Haxe is an open-source programming language and compiler with a focused product footprint centered on its core development toolkit and related distributions. The recorded vulnerabilities reflect a durable signal around sensitive-data handling, clustering around missing encryption protections; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Haxe over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10637HIGH haxe-dev is a cross-platform toolkit. haxe-dev downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution ( | Jun 4, 2018 | 8.1 | 23 | NO | NO |
CVE-2016-10688HIGH Haxe 3 : The Cross-Platform Toolkit (a fork from David Mouton's damoebius/haxe-npm) haxe3 downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possi | Jun 4, 2018 | 8.1 | 22 | NO | NO |
CVE-2016-10602HIGH haxe is a cross-platform toolkit haxe downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by s | Jun 1, 2018 | 8.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Haxe.
Media articles that mention a CVE ID that affects a product developed by Haxe — matched by CVE ID, not by vendor name.