voidzero records
5 published records for vendor voidzero.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-180 Incorrect Behavior Order: Validate Before Canonicalize1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
33Monitor | CVE-2026-39363Proof of concept | Vite Affected by Arbitrary File Read via Vite Dev Server WebSocketvitejs · vite · CWE-200 | High8.2 | — | 2.6% | Apr 7, 2026 |
33Monitor | CVE-2026-41211No exploit | `vite-plus/binding` has path traversal `downloadPackageManager()` that leads to writes outside of `VP_HOME`voidzero · vite\+ · CWE-22 | High8.4 | — | 0.4% | Apr 22, 2026 |
32Monitor | CVE-2026-39364Proof of concept | Vite has a `server.fs.deny` bypass with queriesvitejs · vite · CWE-180 | High8.2 | — | 1.5% | Apr 7, 2026 |
32Monitor | CVE-2026-53571Proof of concept | Vite: `server.fs.deny` bypass on Windows alternate pathsvitejs · vite · CWE-22 | High8.2 | — | 0.6% | Jun 22, 2026 |
25Monitor | CVE-2026-39365Proof of concept | Vite has a Path Traversal in Optimized Deps `.map` Handlingvitejs · vite · CWE-22 | Medium6.3 | — | 1.0% | Apr 7, 2026 |
- CVE-2026-3936333Monitor
Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket
HighCVSS 8.2Proof of conceptEPSS 3%vitejs · viteApr 7, 2026
- CVE-2026-4121133Monitor
`vite-plus/binding` has path traversal `downloadPackageManager()` that leads to writes outside of `VP_HOME`
HighCVSS 8.4No exploitEPSS 0%voidzero · vite\+Apr 22, 2026
- CVE-2026-3936432Monitor
Vite has a `server.fs.deny` bypass with queries
HighCVSS 8.2Proof of conceptEPSS 2%vitejs · viteApr 7, 2026
- CVE-2026-5357132Monitor
Vite: `server.fs.deny` bypass on Windows alternate paths
HighCVSS 8.2Proof of conceptEPSS 1%vitejs · viteJun 22, 2026
- CVE-2026-3936525Monitor
Vite has a Path Traversal in Optimized Deps `.map` Handling
MediumCVSS 6.3Proof of conceptEPSS 1%vitejs · viteApr 7, 2026