Known vulnerabilities in Deno

Vendor: Deno Land
Software: Deno
Software CPE: cpe:2.3:a:deno_land:deno:*:*:*:*:*:*:*:*
Total vulnerabilities: 30
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Deno Deno is affected by 30 known vulnerabilities: 10 high, 10 medium, 10 low Critical High Medium Low

Vulnerabilities (30)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU127067 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-32260
CWE-78 High
No
No
2.7.2 23.04.2026 SB20260423130
#VU127066 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-27190
CWE-78 High
No
No
2.6.8 23.04.2026 SB20260423129
#VU127065 - Command injection
CVE-2026-22864
CWE-77 High
No
No
2.5.6 23.04.2026 SB20260423128
#VU127064 - Missing Required Cryptographic Step
CVE-2026-22863
CWE-325 High
No
No
2.6.0 23.04.2026 SB20260423127
#VU127063 - Improper Privilege Management
CVE-2025-61786
CWE-269 Low
No
No
2.2.15, 2.5.3 23.04.2026 SB20260423126
#VU127062 - Incorrect Privilege Assignment
CVE-2025-61785
CWE-266 Low
No
No
2.2.15, 2.5.3 23.04.2026 SB20260423126
#VU127061 - Command injection
CVE-2025-61787
CWE-77 High
No
No
2.2.15, 2.5.2 23.04.2026 SB20260423126
#VU127060 - Exposure of sensitive information to an unauthorized actor
CVE-2024-21486
CWE-200 Medium
No
No
2.0.0 23.04.2026 SB20260423125
#VU127059 - Improper Verification of Cryptographic Signature
CVE-2025-24015
CWE-347 High
No
No
2.1.7 23.04.2026 SB20260423124
#VU127058 - Improper Access Control
CVE-2025-48935
CWE-284 Medium
No
No
2.2.5 23.04.2026 SB20260423123
#VU127057 - Improper Access Control
CVE-2025-48934
CWE-284 Low
No
No
2.1.13 23.04.2026 SB20260423122
#VU127056 - Improper Access Control
CVE-2025-48888
CWE-284 Low
No
No
2.1.13, 2.2.13 23.04.2026 SB20260423122
#VU102418 - Exposure of sensitive information to an unauthorized actor
CVE-2025-21620
CWE-200 Low
No
No
2.1.2 07.01.2025 SB2025010747
#VU127055 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-32468
CWE-79 Low
No
No
1.42.0 25.11.2024 SB2024112552
#VU127054 - Exposure of sensitive information to an unauthorized actor
CVE-2024-37150
CWE-200 Medium
No
No
1.44.1 06.06.2024 SB2024060641
#VU127053 - Improper Access Control
CVE-2024-34346
CWE-284 Low
No
No
1.43.1 07.05.2024 SB2024050749
#VU88863 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2024-32477
CWE-362 High
No
No
1.42.2 22.04.2024 SB2024042206
#VU127052 - Improper Neutralization of Escape, Meta, or Control Sequences
CVE-2024-27936
CWE-150 Low
No
No
1.41.0 05.03.2024 SB2024030586
#VU127051 - Exposure of resource to wrong sphere
CVE-2024-27935
CWE-668 Medium
No
No
1.36.3 05.03.2024 SB2024030585
#VU127049 - Improper Resource Shutdown or Release
CVE-2024-27933
CWE-404 Low
No
No
1.39.1 05.03.2024 SB2024030584


Showing elements 1 - 20 out of 30