Vulnerability Directory

If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.

Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.

Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.

Codey gradient
Filtering by:
Severity
=
Text for Severity
Close icon
Clear Filters
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Medium
Spring
Spring Security
Authorization Bypass
<=5.7.13, >=5.8.0 <=5.8.15, >=6.0.0 <=6.0.13, >=6.1.0 <=6.1.11, >=6.2.0 <=6.2.7, >=6.3.0 <=6.3.4
Nov 19, 2024
Medium
Spring
Spring Framework
Denial of Service
<5.3.42
Nov 15, 2024
High
Spring
Spring Framework
Path Traversal
<5.3.41, >=6.0.0 <6.0.25, >=6.1.0 <6.1.14
Oct 30, 2024
Medium
Express
Express
Resource Injection
>=3.0.0-alpha1 <=3.21.2
Oct 29, 2024
Critical
Spring
Spring Security
Authorization Bypass
<5.7.13, >=5.8.0 <5.8.15, >=6.0.0 <6.0.13, >=6.1.0 <6.1.11, >=6.2.0 <6.2.7, >=6.3.0 <6.3.4
Oct 25, 2024
Low
Spring
Spring Framework
Authorization Bypass
<5.3.41, >=6.0.0 <6.0.25, >=6.1.0 <6.1.14
Oct 23, 2024
Medium
Express
Express
Resource Injection
>=3.0.0-alpha1 <=3.21.2, >=4.0.0-rc1 <4.21.1, >=5.0.0-alpha.1 <5.0.1
Oct 17, 2024
High
Node.js
Node.js
HTTP Request Smuggling
>=16.0.0 <16.20.1, >=18.0.0 <18.16.1, >=20.0.0 <20.3.1
Oct 16, 2024
Low
Node.js
Node.js
Information Exposure
>=16.0.0 <=16.20.2
Oct 15, 2024
Medium
Node.js
Node.js
Denial of Service
>=14.0.0 <=14.21.3, >=16.0.0 <=16.20.2
Oct 15, 2024
High
Next.js
Next.js
Denial of Service
<=14.2.6
Oct 14, 2024
Low
Vue 2
Vue
ReDoS Vulnerability
>=2.0.0 <3.0.0
Oct 14, 2024
High
Vue 2, Nuxt 2
Command Injection
Vue 2.6, Vue 2.7, and Nuxt 2
Oct 8, 2024
Medium
Express
Express
URL Redirect/Open Redirect
>=3.4.5 <4.0.0
Oct 3, 2024
Critical
PHP
PHP
Content Spoofing
>=8.1.0 <8.1.29, >=8.2.0 <8.2.20, >=8.3.0 <8.3.8
Sep 30, 2024
Exclamation icon
No results found

Please enter a valid Vulnerability ID number or Technology name.

Sign up for the latest vulnerability alerts
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.