Show filters
218 Total Results
Displaying 81-90 of 218
Sort by:
Attacker Value
Unknown
CVE-2021-23558
Disclosure Date: January 28, 2022 (last updated February 23, 2025)
The package bmoor before 0.10.1 are vulnerable to Prototype Pollution due to missing sanitization in set function. **Note:** This vulnerability derives from an incomplete fix in [CVE-2020-7736](https://security.snyk.io/vuln/SNYK-JS-BMOOR-598664)
0
Attacker Value
Unknown
CVE-2021-23460
Disclosure Date: January 21, 2022 (last updated February 23, 2025)
The package min-dash before 3.8.1 are vulnerable to Prototype Pollution via the set method due to missing enforcement of key types.
0
Attacker Value
Unknown
CVE-2021-23518
Disclosure Date: January 21, 2022 (last updated February 23, 2025)
The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using the origin path as __proto__, the attribute of the object is accessed instead of a path. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-72573
0
Attacker Value
Unknown
CVE-2021-23594
Disclosure Date: January 10, 2022 (last updated February 23, 2025)
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.
0
Attacker Value
Unknown
CVE-2021-23568
Disclosure Date: January 10, 2022 (last updated February 23, 2025)
The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive merge.
0
Attacker Value
Unknown
CVE-2021-23543
Disclosure Date: January 10, 2022 (last updated February 23, 2025)
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.
0
Attacker Value
Unknown
CVE-2021-43852
Disclosure Date: January 04, 2022 (last updated February 23, 2025)
OroPlatform is a PHP Business Application Platform. In affected versions by sending a specially crafted request, an attacker could inject properties into existing JavaScript language construct prototypes, such as objects. Later this injection may lead to JS code execution by libraries that are vulnerable to Prototype Pollution. This issue has been patched in version 4.2.8. Users unable to upgrade may configure a firewall to drop requests containing next strings: `__proto__` , `constructor[prototype]`, and `constructor.prototype` to mitigate this issue.
0
Attacker Value
Unknown
CVE-2021-23574
Disclosure Date: December 24, 2021 (last updated February 23, 2025)
All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions. This is an incomplete fix of [CVE-2020-28442](https://snyk.io/vuln/SNYK-JS-JSDATA-1023655).
0
Attacker Value
Unknown
CVE-2021-23450
Disclosure Date: December 17, 2021 (last updated February 23, 2025)
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
0
Attacker Value
Unknown
CVE-2021-23561
Disclosure Date: December 10, 2021 (last updated February 23, 2025)
All versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function.
0