Vulnerability Directory

If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.

Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.

Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.

Codey gradient
Filtering by:
Severity
=
Text for Severity
Close icon
Clear Filters
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Low
Apache Log4j
Apache Log4j
Improper Certificate Validation
>= 1.0, <= 1.2.17
Jan 5, 2026
High
Apache Log4j
Apache Log4j
Code Injection
>= 1.2, <= 1.2.17
Jan 5, 2026
High
Apache Log4j
Apache Log4j
Code Injection
>= 1.2, <= 1.2.17
Jan 5, 2026
High
SnakeYAML
SnakeYAML
Remote Code Execution
>=1.0, <=1.33
Dec 18, 2025
High
Spring
Apache Kafka
Remote Code Execution
>=2.3.0 <=3.3.2
Dec 16, 2025
Medium
Spring
Apache Kafka
Inconsistent Interpretation of HTTP Requests
>=2.3.0 <=3.5.2 >=3.6.0 <=3.6.2 =3.7.0
Dec 16, 2025
High
Spring
Apache Kafka
Server-Side Request Forgery
>=3.1.0 <3.9.1
Dec 16, 2025
Medium
Spring
Apache Kafka
Incorrectly Configured Access Control
>=0.10.2.0 <3.7.2 =3.8.0
Dec 16, 2025
High
Struts
Apache Struts
Denial of Service
>=2.0.0 <=2.3.37, >=2.5.0 <=2.5.33, >=6.0.0 <6.8.0, >=7.0.0 <7.1.1, >=2.5.33-struts 2-2.5.34 <2.5.33-struts 2-2.5.38
Dec 15, 2025
High
Drupal 7
Facebook Pixel
Cross-Site Scripting
>= 7.0.0, <=7.1.1
Dec 15, 2025
Medium
Drupal 7
Flag
Cross-Site Scripting
>=7.0.0 <=7.3.9
Dec 15, 2025
High
Vuetify
Vuetify
Prototype Pollution
>=2.2.0-beta.2 <3.0.0-alpha.10
Dec 11, 2025
Medium
Vuetify
Vuetify
Cross-Site Scripting
>=2.0.0 <3.0.0
Dec 11, 2025
Medium
Drupal 7
Coffee
Cross-Site Scripting
>=7.0.0 <=7.1.4
Dec 11, 2025
High
Struts
Apache Struts
Denial of Service
>=2.0.0 <=2.3.37, >=2.5.0 <=2.5.33, >=6.0.0 <6.8.0, >=7.0.0 <7.1.1
Dec 9, 2025
Exclamation icon
No results found

Please enter a valid Vulnerability ID number or Technology name.

Sign up for the latest vulnerability alerts
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.