Записи vitejs
16 опубликованных записей вендора vitejs.
Профиль для исследователя
- Попали в KEV
- 1 · 6,3 %
- С эксплойтом
- 1 · 6,3 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- 297 дн.
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-346 Origin Validation Error1
- CWE-50 Path Equivalence: '//multiple/leading/slash'1
- CWE-23 Relative Path Traversal1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
16 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
79На этой неделе | CVE-2025-31125Готовый эксплойт | Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` queryvitejs · vite · CWE-200 | Высокая7,5 | KEV | 64,7 % | 31 мар. 2025 г. |
52В плане | CVE-2025-30208Proof of concept | Vite bypasses server.fs.deny when using `?raw??`vitejs · vite · CWE-200 | Высокая7,5 | — | 74,8 % | 24 мар. 2025 г. |
33Наблюдать | CVE-2026-39363Proof of concept | Vite Affected by Arbitrary File Read via Vite Dev Server WebSocketvitejs · vite · CWE-200 | Высокая8,2 | — | 2,6 % | 7 апр. 2026 г. |
32Наблюдать | CVE-2026-39364Proof of concept | Vite has a `server.fs.deny` bypass with queriesvitejs · vite · CWE-180 | Высокая8,2 | — | 1,5 % | 7 апр. 2026 г. |
32Наблюдать | CVE-2026-53571Proof of concept | Vite: `server.fs.deny` bypass on Windows alternate pathsvitejs · vite · CWE-22 | Высокая8,2 | — | 0,6 % | 22 июн. 2026 г. |
31Наблюдать | CVE-2023-34092Proof of concept | Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)vitejs · vite · CWE-50 | Высокая7,5 | — | 3,1 % | 1 июн. 2023 г. |
30Наблюдать | CVE-2024-23331Эксплойта нет | Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystemvitejs · vite · CWE-178 | Высокая7,5 | — | 0,8 % | 19 янв. 2024 г. |
26Наблюдать | CVE-2025-24010Эксплойта нет | Vite allows any websites to send any requests to the development server and read the responsevitejs · vite · CWE-346 | Средняя6,5 | — | 0,3 % | 20 янв. 2025 г. |
25Наблюдать | CVE-2026-39365Proof of concept | Vite has a Path Traversal in Optimized Deps `.map` Handlingvitejs · vite · CWE-22 | Средняя6,3 | — | 1,0 % | 7 апр. 2026 г. |
25Наблюдать | CVE-2024-45812Эксплойта нет | DOM Clobbering gadget found in vite bundled scripts that leads to XSS in Vitevitejs · vite · CWE-79 | Средняя6,4 | — | 0,6 % | 17 сент. 2024 г. |
24Наблюдать | CVE-2025-46565Proof of concept | Vite's server.fs.deny bypassed with /. for files under project rootvitejs · vite · CWE-22 | Средняя6,0 | — | 1,2 % | 1 мая 2025 г. |
24Наблюдать | CVE-2023-49293Proof of concept | Cross-site Scripting in `server.transformIndexHtml` via URL payload in vitevitejs · vite · CWE-79 | Средняя6,1 | — | 1,0 % | 4 дек. 2023 г. |
19Наблюдать | CVE-2024-45811Эксплойта нет | server.fs.deny bypassed when using ?import&raw in vitevitejs · vite · CWE-200 | Средняя4,8 | — | 1,1 % | 17 сент. 2024 г. |
17Наблюдать | CVE-2022-35204Эксплойта нет | Vitejs Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the victim's service.vitejs · vite · CWE-22 | Средняя4,3 | — | 1,3 % | 18 авг. 2022 г. |
9Наблюдать | CVE-2025-58751Proof of concept | Vite middleware may serve files starting with the same name with the public directoryvitejs · vite · CWE-22 | Низкая2,3 | — | 1,2 % | 8 сент. 2025 г. |
9Наблюдать | CVE-2025-58752Эксплойта нет | Vite's `server.fs` settings were not applied to HTML filesvitejs · vite · CWE-23 | Низкая2,3 | — | 0,6 % | 8 сент. 2025 г. |
- CVE-2025-3112579На этой неделе
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 65 %vitejs · vite31 мар. 2025 г.
- CVE-2025-3020852В плане
Vite bypasses server.fs.deny when using `?raw??`
ВысокаяCVSS 7,5Proof of conceptEPSS 75 %vitejs · vite24 мар. 2025 г.
- CVE-2026-3936333Наблюдать
Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket
ВысокаяCVSS 8,2Proof of conceptEPSS 3 %vitejs · vite7 апр. 2026 г.
- CVE-2026-3936432Наблюдать
Vite has a `server.fs.deny` bypass with queries
ВысокаяCVSS 8,2Proof of conceptEPSS 2 %vitejs · vite7 апр. 2026 г.
- CVE-2026-5357132Наблюдать
Vite: `server.fs.deny` bypass on Windows alternate paths
ВысокаяCVSS 8,2Proof of conceptEPSS 1 %vitejs · vite22 июн. 2026 г.
- CVE-2023-3409231Наблюдать
Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %vitejs · vite1 июн. 2023 г.
- CVE-2024-2333130Наблюдать
Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %vitejs · vite19 янв. 2024 г.
- CVE-2025-2401026Наблюдать
Vite allows any websites to send any requests to the development server and read the response
СредняяCVSS 6,5Эксплойта нетEPSS 0 %vitejs · vite20 янв. 2025 г.
- CVE-2026-3936525Наблюдать
Vite has a Path Traversal in Optimized Deps `.map` Handling
СредняяCVSS 6,3Proof of conceptEPSS 1 %vitejs · vite7 апр. 2026 г.
- CVE-2024-4581225Наблюдать
DOM Clobbering gadget found in vite bundled scripts that leads to XSS in Vite
СредняяCVSS 6,4Эксплойта нетEPSS 1 %vitejs · vite17 сент. 2024 г.
- CVE-2025-4656524Наблюдать
Vite's server.fs.deny bypassed with /. for files under project root
СредняяCVSS 6,0Proof of conceptEPSS 1 %vitejs · vite1 мая 2025 г.
- CVE-2023-4929324Наблюдать
Cross-site Scripting in `server.transformIndexHtml` via URL payload in vite
СредняяCVSS 6,1Proof of conceptEPSS 1 %vitejs · vite4 дек. 2023 г.
- CVE-2024-4581119Наблюдать
server.fs.deny bypassed when using ?import&raw in vite
СредняяCVSS 4,8Эксплойта нетEPSS 1 %vitejs · vite17 сент. 2024 г.
- CVE-2022-3520417Наблюдать
Vitejs Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the victim's service.
СредняяCVSS 4,3Эксплойта нетEPSS 1 %vitejs · vite18 авг. 2022 г.
- CVE-2025-587519Наблюдать
Vite middleware may serve files starting with the same name with the public directory
НизкаяCVSS 2,3Proof of conceptEPSS 1 %vitejs · vite8 сент. 2025 г.
- CVE-2025-587529Наблюдать
Vite's `server.fs` settings were not applied to HTML files
НизкаяCVSS 2,3Эксплойта нетEPSS 1 %vitejs · vite8 сент. 2025 г.