Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.5
CVE-2026-56301
Nuxt 4.0.0 before 4.4.7 and 3.18.0 before 3.21.7, when running the development server (nuxt dev) on Linux, binds the vite-node IPC server to an abstr…
Nuxt
3.21.7 / 4.4.7+
MEDIUM 6.1
CVE-2026-56326
Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 contain a server-side open redirect vulnerability in navigateTo that fails to properly validat…
Nuxt
3.21.7 / 4.4.7+
MEDIUM 6.1
CVE-2026-56697
Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 accept protocol-relative paths such as //evil.com in the reloadNuxtApp function; these pass th…
Nuxt
3.21.7 / 4.4.7+
MEDIUM 6.1
CVE-2026-56698
Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 fail to validate script-capable URLs in the navigateTo open option, allowing client-side scrip…
Nuxt
3.21.7 / 4.4.7+
MEDIUM 6.1
CVE-2026-56317
Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot content…
Nuxt
3.21.7 / 4.4.7+
HIGH 8.2
CVE-2026-53721
Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule m…
Nuxt
3.21.7 / 4.4.7+
MEDIUM 5.4
CVE-2026-53722
Nuxt is an open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, <NuxtLink> did not validate the URL scheme of values…
Nuxt
3.21.7 / 4.4.7+
MEDIUM 5.7
CVE-2026-49993
Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder from versions 3.15.4 to before 3.21.7 …
Nuxt\/rspack Builder
3.21.7 / 4.4.7+
MEDIUM 5.3
CVE-2026-47200
Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nit…
Nuxt
3.21.6 / 4.4.6+
MEDIUM 5.4
CVE-2026-45669
Nuxt is an open-source web development framework for Vue.js. From versions 3.4.3 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6, navigateTo() wit…
Nuxt
3.21.6 / 4.4.6+
MEDIUM 5.4
CVE-2026-45670
Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder versions 3.15.4 to before 3.21.6, and …
Nuxt\/rspack Builder
3.21.5 / 4.4.5+
MEDIUM 5.4
CVE-2026-46342
Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.1.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitr…
Nuxt
3.21.6 / 4.4.5+
HIGH 7.5
CVE-2026-34404
Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in old…
Og Image
6.2.5+
MEDIUM 6.1
CVE-2026-34405
Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in old…
Og Image
6.2.5+
MEDIUM 6.1
CVE-2025-52662
A vulnerability in Nuxt DevTools has been fixed in version **2.6.4***. This issue may have allowed Nuxt auth token extraction via XSS under certain c…
Devtools
2.6.4+
HIGH 7.5
CVE-2025-27415
Nuxt is an open-source web development framework for Vue.js. Prior to 3.16.0, by sending a crafted HTTP request to a server behind an CDN, it is poss…
Nuxt
3.16.0+
HIGH 8.8
CVE-2024-34344
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Due to the insufficient validation of the `p…
Nuxt
3.12.4+
HIGH 7.5
CVE-2024-42352
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. `nuxt/icon` provides an API to allow client …
Nuxt
1.4.5+
MEDIUM 6.1
CVE-2024-34343
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. The `navigateTo` function attempts to blockt…
Nuxt
3.12.4+
HIGH 8.8
CVE-2024-23657
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Nuxt Devtools is missing authentication on t…
Nuxt
1.3.9+
CRITICAL 9.8
CVE-2023-3224EPSS 59%
Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3.
Nuxt
3.4.3+
MEDIUM 6.1
CVE-2023-0878
Cross-site Scripting (XSS) - Generic in GitHub repository nuxt/framework prior to 3.2.1.
Nuxt
3.2.1+
MEDIUM 6.1
CVE-2022-4414
Cross-site Scripting (XSS) - DOM in GitHub repository nuxt/framework prior to v3.0.0-rc.13.
Framework
Patch available
MEDIUM 6.1
CVE-2022-4413
Cross-site Scripting (XSS) - Reflected in GitHub repository nuxt/framework prior to v3.0.0-rc.13.
Framework
Patch available