Vulnerability index

Browse CVEs

122 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-23870 A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to serv… React Server Dom Parcel after 19.2.5 Fix from $1,9502026-05-06 HIGH 7.5 CVE-2026-23864 Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-… React 19.0.4 / 19.1.5+ Fix from $1,9502026-01-26 HIGH 7.5 CVE-2025-67779EPSS 20% It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a sp… React 14.2.35 / 15.0.7+ Fix from $1,9502025-12-12 HIGH 7.5 CVE-2025-55184EPSS 67% A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.… React 14.2.35 / 15.0.7+ Fix from $1,9502025-12-11 MEDIUM 5.3 CVE-2025-55183EPSS 64% An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0… React 15.0.7 / 15.1.11+ Fix from $1,6002025-12-11 CRITICAL 10.0 CVE-2025-55182 KEVEPSS 100% A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the … React 15.0.5 / 15.1.9+ Fix from $2,3002025-12-03 MEDIUM 5.3 CVE-2025-55181 Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuicCoroSession which blocks the … Proxygen after 2025.12.01.00 Fix from $1,6002025-12-02 MEDIUM 6.8 CVE-2025-27591 A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below… Below 0.9.0+ Fix from $1,6002025-03-11 HIGH 7.8 CVE-2024-23347 Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that proj… Meta Spark Studio 176+ Fix from $1,9502024-01-16 HIGH 7.5 CVE-2023-49062 Katran could disclose non-initialized kernel memory as part of an IP header. The issue was present for IPv4 encapsulation and ICMP (v4) Too Big packe… Katran 2023-11-15+ Fix from $1,9502023-11-28 MEDIUM 6.5 CVE-2023-5654 The React Developer Tools extension registers a message listener with window.addEventListener('message', <listener>) in a content script that is acce… React Devtools 4.28.4+ Fix from $1,6002023-10-19 CRITICAL 9.8 CVE-2023-23556 An error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have been used by a malicious attack… Hermes 2023-02-02+ Fix from $2,3002023-05-18 CRITICAL 9.8 CVE-2023-23557 An error in Hermes' algorithm for copying objects properties prior to commit a00d237346894c6067a594983be6634f4168c9ad could be used by a malicious at… Hermes 2023-01-10+ Fix from $2,3002023-05-18 CRITICAL 9.8 CVE-2023-25933 A type confusion bug in TypedArray prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could have been used by a malicious attacker to execute a… Hermes Patch available Fix from $2,3002023-05-18 CRITICAL 9.8 CVE-2023-28081 A bytecode optimization bug in Hermes prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could be used to cause an use-after-free and obtain ar… Hermes Patch available Fix from $2,3002023-05-18 CRITICAL 9.8 CVE-2023-28753 netconsd prior to v0.2 was vulnerable to an integer overflow in its parse_packet function. A malicious individual could leverage this overflow to cre… Netconsd Patch available Fix from $2,3002023-05-18 CRITICAL 9.8 CVE-2023-30470 A use-after-free related to unsound inference in the bytecode generation when optimizations are enabled for Hermes prior to commit da8990f737ebb9d981… Hermes Patch available Fix from $2,3002023-05-18 HIGH 7.5 CVE-2023-23759 There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. This behavior requires the clie… Fizz 2023.01.30.00+ Fix from $1,9502023-05-18 HIGH 7.5 CVE-2023-24832 A null pointer dereference bug in Hermes prior to commit 5cae9f72975cf0e5a62b27fdd8b01f103e198708 could have been used by an attacker to crash an Her… Hermes 2023-01-31+ Fix from $1,9502023-05-18 HIGH 7.5 CVE-2023-24833 A use-after-free in BigIntPrimitive addition in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have been used by an attacker t… Hermes 2023-02-02+ Fix from $1,9502023-05-18 CRITICAL 9.8 CVE-2022-36937 HHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in the stream extension. TLS1.0 has numerous publish… Hhvm 4.153.4 / 4.168.2+ Fix from $2,3002023-05-10 MEDIUM 6.1 CVE-2023-30792 Anchor tag hrefs in Lexical prior to v0.10.0 would render javascript: URLs, allowing for cross-site scripting on link clicks in cases where input was… Lexical 0.10.0+ Fix from $1,6002023-04-29 HIGH 7.5 CVE-2022-4899 A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun. Zstandard Patch available Fix from $1,9502023-03-31 CRITICAL 9.8 CVE-2022-36938 DexLoader function get_stringidx_fromdex() in Redex prior to commit 3b44c64 can load an out of bound address when loading the string index table, pot… Redex 2022-11-04+ Fix from $2,3002022-11-11 CRITICAL 9.8 CVE-2022-35289 A write-what-where condition in hermes caused by an integer overflow, prior to commit 5b6255ae049fa4641791e47fad994e8e8c4da374 allows attackers to po… Hermes 0.12.0+ Fix from $2,3002022-10-11 CRITICAL 9.8 CVE-2022-40138 An integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d13adf70033237097, could have been used to perform … Hermes 2022-09-27+ Fix from $2,3002022-10-11 CRITICAL 9.8 CVE-2022-32234 An out of bounds write in hermes, while handling large arrays, prior to commit 06eaec767e376bfdb883d912cb15e987ddf2bda1 allows attackers to potential… Hermes 0.12.0+ Fix from $2,3002022-10-11 HIGH 7.5 CVE-2022-27810 It was possible to trigger an infinite recursion condition in the error handler when Hermes executed specific maliciously formed JavaScript. This con… Hermes 0.12.0+ Fix from $1,9502022-10-06 MEDIUM 6.5 CVE-2020-20093 The Facebook Messenger app for iOS 227.0 and prior and Android 228.1.0.10.116 and prior user interface does not properly represent URI messages to th… Messenger after 228.1.0.10.116 Fix from $1,6002022-03-23 MEDIUM 6.5 CVE-2020-20094 Instagram iOS 106.0 and prior and Android 107.0.0.11 and prior user interface does not properly represent URI messages to the user, which results in … Instagram after 107.0.0.11 Fix from $1,6002022-03-23