Show filters
200 Total Results
Displaying 71-80 of 200
Sort by:
Attacker Value
Unknown
CVE-2021-23450
Disclosure Date: December 17, 2021 (last updated February 23, 2025)
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
0
Attacker Value
Unknown
CVE-2021-23561
Disclosure Date: December 10, 2021 (last updated February 23, 2025)
All versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function.
0
Attacker Value
Unknown
CVE-2021-23700
Disclosure Date: December 10, 2021 (last updated February 23, 2025)
All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function.
0
Attacker Value
Unknown
CVE-2021-23663
Disclosure Date: December 10, 2021 (last updated February 23, 2025)
All versions of package sey are vulnerable to Prototype Pollution via the deepmerge() function.
0
Attacker Value
Unknown
CVE-2021-3815
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
utils.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
0
Attacker Value
Unknown
CVE-2021-43787
Disclosure Date: November 29, 2021 (last updated February 23, 2025)
Nodebb is an open source Node.js based forum software. In affected versions a prototype pollution vulnerability in the uploader module allowed a malicious user to inject arbitrary data (i.e. javascript) into the DOM, theoretically allowing for an account takeover when used in conjunction with a path traversal vulnerability disclosed at the same time as this report. The vulnerability has been patched as of v1.18.5. Users are advised to upgrade as soon as possible.
0
Attacker Value
Unknown
CVE-2021-23433
Disclosure Date: November 19, 2021 (last updated February 23, 2025)
The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in src/SearchParameters/index.jsSearchParameters._parseNumbers without any protection against prototype properties. Note that this vulnerability is only exploitable if the implementation allows users to define arbitrary search patterns.
0
Attacker Value
Unknown
CVE-2021-3918
Disclosure Date: November 13, 2021 (last updated February 23, 2025)
json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
0
Attacker Value
Unknown
CVE-2021-23452
Disclosure Date: October 20, 2021 (last updated February 23, 2025)
This affects all versions of package x-assign. The global proto object can be polluted using the __proto__ object.
0
Attacker Value
Unknown
CVE-2021-23449
Disclosure Date: October 18, 2021 (last updated February 23, 2025)
This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine.
0