Vulnerability Directory

If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.

Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.

Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.
Arrow down
Search here
Clear
Filter by Severity
Clear
Filter by Technology
Sign up for the latest vulnerability alerts
Rss feed icon
Subscribe via RSS
or
Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Critical
Rails
Ruby on Rails Framework
Remote Code Execution
2.2.0.0 - <=2.2.3.0 2.1.0.0 - <=2.1.4.0 2.0.0.0 - <=2.0.9.0
Dec 5, 2022
High
Spring
Spring Security
Authorization Bypass
>=5.6.0 <5.6.9, >=5.7.0 <5.7.5
Oct 31, 2022
Critical
Struts
Apache Struts
Remote Code Execution
>=2.3.0 <2.3.35, >=2.5.0 <2.5.17
Aug 18, 2022
Medium
AngularJS
AngularJS
Cross-Site Scripting
>=0.0.0
Jul 15, 2022
Critical
Rails
Ruby on Rails Framework
Remote Code Execution
7.0.0.0 - <= 7.0.2.2 6.1.0.0 - <= 6.1.4.6 6.0.0.0 - <= 6.0.4.6 5.2.0.0 - <= 5.2.6.2
May 26, 2022
Medium
Angular
Angular
Cross-Site Scripting
<=11.1.0
May 26, 2022
Medium
Spring
Spring Security
Authorization Bypass
<5.5.7, >=5.6.0 <5.6.4
May 17, 2022
High
Spring
Spring Security
Authorization Bypass
<5.4.11, >=5.5.0 <5.5.7, >=5.6.x <5.6.4
May 16, 2022
Medium
Spring
Spring Framework
Denial of Service
<5.2.22, >=5.3.0 <5.3.20
May 11, 2022
Medium
Spring
Spring Framework
Denial of Service
<5.2.22, >=5.3.0 <5.3.20
May 11, 2022
Medium
AngularJS
AngularJS
ReDoS Vulnerability
>=1.7.0
May 1, 2022
Medium
Spring
Spring Framework
Authorization Bypass
<5.2.21, >=5.3.0 <5.3.19
Apr 14, 2022
Critical
Spring
Spring Framework
Remote Code Execution
<5.2.20, >=5.3.0 <5.3.18
Apr 1, 2022
Medium
Spring
Spring Framework
Denial of Service
<5.2.20, >=5.3.0 <5.3.17
Apr 1, 2022
Low
Spring
Spring Security
Denial of Service
<5.2.9.RELEASE, >=5.3.0 <5.3.9.RELEASE, >=5.4.0 <5.4.4
Feb 19, 2021
Exclamation icon
No results found

Please enter a valid Vulnerability ID number or Technology name.