Show filters
101 Total Results
Displaying 1-10 of 101
Sort by:
Attacker Value
Very High
CVE-2019-0230
Disclosure Date: September 14, 2020 (last updated February 22, 2025)
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
1
Attacker Value
Unknown
CVE-2021-32736
Disclosure Date: June 30, 2021 (last updated February 22, 2025)
think-helper defines a set of helper functions for ThinkJS. In versions of think-helper prior to 1.1.3, the software receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype. The vulnerability is patched in version 1.1.3.
0
Attacker Value
Unknown
CVE-2021-23396
Disclosure Date: June 17, 2021 (last updated February 22, 2025)
All versions of package lutils are vulnerable to Prototype Pollution via the main (merge) function.
0
Attacker Value
Unknown
CVE-2020-24939
Disclosure Date: June 16, 2021 (last updated February 22, 2025)
Prototype pollution in Stampit supermixer 1.0.3 allows an attacker to modify the prototype of a base object which can vary in severity depending on the implementation.
0
Attacker Value
Unknown
CVE-2021-23395
Disclosure Date: June 15, 2021 (last updated February 22, 2025)
This affects all versions of package nedb. The library could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor.prototype payload.
0
Attacker Value
Unknown
CVE-2021-25949
Disclosure Date: June 10, 2021 (last updated February 22, 2025)
Prototype pollution vulnerability in 'set-getter' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution.
0
Attacker Value
Unknown
CVE-2021-25948
Disclosure Date: June 10, 2021 (last updated February 22, 2025)
Prototype pollution vulnerability in 'expand-hash' versions 0.1.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
0
Attacker Value
Unknown
CVE-2021-25947
Disclosure Date: June 03, 2021 (last updated February 22, 2025)
Prototype pollution vulnerability in 'nestie' versions 0.0.0 through 1.0.0 allows an attacker to cause a denial of service and may lead to remote code execution.
0
Attacker Value
Unknown
CVE-2021-26707
Disclosure Date: June 02, 2021 (last updated February 22, 2025)
The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library.
0
Attacker Value
Unknown
CVE-2021-25945
Disclosure Date: May 26, 2021 (last updated February 22, 2025)
Prototype pollution vulnerability in 'js-extend' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
0