Known Vulnerabilities for Vue-start-server by @tanstack
Listed below are 10 of the newest known vulnerabilities associated with "Vue-start-server" by "@tanstack".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-68749 json | Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthentica... | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-68173 json | In the Linux kernel, the following vulnerability has been resolved: ublk: wait on ublk_dev_ready() instead of ub->completion... | Not Provided | 2026-08-10 | 2026-08-13 |
| CVE-2026-64649 json | Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through ... | Not Provided | 2026-07-27 | 2026-07-28 |
| CVE-2026-64578 json | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate compound request size before reading Str... | Not Provided | 2026-08-05 | 2026-08-08 |
| CVE-2026-64269 json | In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in ... | Not Provided | 2026-07-25 | 2026-08-05 |
| CVE-2026-61498 json | Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoin... | Not Provided | 2026-07-13 | 2026-07-14 |
| CVE-2026-58469 json | GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string... | Not Provided | 2026-07-07 | 2026-07-08 |
| CVE-2026-58371 json | SeaweedFS before 4.30 reflects the callback query parameter verbatim into responses served with Content-Type application/java... | Not Provided | 2026-06-30 | 2026-07-14 |
| CVE-2026-56231 json | Capgo before 12.128.2 contains a broken object level authorization (BOLA) vulnerability in the POST /build/start/:jobId and P... | Not Provided | 2026-06-24 | 2026-06-25 |
| CVE-2026-55994 json | Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vul... | Not Provided | 2026-07-06 | 2026-07-06 |