0.0 <21.2.22, >=22.0.0 <22.1.4
Sep 16, 2026
High
Angular
Angular
Cross-Site Scripting
>=5.0.0-beta.6 <=19.2.25, >=20.0.0 < 20.3.30, >=21.0.0 < 21.2.22, >=22.0.0 < 22.1.4
Sep 16, 2026
Medium
Angular
Angular
Information Exposure
>=16.0.0-next.7 <=19.2.25, >=20.0.0 <20.3.28, >=21.0.0 <21.2.20, >=22.0.0 <22.1.1
Sep 16, 2026
Medium
Angular
Angular
Cross-Site Scripting
<=19.2.25, >=20.0.0 <20.3.28, >=21.0.0 <21.2.20, >=22.0.0 <22.1.0
Sep 16, 2026
High
Angular
Angular
Server-Side Request Forgery
>=8.0.0-rc.0 <=19.2.25, >=20.0.0 <20.3.30, >=21.0.0 <21.2.22, >=22.0.0 <22.1.4
Sep 16, 2026
Medium
Node.js
Node.js
Improper Certificate Validation
<=26.5.0; <=24.18.0; <=22.23.1 (active lines); and the End-of-Life Node.js 12.x, 14.x, 16.x, 18.x, and 20.x lines (all versions, addressed via Node.js NES)
Sep 12, 2026
Medium
Node.js
Node.js
Incorrect Authorization
Node.js 22.x <=22.22.3; 24.x <=24.16.0; 26.x <=26.3.0
Sep 11, 2026
Low
Node.js
Node.js
Incorrect Authorization
<=22.22.3; <=24.16.0; <=26.3.0 (per upstream advisory/NVD/CNA scope; the Permission Model was introduced in Node.js 20 and remains present in the also-affected, now-EOL Node.js 20.x line, which upstream advisory does not separately name since Node.js no longer supports that line)
Sep 11, 2026
No results found
Please enter a valid Vulnerability ID number or Technology name.
