HeroDevs
First CVE: Jul 11, 2024Active for: 2 years
23
CVEs Published
More CVEs Published than 44% of tracked CNAs
7.7
Avg CVEs / Year
More Avg CVEs / Year than 46% of tracked CNAs
6.1
Avg CVSS Score
Higher Avg CVSS Score than 10% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by HeroDevs over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 11, 2024
2 years ago
Most Recent CVE
Jun 24, 2026
29 days ago
Top CVEs
All CVEs published by HeroDevs as a CNA, regardless of affected vendor or product.
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-11998HIGH A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the contex | Jun 24, 2026 | 7.6 | 34 | NO | NO |
CVE-2025-36855HIGH A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read.
Per CWE-126: Buffer Over-read https://cwe.mitre.org/data/def | Sep 8, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-36852CRITICAL A critical security vulnerability exists in remote cache extensions for common build systems utilizing bucket-based remote cache (such as those using Amazon S3, Google Cloud Storag | Jun 10, 2025 | 9.4 | 27 | NO | NO |
CVE-2026-2818HIGH A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnera | Feb 20, 2026 | 8.2 | 26 | NO | NO |
CVE-2025-36854HIGH A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream while application code is writing to the response body, a race | Sep 8, 2025 | 8.1 | 26 | NO | NO |
CVE-2025-8083HIGH The Preset configuration https://v2.vuetifyjs.com/en/features/presets feature of Vuetify is vulnerable to Prototype Pollution https://cheatsheetseries.owasp.org/cheatsheets/Prot | Dec 12, 2025 | 8.6 | 25 | NO | NO |
CVE-2025-36853HIGH A vulnerability (CVE-2025-21172) exists in msdia140.dll due to integer overflow and heap-based overflow.
Per CWE-122: Heap-based Buffer Overflow, a heap overflow condition is a b | Sep 8, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-8082MEDIUM Improper neutralization of the title date in the 'VDatePicker' component in Vuetify, allows unsanitized HTML to be inserted into the page. This can lead to a Cross-Site Scripting | Dec 12, 2025 | 6.3 | 22 | NO | NO |
CVE-2025-14505MEDIUM The ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of 'k' (as computed based on step 3.2 of RFC 6979 https://datatracker.ietf.org/ | Jan 8, 2026 | 5.6 | 21 | NO | NO |
CVE-2024-6485MEDIUM A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute | Jul 11, 2024 | 6.4 | 21 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA23 CVEs
61%
30%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (4.3%)
Network22 (95.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (52.2%)
High11 (47.8%)
Unknown0 (0.0%)
User Interaction
None13 (56.5%)
Unknown0 (0.0%)
Required10 (43.5%)
Privileges Required
Low2 (8.7%)
High0 (0.0%)
None21 (91.3%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (23 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by HeroDevs as a CNA.
Media Mentions
Media articles that mention a CVE ID published by HeroDevs as a CNA — matched by CVE ID, not by organization name.