vitejs kayıtları
vitejs üreticisine ait 16 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %6,3
- Silahlaştırılmış
- 1 · %6,3
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- 297 gün
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-346 Origin Validation Error1
- CWE-50 Path Equivalence: '//multiple/leading/slash'1
- CWE-23 Relative Path Traversal1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
16 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
79Bu hafta | CVE-2025-31125Silahlaştırılmış | Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` queryvitejs · vite · CWE-200 | Yüksek7,5 | KEV | %64,7 | 31 Mar 2025 |
52Planlayın | CVE-2025-30208Kavram kanıtı | Vite bypasses server.fs.deny when using `?raw??`vitejs · vite · CWE-200 | Yüksek7,5 | — | %74,8 | 24 Mar 2025 |
33İzleyin | CVE-2026-39363Kavram kanıtı | Vite Affected by Arbitrary File Read via Vite Dev Server WebSocketvitejs · vite · CWE-200 | Yüksek8,2 | — | %2,6 | 7 Nis 2026 |
32İzleyin | CVE-2026-39364Kavram kanıtı | Vite has a `server.fs.deny` bypass with queriesvitejs · vite · CWE-180 | Yüksek8,2 | — | %1,5 | 7 Nis 2026 |
32İzleyin | CVE-2026-53571Kavram kanıtı | Vite: `server.fs.deny` bypass on Windows alternate pathsvitejs · vite · CWE-22 | Yüksek8,2 | — | %0,6 | 22 Haz 2026 |
31İzleyin | CVE-2023-34092Kavram kanıtı | Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)vitejs · vite · CWE-50 | Yüksek7,5 | — | %3,1 | 1 Haz 2023 |
30İzleyin | CVE-2024-23331İstismar yok | Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystemvitejs · vite · CWE-178 | Yüksek7,5 | — | %0,8 | 19 Oca 2024 |
26İzleyin | CVE-2025-24010İstismar yok | Vite allows any websites to send any requests to the development server and read the responsevitejs · vite · CWE-346 | Orta6,5 | — | %0,3 | 20 Oca 2025 |
25İzleyin | CVE-2026-39365Kavram kanıtı | Vite has a Path Traversal in Optimized Deps `.map` Handlingvitejs · vite · CWE-22 | Orta6,3 | — | %1,0 | 7 Nis 2026 |
25İzleyin | CVE-2024-45812İstismar yok | DOM Clobbering gadget found in vite bundled scripts that leads to XSS in Vitevitejs · vite · CWE-79 | Orta6,4 | — | %0,6 | 17 Eyl 2024 |
24İzleyin | CVE-2025-46565Kavram kanıtı | Vite's server.fs.deny bypassed with /. for files under project rootvitejs · vite · CWE-22 | Orta6,0 | — | %1,2 | 1 May 2025 |
24İzleyin | CVE-2023-49293Kavram kanıtı | Cross-site Scripting in `server.transformIndexHtml` via URL payload in vitevitejs · vite · CWE-79 | Orta6,1 | — | %1,0 | 4 Ara 2023 |
19İzleyin | CVE-2024-45811İstismar yok | server.fs.deny bypassed when using ?import&raw in vitevitejs · vite · CWE-200 | Orta4,8 | — | %1,1 | 17 Eyl 2024 |
17İzleyin | CVE-2022-35204İstismar yok | Vitejs Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the victim's service.vitejs · vite · CWE-22 | Orta4,3 | — | %1,3 | 18 Ağu 2022 |
9İzleyin | CVE-2025-58751Kavram kanıtı | Vite middleware may serve files starting with the same name with the public directoryvitejs · vite · CWE-22 | Düşük2,3 | — | %1,2 | 8 Eyl 2025 |
9İzleyin | CVE-2025-58752İstismar yok | Vite's `server.fs` settings were not applied to HTML filesvitejs · vite · CWE-23 | Düşük2,3 | — | %0,6 | 8 Eyl 2025 |
- CVE-2025-3112579Bu hafta
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %65vitejs · vite31 Mar 2025
- CVE-2025-3020852Planlayın
Vite bypasses server.fs.deny when using `?raw??`
YüksekCVSS 7,5Kavram kanıtıEPSS %75vitejs · vite24 Mar 2025
- CVE-2026-3936333İzleyin
Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket
YüksekCVSS 8,2Kavram kanıtıEPSS %3vitejs · vite7 Nis 2026
- CVE-2026-3936432İzleyin
Vite has a `server.fs.deny` bypass with queries
YüksekCVSS 8,2Kavram kanıtıEPSS %2vitejs · vite7 Nis 2026
- CVE-2026-5357132İzleyin
Vite: `server.fs.deny` bypass on Windows alternate paths
YüksekCVSS 8,2Kavram kanıtıEPSS %1vitejs · vite22 Haz 2026
- CVE-2023-3409231İzleyin
Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)
YüksekCVSS 7,5Kavram kanıtıEPSS %3vitejs · vite1 Haz 2023
- CVE-2024-2333130İzleyin
Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem
YüksekCVSS 7,5İstismar yokEPSS %1vitejs · vite19 Oca 2024
- CVE-2025-2401026İzleyin
Vite allows any websites to send any requests to the development server and read the response
OrtaCVSS 6,5İstismar yokEPSS %0vitejs · vite20 Oca 2025
- CVE-2026-3936525İzleyin
Vite has a Path Traversal in Optimized Deps `.map` Handling
OrtaCVSS 6,3Kavram kanıtıEPSS %1vitejs · vite7 Nis 2026
- CVE-2024-4581225İzleyin
DOM Clobbering gadget found in vite bundled scripts that leads to XSS in Vite
OrtaCVSS 6,4İstismar yokEPSS %1vitejs · vite17 Eyl 2024
- CVE-2025-4656524İzleyin
Vite's server.fs.deny bypassed with /. for files under project root
OrtaCVSS 6,0Kavram kanıtıEPSS %1vitejs · vite1 May 2025
- CVE-2023-4929324İzleyin
Cross-site Scripting in `server.transformIndexHtml` via URL payload in vite
OrtaCVSS 6,1Kavram kanıtıEPSS %1vitejs · vite4 Ara 2023
- CVE-2024-4581119İzleyin
server.fs.deny bypassed when using ?import&raw in vite
OrtaCVSS 4,8İstismar yokEPSS %1vitejs · vite17 Eyl 2024
- CVE-2022-3520417İzleyin
Vitejs Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the victim's service.
OrtaCVSS 4,3İstismar yokEPSS %1vitejs · vite18 Ağu 2022
- CVE-2025-587519İzleyin
Vite middleware may serve files starting with the same name with the public directory
DüşükCVSS 2,3Kavram kanıtıEPSS %1vitejs · vite8 Eyl 2025
- CVE-2025-587529İzleyin
Vite's `server.fs` settings were not applied to HTML files
DüşükCVSS 2,3İstismar yokEPSS %1vitejs · vite8 Eyl 2025