Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vite HIGH 7.5
CVE-2026-53571

Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny ca…

Fix: 0.1.24 / 6.4.3+
Fix from $1,950 2026-06-22
Vite HIGH 7.5
CVE-2026-39363

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev serve…

Fix: after 8.0.4
Fix from $1,950 2026-04-07
Vite HIGH 7.5
CVE-2026-39364

Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by se…

Fix: after 8.0.4
Fix from $1,950 2026-04-07
Vite MEDIUM 5.3
CVE-2026-39365

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s handling of .map requests for opt…

Fix: after 8.0.4
Fix from $1,600 2026-04-07
Vite MEDIUM 5.3
CVE-2025-58751

Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the pu…

Fix: 5.4.20 / 6.3.6+
Fix from $1,600 2025-09-08
Vite MEDIUM 5.3
CVE-2025-58752

Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served reg…

Fix: 5.4.20 / 6.3.6+
Fix from $1,600 2025-09-08
Vite MEDIUM 5.3
CVE-2025-46565

Vite is a frontend tooling framework for javascript. Prior to versions 6.3.4, 6.2.7, 6.1.6, 5.4.19, and 4.5.14, the contents of files in the project …

Fix: 4.5.14 / 5.4.19+
Fix from $1,600 2025-05-01
Vite HIGH 7.5
CVE-2025-31125 KEVEPSS 59%

Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explici…

Fix: 4.5.11 / 5.4.16+
Fix from $1,950 2025-03-31
Vite HIGH 7.5
CVE-2025-30208EPSS 75%

Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies acc…

Fix: 4.5.10 / 5.4.15+
Fix from $1,950 2025-03-24
Vite MEDIUM 6.5
CVE-2025-24010

Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response d…

Fix: 4.5.5 / 5.4.12+
Fix from $1,600 2025-01-20
Vite HIGH 7.5
CVE-2024-23331

Vite is a frontend tooling framework for javascript. The Vite dev server option `server.fs.deny` can be bypassed on case-insensitive file systems usi…

Fix: 2.9.17 / 3.2.8+
Fix from $1,950 2024-01-19
Vite MEDIUM 6.1
CVE-2023-49293

Vite is a website frontend framework. When Vite's HTML transformation is invoked manually via `server.transformIndexHtml`, the original request URL i…

Fix: after 5.0.4
Fix from $1,600 2023-12-04
Vite HIGH 7.5
CVE-2023-34092

Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server Options (`server.fs.deny`) can be bypass…

Fix: 3.2.7 / 4.0.5+
Fix from $1,950 2023-06-01