Vulnerability Directory

If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.

Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.

Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.

Codey gradient
Filtering by:
Severity
=
Text for Severity
Close icon
Clear Filters
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
High
Apache Tomcat
Apache Tomcat
Cryptographic Weakness
>=7.0.100 <=7.0.109, >=8.5.38 <=8.5.100, >=9.0.13 <=9.0.115, >=10.0.0-M1 <=10.1.52, >=11.0.0-M1 <=11.0.18
Apr 13, 2026
Low
Apache Tomcat
Apache Tomcat
URL Redirect/Open Redirect
>=8.5.30 <=8.5.100, >=9.0.0.M23 <=9.0.115, >=10.1.0-M1 <=10.1.52, >=11.0.0-M1 <=11.0.18
Apr 13, 2026
Low
Apache Tomcat
Apache Tomcat
HTTP Request Smuggling
>=7.0.0 <=7.0.109, >=8.5.0 <=8.5.100, >=9.0.0.M1 <=9.0.115, >=10.1.0-M1 <=10.1.52, >=11.0.0-M1 <=11.0.18
Apr 13, 2026
Medium
Node.js
Node.js
Denial of Service
<20.20.2 >=22.0.0 <22.22.2 >=24.0.0 <24.14.1 >=25.0.0 <25.8.2
Apr 13, 2026
High
Jetty
jetty-jaspi
Information Exposure
>= 9.4.0 < 9.4.61, >= 10.0.0 < 10.0.29, >= 11.0.0 < 11.0.29, >= 12.0.0 < 12.0.34, >= 12.1.0 < 12.1.8
Apr 10, 2026
High
Spring
Spring Cloud Gateway
Cryptographic Weakness
4.2.0
Apr 9, 2026
Critical
Apache Derby
Command Injection
>= 10.1.1.0, < 10.14.3, >= 10.15.0.0, < 10.15.2.1, >= 10.16.0.0, < 10.16.1.2, >= 10.17.0.0, < 10.17.1.0
Apr 1, 2026
High
Drupal 7
Protected Pages
Broken Access
>=7.0.0 <=7.2.4
Mar 31, 2026
Medium
Spring
Spring Data REST
Information Exposure
>=3.5.0 <=3.5.12, >= 3.6.0 < 3.6.7, >= 3.7.0, < 3.7.3
Mar 24, 2026
Low
Spring
Spring Cloud Contract
Information Exposure
>=3.1.0 <3.1.10, >=4.0.0 <4.0.5, =4.1.0
Mar 24, 2026
Medium
Spring
Spring Cloud Config
Path Traversal
<3.1.13, >=4.1.0 <4.1.9, >=4.2.0 < 4.2.6, >=4.3.0 <4.3.2, >5.0.0 <5.0.2
Mar 24, 2026
High
Spring
Spring Security
Privilege Escalation
>= 5.7.0 < 5.7.5, < 5.6.9
Mar 24, 2026
Critical
Spring
Spring Security
Incorrectly Configured Access Control
>=4.0.2 <6.5.9, >=7.0.0 <7.0.4
Mar 20, 2026
High
Spring
Spring Boot
Authorization Bypass
>=3.4.0 <=3.4.14, >=3.5.0 <=3.5.11, >=4.0.0 <=4.0.3
Mar 20, 2026
High
Spring
Spring Boot
Authorization Bypass
>=2.0.0 <3.5.12, >=4.0.0 <4.0.4
Mar 20, 2026
Exclamation icon
No results found

Please enter a valid Vulnerability ID number or Technology name.

Sign up for the latest vulnerability alerts
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.