CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA.
This affects all versions of package github.com/russellhaering/gosaml2. There is a crash on nil-pointer dereference caused by sending malformed XML signatures.
The package bestzip before 2.1.7 are vulnerable to Command Injection via the options param.
The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.
All versions of package gedi are vulnerable to Prototype Pollution via the set function.
All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function.
All versions of package worksmith are vulnerable to Prototype Pollution via the setValue function.
All versions of package tiny-conf are vulnerable to Prototype Pollution via the set function.
All versions of package promisehelpers are vulnerable to Prototype Pollution via the insert function.
All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function.
