Varixo
4 exploits
Active since Feb 2026
Qwik < 1.19.0 - Cross-Site Scripting via Virtual Attribute Serialization
CVSS 6.1
Qwik < 1.19.0 - Open Redirect via Default Request Handler Middleware
CVSS 6.1
Qwik and Qwik City < 1.19.0 - Unauthenticated Prototype Pollution via formToObj Function
CVSS 9.3
Qwik and Qwik City < 1.19.0 - Cross-Site Request Forgery via Crafted Content-Type Header
CVSS 5.9