Show filters
266 Total Results
Displaying 171-180 of 266
Sort by:
Attacker Value
Unknown

CVE-2021-25949

Disclosure Date: June 10, 2021 (last updated February 22, 2025)
Prototype pollution vulnerability in 'set-getter' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution.
Attacker Value
Unknown

CVE-2021-25948

Disclosure Date: June 10, 2021 (last updated February 22, 2025)
Prototype pollution vulnerability in 'expand-hash' versions 0.1.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
Attacker Value
Unknown

CVE-2021-25947

Disclosure Date: June 03, 2021 (last updated February 22, 2025)
Prototype pollution vulnerability in 'nestie' versions 0.0.0 through 1.0.0 allows an attacker to cause a denial of service and may lead to remote code execution.
Attacker Value
Unknown

CVE-2021-26707

Disclosure Date: June 02, 2021 (last updated February 22, 2025)
The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library.
Attacker Value
Unknown

CVE-2021-25945

Disclosure Date: May 26, 2021 (last updated February 22, 2025)
Prototype pollution vulnerability in 'js-extend' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
Attacker Value
Unknown

CVE-2021-25946

Disclosure Date: May 25, 2021 (last updated February 22, 2025)
Prototype pollution vulnerability in `nconf-toml` versions 0.0.1 through 0.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.
Attacker Value
Unknown

CVE-2021-25944

Disclosure Date: May 25, 2021 (last updated February 22, 2025)
Prototype pollution vulnerability in 'deep-defaults' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.
Attacker Value
Unknown

CVE-2021-25941

Disclosure Date: May 14, 2021 (last updated February 22, 2025)
Prototype pollution vulnerability in 'deep-override' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
Attacker Value
Unknown

CVE-2021-25943

Disclosure Date: May 14, 2021 (last updated February 22, 2025)
Prototype pollution vulnerability in '101' versions 1.0.0 through 1.6.3 allows an attacker to cause a denial of service and may lead to remote code execution.
Attacker Value
Unknown

CVE-2021-23383

Disclosure Date: May 04, 2021 (last updated February 22, 2025)
The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.