Show filters
101 Total Results
Displaying 1-10 of 101
Sort by:
Attacker Value
Very High

CVE-2019-0230

Disclosure Date: September 14, 2020 (last updated February 22, 2025)
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
Attacker Value
Unknown

CVE-2021-32736

Disclosure Date: June 30, 2021 (last updated February 22, 2025)
think-helper defines a set of helper functions for ThinkJS. In versions of think-helper prior to 1.1.3, the software receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype. The vulnerability is patched in version 1.1.3.
Attacker Value
Unknown

CVE-2021-23396

Disclosure Date: June 17, 2021 (last updated February 22, 2025)
All versions of package lutils are vulnerable to Prototype Pollution via the main (merge) function.
Attacker Value
Unknown

CVE-2020-24939

Disclosure Date: June 16, 2021 (last updated February 22, 2025)
Prototype pollution in Stampit supermixer 1.0.3 allows an attacker to modify the prototype of a base object which can vary in severity depending on the implementation.
Attacker Value
Unknown

CVE-2021-23395

Disclosure Date: June 15, 2021 (last updated February 22, 2025)
This affects all versions of package nedb. The library could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor.prototype payload.
Attacker Value
Unknown

CVE-2021-25949

Disclosure Date: June 10, 2021 (last updated February 22, 2025)
Prototype pollution vulnerability in 'set-getter' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution.
Attacker Value
Unknown

CVE-2021-25948

Disclosure Date: June 10, 2021 (last updated February 22, 2025)
Prototype pollution vulnerability in 'expand-hash' versions 0.1.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
Attacker Value
Unknown

CVE-2021-25947

Disclosure Date: June 03, 2021 (last updated February 22, 2025)
Prototype pollution vulnerability in 'nestie' versions 0.0.0 through 1.0.0 allows an attacker to cause a denial of service and may lead to remote code execution.
Attacker Value
Unknown

CVE-2021-26707

Disclosure Date: June 02, 2021 (last updated February 22, 2025)
The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library.
Attacker Value
Unknown

CVE-2021-25945

Disclosure Date: May 26, 2021 (last updated February 22, 2025)
Prototype pollution vulnerability in 'js-extend' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.