Risk grade
F
100 / 100
Findings
135
0 critical17 high117 medium1 low0 info0 on CISA KEV0ATT&CK
Showing 135 of 135 findings
Findings
- Detected private-key: Identified a Private Key, which may compromise cryptographic security and sensitive data encryptionIdentified a Private Key, which may compromise cryptographic security and sensitive data encryption.gitleaks
- Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijackinggrypeCVE-2026-42264EPSS 0.7%
- Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfiggrypeCVE-2026-25639EPSS 2.5%
- Axios is vulnerable to DoS attack through lack of data size checkgrypeCVE-2025-58754EPSS 1.1%
- axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URLgrypeCVE-2025-27152EPSS 0.8%
- axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config MergegrypeCVE-2026-44495EPSS 0.5%
- axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`grypeCVE-2026-44494EPSS 1.0%
- Axios: Header Injection via Prototype PollutiongrypeCVE-2026-42035EPSS 0.4%
- Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0grypeCVE-2026-42043EPSS 0.7%
- Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request HijackinggrypeCVE-2026-42033EPSS 0.8%
- Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP AdaptergrypeCVE-2026-44487EPSS 0.7%
- Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connectiongrypeCVE-2026-44486EPSS 0.7%
- Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name InjectiongrypeCVE-2026-44496EPSS 0.6%
- PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosuregrype
- vite: `server.fs.deny` bypass on Windows alternate pathsgrypeCVE-2026-53571EPSS 0.6%
- PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure## Vulnerability Details **File**: `lib/previous-map.js` **Line**: 87-98 (`loadFile`), 129-144 (`loadMap`) ### Root Cause PostCSS auto-detects a `/*# sourceMappingURL=... */` comment inside the CSS text it is asked to parse and, unless the caller explicitly passes `map: false`…trivy
- vite: `server.fs.deny` bypass on Windows alternate pathsVite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s dev server denies direct access to sensitive files through server.fs.deny, includin…trivyCVE-2026-53571
This report is public.