Search Results (41077 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-23448 1 Config-handler Project 1 Config-handler 2024-11-21 6.5 Medium
All versions of package config-handler are vulnerable to Prototype Pollution when loading config files.
CVE-2021-23446 1 Handsontable 1 Handsontable 2024-11-21 7.5 High
The package handsontable before 10.0.0; the package handsontable from 0 and before 10.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) in Handsontable.helper.isNumeric function.
CVE-2021-23442 1 Cookiex-deep Project 1 Cookiex-deep 2024-11-21 8.6 High
This affects all versions of package @cookiex/deep. The global proto object can be polluted using the __proto__ object.
CVE-2021-23437 2 Fedoraproject, Python 2 Fedora, Pillow 2024-11-21 7.5 High
The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
CVE-2021-23433 1 Algolia 1 Algoliasearch-helper 2024-11-21 5.9 Medium
The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in src/SearchParameters/index.jsSearchParameters._parseNumbers without any protection against prototype properties. Note that this vulnerability is only exploitable if the implementation allows users to define arbitrary search patterns.
CVE-2021-23421 1 Merge-change Project 1 Merge-change 2024-11-21 5.6 Medium
All versions of package merge-change are vulnerable to Prototype Pollution via the utils.set function.
CVE-2021-23419 1 Open-graph Project 1 Open-graph 2024-11-21 7.3 High
This affects the package open-graph before 0.2.6. The function parse could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor payload.
CVE-2021-23417 1 Deepmergefn Project 1 Deepmergefn 2024-11-21 5.6 Medium
All versions of package deepmergefn are vulnerable to Prototype Pollution via deepMerge function.
CVE-2021-23408 1 Graphhopper 1 Graphhopper 2024-11-21 5.4 Medium
This affects the package com.graphhopper:graphhopper-web-bundle before 3.2, from 4.0-pre1 and before 4.0. The URL parser could be tricked into adding or modifying properties of Object.prototype using a constructor or __proto__ payload.
CVE-2021-23403 1 Ts-nodash Project 1 Ts-nodash 2024-11-21 7.3 High
All versions of package ts-nodash are vulnerable to Prototype Pollution via the Merge() function due to lack of validation input.
CVE-2021-23402 1 Record-like-deep-assign Project 1 Record-like-deep-assign 2024-11-21 7.3 High
All versions of package record-like-deep-assign are vulnerable to Prototype Pollution via the main functionality.
CVE-2021-23397 1 Merge Project 1 Merge 2024-11-21 5.6 Medium
All versions of package @ianwalter/merge are vulnerable to Prototype Pollution via the main (merge) function. Maintainer suggests using @generates/merger instead.
CVE-2021-23396 1 Lutils Project 1 Lutils 2024-11-21 5.6 Medium
All versions of package lutils are vulnerable to Prototype Pollution via the main (merge) function.
CVE-2021-23395 1 Nedb Project 1 Nedb 2024-11-21 7.3 High
This affects all versions of package nedb. The library could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor.prototype payload.
CVE-2021-23383 3 Handlebarsjs, Netapp, Redhat 6 Handlebars, E-series Performance Analyzer, Acm and 3 more 2024-11-21 5.6 Medium
The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.
CVE-2021-23382 2 Postcss, Redhat 4 Postcss, Acm, Openshift and 1 more 2024-11-21 5.3 Medium
The package postcss before 8.2.13 are vulnerable to Regular Expression Denial of Service (ReDoS) via getAnnotationURL() and loadAnnotation() in lib/previous-map.js. The vulnerable regexes are caused mainly by the sub-pattern \/\*\s* sourceMappingURL=(.*).
CVE-2021-23373 1 Set-deep-prop Project 1 Set-deep-prop 2024-11-21 7.5 High
All versions of package set-deep-prop are vulnerable to Prototype Pollution via the main functionality.
CVE-2021-23364 2 Browserslist Project, Redhat 3 Browserslist, Acm, Quay 2024-11-21 5.3 Medium
The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.
CVE-2021-23362 3 Npmjs, Redhat, Siemens 7 Hosted-git-info, Acm, Enterprise Linux and 4 more 2024-11-21 5.3 Medium
The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity.
CVE-2021-23354 1 Adaltas 1 Printf 2024-11-21 5.3 Medium
The package printf before 0.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex string /\%(?:\(([\w_.]+)\)|([1-9]\d*)\$)?([0 +\-\]*)(\*|\d+)?(\.)?(\*|\d+)?[hlL]?([\%bscdeEfFgGioOuxX])/g in lib/printf.js. The vulnerable regular expression has cubic worst-case time complexity.