Vulnerability Directory

If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.

Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.

Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.
Arrow down
Search here
Clear
Filter by Severity
Clear
Filter by Technology
Sign up for the latest vulnerability alerts
Rss feed icon
Subscribe via RSS
or
Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Critical
Next.js
Authorization Bypass
>= 11.1.4
Mar 23, 2025
High
Spring
Spring Security
Authorization Bypass
<=5.6.12, >=5.7.0 <5.7.16, >=5.8.0 <5.8.18, >=6.0.0 <=6.0.16, >=6.1.0 <6.1.14, >=6.2.0 <6.2.10, >=6.3.0 <6.3.8, >=6.4.0 <6.4.4
Mar 20, 2025
Medium
Spring
Spring for Apache Kafka
Remote Code Execution
<2.9.11, >=3.0.0 <3.0.10
Mar 3, 2025
Medium
Bootstrap
Bootstrap
Cross-Site Scripting
>=2.0.0 <=2.3.2, >=3.0.0-rc1 <3.4.1
Feb 28, 2025
Medium
Bootstrap
Bootstrap
Cross-Site Scripting
>=2.0.0 <=2.3.2, >=3.0.0-rc1 <3.4.0, >=4.0.0-alpha <4.0.0-beta.2
Feb 28, 2025
Medium
Bootstrap
Bootstrap
Cross-Site Scripting
>=2.3.0 <=2.3.2, >=3.0.0-rc1 <3.4.0, >=4.0.0-alpha <4.1.2
Feb 28, 2025
Medium
Bootstrap
Bootstrap
Cross-Site Scripting
>=2.3.0 <=2.3.2, >=3.0.0-rc1 <3.4.0, >=4.0.0-alpha <4.1.2
Feb 28, 2025
Medium
Rails
Rack
Improper Output Neutralization for Logs
<2.2.11, <3.0.12, <3.1.10
Feb 14, 2025
High
Web Essentials
IP
Server-Side Request Forgery
<=2.0.1
Jan 27, 2025
High
Web Essentials
Http Proxy Middleware
Denial of Service
<2.0.7, >=3.0.0 <3.0.3
Jan 27, 2025
High
Web Essentials
Webpack Dev Middleware
Path Traversal
<5.3.4, >=6.0.0 <6.1.2, >=7.0.0 <7.1.0
Jan 27, 2025
High
Node.js
Node.js
Use of Unmaintained Third Party
<= 21.7.3
Jan 21, 2025
High
Node.js
Node.js
Use of Unmaintained Third Party
<= 19.9.0
Jan 21, 2025
High
Node.js
Node.js
Use of Unmaintained Third Party
<= 17.9.1
Jan 21, 2025
Critical
Struts
Apache Struts
Remote Code Execution
>=2.0.0 <=2.3.37, >=2.5.0 <=2.5.33, >=6.0.0 <=6.3.0.2
Dec 17, 2024
Exclamation icon
No results found

Please enter a valid Vulnerability ID number or Technology name.