• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-1321

CVE-2020-7727

February 26, 2023 by

All versions of package gedi are vulnerable to Prototype Pollution via the set function.

CVE-2020-7736

February 26, 2023 by

The package bmoor before 0.8.12 are vulnerable to Prototype Pollution via the set function.

CVE-2020-7737

February 26, 2023 by

All versions of package safetydance are vulnerable to Prototype Pollution via the set function.

CVE-2020-7743

February 26, 2023 by

The package mathjs before 7.5.1 are vulnerable to Prototype Pollution via the deepExtend function that runs upon configuration updates.

CVE-2020-7746

February 26, 2023 by

This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing options (or the defaults options) are deeply merged with provided options. However, during this operation, the keys of the object being set are not checked, leading to a prototype pollution.

CVE-2020-7748

February 26, 2023 by

This affects the package @tsed/core before 5.65.7. This vulnerability relates to the deepExtend function which is used as part of the utils directory. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.

  • « Go to Previous Page
  • Go to page 1
  • Go to page 2
  • Go to page 3
  • Go to page 4
  • Go to page 5
  • Go to page 6
  • Interim pages omitted …
  • Go to page 37
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE