HeroDevs

First CVE: Jul 11, 2024Active for: 2 years
23
CVEs Published
More CVEs Published than 44% of tracked CNAs
7.7
Avg CVEs / Year
More Avg CVEs / Year than 46% of tracked CNAs
6.1
Avg CVSS Score
Higher Avg CVSS Score than 10% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by HeroDevs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 11, 2024
2 years ago
Most Recent CVE
Jun 24, 2026
29 days ago

Top CVEs

All CVEs published by HeroDevs as a CNA, regardless of affected vendor or product.

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the contex
Jun 24, 20267.634NONO
A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. Per CWE-126: Buffer Over-read https://cwe.mitre.org/data/def
Sep 8, 20258.827NONO
A critical security vulnerability exists in remote cache extensions for common build systems utilizing bucket-based remote cache (such as those using Amazon S3, Google Cloud Storag
Jun 10, 20259.427NONO
A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnera
Feb 20, 20268.226NONO
A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream while application code is writing to the response body, a race
Sep 8, 20258.126NONO
The Preset configuration https://v2.vuetifyjs.com/en/features/presets  feature of Vuetify is vulnerable to Prototype Pollution https://cheatsheetseries.owasp.org/cheatsheets/Prot
Dec 12, 20258.625NONO
A vulnerability (CVE-2025-21172) exists in msdia140.dll due to integer overflow and heap-based overflow. Per CWE-122: Heap-based Buffer Overflow, a heap overflow condition is a b
Sep 8, 20257.525NONO
Improper neutralization of the title date in the 'VDatePicker' component in Vuetify, allows unsanitized HTML to be inserted into the page. This can lead to a Cross-Site Scripting
Dec 12, 20256.322NONO
The ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of 'k' (as computed based on step 3.2 of RFC 6979 https://datatracker.ietf.org/
Jan 8, 20265.621NONO
A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute
Jul 11, 20246.421NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA23 CVEs
Severity distribution among all CVEs352,101 CVEs
LowMediumHighCritical
Attack Vector
Local1 (4.3%)
Network22 (95.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (52.2%)
High11 (47.8%)
Unknown0 (0.0%)
User Interaction
None13 (56.5%)
Unknown0 (0.0%)
Required10 (43.5%)
Privileges Required
Low2 (8.7%)
High0 (0.0%)
None21 (91.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by HeroDevs as a CNA.

Media Mentions

Media articles that mention a CVE ID published by HeroDevs as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs