The number and severity of CVEs published that impact products developed by Vega over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-3323HIGH An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive information, including hashed credentials and access codes. | Apr 28, 2026 | 7.5 | 30 | NO | NO |
CVE-2025-65110CRITICAL Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Prior to versions 6.1.2 and 5.6.3, applications meeting t | Jan 5, 2026 | 9.3 | 28 | NO | NO |
CVE-2020-26296HIGH Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Vega in an npm package. In Vega before version 5.17.3 the | Dec 30, 2020 | 8.7 | 26 | NO | NO |
CVE-2023-26487MEDIUM Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs.`lassoAppend' function accepts 3 arguments and internally | Mar 4, 2023 | 6.1 | 21 | NO | NO |
CVE-2023-26486MEDIUM Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. The Vega `scale` expression function has the ability to c | Mar 4, 2023 | 6.1 | 21 | NO | NO |
CVE-2025-26619MEDIUM Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. In `vega` 5.30.0 and lower and in `vega-functions` 5.15.0 | Mar 27, 2025 | 6.1 | 18 | NO | NO |
CVE-2019-10806MEDIUM vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could be tricked into adding or modifying properties of the Object | Mar 9, 2020 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vega.
Media articles that mention a CVE ID that affects a product developed by Vega — matched by CVE ID, not by vendor name.