Vulnerability index

Browse CVEs

122 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

React Server Dom Parcel HIGH 7.5
CVE-2026-23870

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to serv…

Fix: after 19.2.5
Fix from $1,950 2026-05-06
React HIGH 7.5
CVE-2026-23864

Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-…

Fix: 19.0.4 / 19.1.5+
Fix from $1,950 2026-01-26
React HIGH 7.5
CVE-2025-67779EPSS 20%

It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a sp…

Fix: 14.2.35 / 15.0.7+
Fix from $1,950 2025-12-12
React HIGH 7.5
CVE-2025-55184EPSS 67%

A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.…

Fix: 14.2.35 / 15.0.7+
Fix from $1,950 2025-12-11
React MEDIUM 5.3
CVE-2025-55183EPSS 64%

An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0…

Fix: 15.0.7 / 15.1.11+
Fix from $1,600 2025-12-11
React CRITICAL 10.0
CVE-2025-55182 KEVEPSS 100%

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the …

Fix: 15.0.5 / 15.1.9+
Fix from $2,300 2025-12-03
Proxygen MEDIUM 5.3
CVE-2025-55181

Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuicCoroSession which blocks the …

Fix: after 2025.12.01.00
Fix from $1,600 2025-12-02
Below MEDIUM 6.8
CVE-2025-27591

A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below…

Fix: 0.9.0+
Fix from $1,600 2025-03-11
Meta Spark Studio HIGH 7.8
CVE-2024-23347

Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that proj…

Fix: 176+
Fix from $1,950 2024-01-16
Katran HIGH 7.5
CVE-2023-49062

Katran could disclose non-initialized kernel memory as part of an IP header. The issue was present for IPv4 encapsulation and ICMP (v4) Too Big packe…

Fix: 2023-11-15+
Fix from $1,950 2023-11-28
React Devtools MEDIUM 6.5
CVE-2023-5654

The React Developer Tools extension registers a message listener with window.addEventListener('message', <listener>) in a content script that is acce…

Fix: 4.28.4+
Fix from $1,600 2023-10-19
Hermes CRITICAL 9.8
CVE-2023-23556

An error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have been used by a malicious attack…

Fix: 2023-02-02+
Fix from $2,300 2023-05-18
Hermes CRITICAL 9.8
CVE-2023-23557

An error in Hermes' algorithm for copying objects properties prior to commit a00d237346894c6067a594983be6634f4168c9ad could be used by a malicious at…

Fix: 2023-01-10+
Fix from $2,300 2023-05-18
Hermes CRITICAL 9.8
CVE-2023-25933

A type confusion bug in TypedArray prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could have been used by a malicious attacker to execute a…

Patch available
Fix from $2,300 2023-05-18
Hermes CRITICAL 9.8
CVE-2023-28081

A bytecode optimization bug in Hermes prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could be used to cause an use-after-free and obtain ar…

Patch available
Fix from $2,300 2023-05-18
Netconsd CRITICAL 9.8
CVE-2023-28753

netconsd prior to v0.2 was vulnerable to an integer overflow in its parse_packet function. A malicious individual could leverage this overflow to cre…

Patch available
Fix from $2,300 2023-05-18
Hermes CRITICAL 9.8
CVE-2023-30470

A use-after-free related to unsound inference in the bytecode generation when optimizations are enabled for Hermes prior to commit da8990f737ebb9d981…

Patch available
Fix from $2,300 2023-05-18
Fizz HIGH 7.5
CVE-2023-23759

There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. This behavior requires the clie…

Fix: 2023.01.30.00+
Fix from $1,950 2023-05-18
Hermes HIGH 7.5
CVE-2023-24832

A null pointer dereference bug in Hermes prior to commit 5cae9f72975cf0e5a62b27fdd8b01f103e198708 could have been used by an attacker to crash an Her…

Fix: 2023-01-31+
Fix from $1,950 2023-05-18
Hermes HIGH 7.5
CVE-2023-24833

A use-after-free in BigIntPrimitive addition in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have been used by an attacker t…

Fix: 2023-02-02+
Fix from $1,950 2023-05-18
Hhvm CRITICAL 9.8
CVE-2022-36937

HHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in the stream extension. TLS1.0 has numerous publish…

Fix: 4.153.4 / 4.168.2+
Fix from $2,300 2023-05-10
Lexical MEDIUM 6.1
CVE-2023-30792

Anchor tag hrefs in Lexical prior to v0.10.0 would render javascript: URLs, allowing for cross-site scripting on link clicks in cases where input was…

Fix: 0.10.0+
Fix from $1,600 2023-04-29
Zstandard HIGH 7.5
CVE-2022-4899

A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.

Patch available
Fix from $1,950 2023-03-31
Redex CRITICAL 9.8
CVE-2022-36938

DexLoader function get_stringidx_fromdex() in Redex prior to commit 3b44c64 can load an out of bound address when loading the string index table, pot…

Fix: 2022-11-04+
Fix from $2,300 2022-11-11
Hermes CRITICAL 9.8
CVE-2022-35289

A write-what-where condition in hermes caused by an integer overflow, prior to commit 5b6255ae049fa4641791e47fad994e8e8c4da374 allows attackers to po…

Fix: 0.12.0+
Fix from $2,300 2022-10-11
Hermes CRITICAL 9.8
CVE-2022-40138

An integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d13adf70033237097, could have been used to perform …

Fix: 2022-09-27+
Fix from $2,300 2022-10-11
Hermes CRITICAL 9.8
CVE-2022-32234

An out of bounds write in hermes, while handling large arrays, prior to commit 06eaec767e376bfdb883d912cb15e987ddf2bda1 allows attackers to potential…

Fix: 0.12.0+
Fix from $2,300 2022-10-11
Hermes HIGH 7.5
CVE-2022-27810

It was possible to trigger an infinite recursion condition in the error handler when Hermes executed specific maliciously formed JavaScript. This con…

Fix: 0.12.0+
Fix from $1,950 2022-10-06
Messenger MEDIUM 6.5
CVE-2020-20093

The Facebook Messenger app for iOS 227.0 and prior and Android 228.1.0.10.116 and prior user interface does not properly represent URI messages to th…

Fix: after 228.1.0.10.116
Fix from $1,600 2022-03-23
Instagram MEDIUM 6.5
CVE-2020-20094

Instagram iOS 106.0 and prior and Android 107.0.0.11 and prior user interface does not properly represent URI messages to the user, which results in …

Fix: after 107.0.0.11
Fix from $1,600 2022-03-23