Vulnerability Directory

If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.

Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.

Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.

Codey gradient
Filtering by:
Severity
=
Text for Severity
Close icon
Clear Filters
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
High
Next.js
Next.js
Server-Side Request Forgery
URL Redirect/Open Redirect
>=12.0.0 <15.5.21, >=16.0.0 <16.2.11
Jul 24, 2026
Critical
Ingress NGINX
NGINX (ngx_http_proxy_v2_module and ngx_http_grpc_module); reaches Ingress NGINX Controller via the NGINX Open Source build compiled into the controller image
Heap-based Buffer Overflow
NGINX Open Source 1.13.10 through 1.31.1; NGINX Plus R33 through R37.0.1; Ingress NGINX Controller builds that compile against those versions, including upstream v1.15.1
Jul 23, 2026
Critical
Ingress NGINX
NGINX (script engine, map directive); reaches Ingress NGINX Controller via the NGINX Open Source build compiled into the controller image
Heap-based Buffer Overflow
NGINX Open Source 0.9.6 through 1.31.2 (map regex support introduced in 0.9.6, 2011); Ingress NGINX Controller builds that compile against those versions, including upstream v1.15.1
Jul 23, 2026
Medium
Ingress NGINX
NGINX (ngx_http_charset_module); reaches Ingress NGINX Controller via the NGINX Open Source build compiled into the controller image
Buffer Over-read
Information Disclosure
NGINX Open Source 0.3.50 through 1.31.1; Ingress NGINX Controller builds that compile against those versions, including upstream v1.15.1
Jul 23, 2026
Medium
Drupal 7
Icon API
Cross-Site Scripting
<=7.1.0
Jul 21, 2026
High
Jetty
Eclipse Jetty
Authorization Bypass
>=9.4.0 <9.4.63, >=10.0.0 <10.0.31, >=11.0.0 <11.0.31, >=12.0.0 <12.0.36, >=12.1.0 <12.1.10
Jul 16, 2026
Medium
Jetty
Eclipse Jetty
HTTP Request Smuggling
>=9.4.0 <9.4.61, >=10.0.0 <10.0.29, >=11.0.0 <11.0.29, >=12.0.0 <12.0.35, >=12.1.0 <12.1.9
Jul 16, 2026
Low
Apache Tomcat
Apache Tomcat
Authorization Bypass
>=8.5.0 <=8.5.100, >=9.0.0.M1 <9.0.120, >=10.1.0-M1 <10.1.57, >=11.0.0-M1 <11.0.24
Jul 16, 2026
Medium
Node.js
Http Proxy Middleware
Improper Input Validation (4.16)
>=0.16.0 <2.0.10 >=3.0.0 <3.0.6 >=4.0.0 <4.1.0
Jul 14, 2026
High
Protocol Buffers
Protocol Buffers
Denial of Service
<3.25.5, >=4.0.0-RC1 <4.27.5, >=4.28.0-RC1 <4.28.2
Jul 9, 2026
High
Angular
Angular
Cross-Site Scripting
>= 22.0.0-next.0 < 22.0.1 >= 21.0.0-next.0 < 21.2.17 >= 20.0.0-next.0 < 20.3.25 <= 19.2.25
Jul 9, 2026
High
Angular
Angular
Denial of Service
>= 22.0.0-next.0 < 22.0.1 >= 21.0.0-next.0 < 21.2.17 >= 20.0.0-next.0 < 20.3.25 <= 19.2.25
Jul 9, 2026
High
Angular
Angular
Resource Injection
>= 22.0.0-next.0 < 22.0.1 >= 21.0.0-next.0 < 21.2.17 >= 20.0.0-next.0 < 20.3.25 <= 19.2.25
Jul 9, 2026
Medium
Angular
Angular
Cross-Site Scripting
>= 22.0.0-next.0 < 22.0.1 >= 21.0.0-next.0 < 21.2.17 >= 20.0.0-next.0 < 20.3.25 <= 19.2.25
Jul 8, 2026
High
Angular
Angular
Information Exposure
>= 22.0.0-next.0 < 22.0.1 >= 21.0.0-next.0 < 21.2.17 >= 20.0.0-next.0 < 20.3.25 <= 19.2.25
Jul 8, 2026
Exclamation icon
No results found

Please enter a valid Vulnerability ID number or Technology name.

Sign up for the latest vulnerability alerts
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.