Vulnerabilities in Cure53

26 results
Vexday analysis

Cure53 apresenta footprint reduzido com apenas 2 CVEs registradas na base, nenhuma sob exploração ativa no momento. Não há vulnerabilidades críticas ou publicações recentes, indicando baixo risco imediato, embora a fraqueza CWE-24 (Path Traversal) demande atenção em revisões de segurança futuras.

CVE-2024-48910CRITICALDOMPurify vulnerable to tampering by prototype polutionEPSS 1.2%CVE-2024-47875CRITICALDOMPurify nesting-based mXSSEPSS 1.1%CVE-2024-45801HIGHTampering by prototype polution in DOMPurifyEPSS 0.8%CVE-2025-26791MEDIUMDOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).EPSS 0.6%CVE-2025-48050HIGHIn DOMPurify through 3.2.5 before 6bc6d60, scripts/server.js does not ensure that a pathname is located under the current working directory.EPSS 0.4%CVE-2026-49458MEDIUMDOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checksEPSS 0.4%CVE-2026-0540MEDIUMDOMPurify XSS via Missing Rawtext Elements in SAFE_FOR_XMLEPSS 0.3%CVE-2026-49978MEDIUMDOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.contentEPSS 0.3%CVE-2026-41240MEDIUMDOMPurify: FORBID_TAGS bypassed by function-based ADD_TAGS predicate (asymmetry with FORBID_ATTR fix)EPSS 0.3%CVE-2026-49459MEDIUMDOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOMEPSS 0.3%CVE-2026-47423HIGHDOMPurify XSS via `selectedcontent` re-cloneEPSS 0.3%CVE-2026-41239MEDIUMDOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM modeEPSS 0.2%CVE-2025-15599MEDIUMDOMPurify XSS via Textarea Rawtext Bypass in SAFE_FOR_XMLEPSS 0.2%CVE-2026-65899MEDIUMDOMPurify before 3.4.9 Trusted Types Policy State ContaminationEPSS 0.2%CVE-2026-41238MEDIUMDOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING FallbackEPSS 0.2%CVE-2026-65902MEDIUMDOMPurify before 3.4.7 Hook Mutation Pollution via allowedTagsEPSS 0.2%CVE-2026-65903MEDIUMDOMPurify before 3.4.0 ADD_TAGS Function Bypasses FORBID_TAGSEPSS 0.2%CVE-2026-65911MEDIUMDOMPurify before 3.4.0 XSS via ADD_ATTR/ADD_TAGS State LeakageEPSS 0.2%CVE-2026-65913MEDIUMDOMPurify before 3.3.2 Prototype Pollution via USE_PROFILESEPSS 0.2%CVE-2026-65900MEDIUMDOMPurify before 3.4.8 Template Expression Injection via RETURN_DOMEPSS 0.2%