Vulnerability Directory
If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.
Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.
Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Medium
Express
Express
Cross-Site Scripting
>=3.0.0-alpha1, <=3.21.2, >=4.0.0-rc1, <4.20.0, >=5.0.0-alpha.1 <5.0.0
Sep 10, 2024
High
Node.js
Node.js
Command Injection
4.0 < 18.20.4, 20.0 < 20.15.1, 22.0< 22.4.1
Sep 7, 2024
Medium
Spring
Spring Framework
Denial of Service
>=4.3.0 <=4.3.30, >=5.3.0 <5.3.38, >=6.0.0 <6.0.23, >=6.1.0 <6.1.12
Aug 27, 2024
Medium
Spring
Spring Boot
Signature Forgery
>=2.7.0 <=2.7.21, >=3.0.0 <=3.0.16, >=3.1.0 <=3.1.12, >=3.2.0 <=3.2.8, >=3.3.0 <=3.3.2
Aug 23, 2024
Medium
Node.js
Node.js
Remote Code Execution
4.0 < 18.20.4, 20 < 20.15.1, 22 < 22.4.1
Jul 9, 2024
High
Rails
Ruby on Rails Framework
Denial of Service
<=3.2.18 Only for instances using PostgreSQL
Jul 7, 2024
No results found
Please enter a valid Vulnerability ID number or Technology name.