Vulnerability Directory
If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.
Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.
Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Medium
Spring
Micrometer (io.micrometer:micrometer-core, io.micrometer:micrometer-registry-statsd)
Content Spoofing
<=1.9.18, >=1.10.0 <=1.14.16, >=1.15.0 <=1.15.12, >=1.16.0 <=1.16.6, 1.17.0
Oct 5, 2026
Medium
Angular
Angular
Path Traversal
<=19.2.27, >=20.0.0 <20.3.36, >=21.0.0 <21.2.23, >=22.0.0 <22.1.7
Oct 5, 2026
Medium
Spring
Micrometer
Denial of Service
>=1.4.0 <=1.9.18, >=1.10.0 <=1.14.16, >=1.15.0 <=1.15.12, >=1.16.0 <=1.16.6, 1.17.0
Oct 5, 2026
Medium
Spring
Micrometer Tracing (io.micrometer:micrometer-tracing-bridge-brave)
Denial of Service
<=1.4.13, >=1.5.0 <=1.5.12, >=1.6.0 <=1.6.6, 1.7.0
Oct 5, 2026
Medium
Apache ActiveMQ Artemis
Apache ActiveMQ Artemis
Regular Expression Denial of Service
>=1.0.0 <=2.44.0, >=2.50.0 <=2.56.0
Oct 5, 2026
Critical
Apache ActiveMQ Artemis
Apache ActiveMQ Artemis
Information Exposure
>=1.0.0 <=2.44.0, >=2.50.0 <=2.56.0
Oct 5, 2026
High
Apache ActiveMQ Artemis
Apache ActiveMQ Artemis
Information Exposure
>=1.0.0 <=2.44.0, >=2.50.0 <=2.56.0
Oct 5, 2026
High
Apache ActiveMQ Artemis
Apache ActiveMQ Artemis
Authorization Bypass
>=1.0.0 <=2.44.0, >=2.50.0 <=2.56.0
Oct 5, 2026
Critical
Apache ActiveMQ Artemis
Apache ActiveMQ Artemis
Authorization Bypass
>=1.0.0 <=2.44.0, >=2.50.0 <=2.56.0
Oct 5, 2026
Critical
Apache ActiveMQ Artemis
Apache ActiveMQ Artemis
Authorization Bypass
>=1.0.0 <=2.44.0, >=2.50.0 <=2.56.0
Oct 5, 2026
Medium
Node.js
Node.js
Information Exposure
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <16.19.1 >=17.0.0 <=17.9.1 >=18.0.0 <18.14.1 >=19.0.0 <19.6.1
Oct 2, 2026
Medium
Node.js
Node.js
Buffer Over-read
>=17.0.0 <=17.9.1; >=18.0.0 <18.14.1; >=19.0.0 <19.6.1
Oct 2, 2026
Medium
Node.js
Node.js
Cryptographic Weakness
>=10.16.0 <=10.24.1; >=11.9.0 <=11.15.0; >=12.0.0 <=12.22.12; >=13.0.0 <=13.14.0; >=14.0.0 <14.20.0; >=15.0.0 <=15.14.0; >=16.0.0 <16.16.0; >=17.0.0 <=17.9.1; >=18.0.0 <18.5.0
Oct 2, 2026
High
Node.js
Node.js
Command Injection
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <14.20.0 >=15.0.0 <=15.14.0 >=16.0.0 <16.16.0 >=17.0.0 <=17.9.1 >=18.0.0 <18.5.0
Oct 2, 2026
Medium
Quarkus
Quarkus
Cross-Site Scripting
<3.27.5.3, >=3.28.0 <3.33.3.3, >=3.34.0 <3.39.5
Oct 1, 2026
No results found
Please enter a valid Vulnerability ID number or Technology name.
