NerdJS
26 credited records · 0 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-7768No exploit | The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.grpc · grpc · CWE-1321 | Critical9.8 | — | 4.2% | Nov 11, 2020 |
39Monitor | CVE-2020-7737No exploit | All versions of package safetydance are vulnerable to Prototype Pollution via the set function.safetydance project · safetydance · CWE-1321 | Critical9.8 | — | 1.4% | Oct 2, 2020 |
39Monitor | CVE-2020-7736No exploit | The package bmoor before 0.8.12 are vulnerable to Prototype Pollution via the set function.bmoor project · bmoor · CWE-1321 | Critical9.8 | — | 1.5% | Oct 2, 2020 |
40Plan | CVE-2020-7727No exploit | All versions of package gedi are vulnerable to Prototype Pollution via the set function.gedi project · gedi · CWE-1321 | Critical9.8 | — | 1.9% | Sep 1, 2020 |
40Plan | CVE-2020-7726No exploit | All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function.safe-object2 project · safe-object2 · CWE-1321 | Critical9.8 | — | 1.9% | Sep 1, 2020 |
40Plan | CVE-2020-7725No exploit | All versions of package worksmith are vulnerable to Prototype Pollution via the setValue function.guidesmiths · worksmith · CWE-1321 | Critical9.8 | — | 1.9% | Sep 1, 2020 |
40Plan | CVE-2020-7724No exploit | All versions of package tiny-conf are vulnerable to Prototype Pollution via the set function.tiny-conf project · tiny-conf · CWE-1321 | Critical9.8 | — | 1.9% | Sep 1, 2020 |
40Plan | CVE-2020-7723No exploit | All versions of package promisehelpers are vulnerable to Prototype Pollution via the insert function.yola · promisehelpers · CWE-1321 | Critical9.8 | — | 1.9% | Sep 1, 2020 |
40Plan | CVE-2020-7722No exploit | All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function.nodee-utils project · nodee-utils · CWE-1321 | Critical9.8 | — | 1.9% | Sep 1, 2020 |
40Plan | CVE-2020-7721No exploit | All versions of package node-oojs are vulnerable to Prototype Pollution via the setPath function.node-oojs project · node-oojs · CWE-1321 | Critical9.8 | — | 1.9% | Sep 1, 2020 |
30Monitor | CVE-2020-7720No exploit | The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function.digitalbazaar · forge · CWE-1321 | High7.3 | — | 3.2% | Sep 1, 2020 |
40Plan | CVE-2020-7719No exploit | Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.locutus · locutus · CWE-1321 | Critical9.8 | — | 2.8% | Sep 1, 2020 |
40Plan | CVE-2020-7718No exploit | All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions.gammautils project · gammautils · CWE-1321 | Critical9.8 | — | 1.9% | Sep 1, 2020 |
40Plan | CVE-2020-7717No exploit | All versions of package dot-notes are vulnerable to Prototype Pollution via the create function.dot-notes project · dot-notes · CWE-1321 | Critical9.8 | — | 1.9% | Sep 1, 2020 |
40Plan | CVE-2020-7716No exploit | All versions of package deeps are vulnerable to Prototype Pollution via the set function.invertase · deeps · CWE-1321 | Critical9.8 | — | 1.9% | Sep 1, 2020 |
40Plan | CVE-2020-7715No exploit | All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function.deep-get-set project · deep-get-set · CWE-1321 | Critical9.8 | — | 2.0% | Sep 1, 2020 |
40Plan | CVE-2020-7714No exploit | All versions of package confucious are vulnerable to Prototype Pollution via the set function.realseriousgames · confucious · CWE-1321 | Critical9.8 | — | 1.9% | Sep 1, 2020 |
40Plan | CVE-2020-7713No exploit | All versions of package arr-flatten-unflatten are vulnerable to Prototype Pollution via the constructor.arr-flatten-unflatten project · arr-flatten-unflatten · CWE-1321 | Critical9.8 | — | 1.9% | Sep 1, 2020 |
40Plan | CVE-2020-7708No exploit | The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via the set, unSet, pushirrelon · \@irrelon\/path · CWE-1321 | Critical9.8 | — | 2.8% | Aug 18, 2020 |
40Plan | CVE-2020-7707No exploit | The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.property-expr project · property-expr · CWE-1321 | Critical9.8 | — | 3.4% | Aug 18, 2020 |
40Plan | CVE-2020-7706No exploit | The package connie-lang before 0.1.1 are vulnerable to Prototype Pollution in the configuration language library used by connie.connie-lang project · connie-lang · CWE-1321 | Critical9.8 | — | 2.8% | Aug 18, 2020 |
40Plan | CVE-2020-7704No exploit | The package linux-cmdline before 1.0.1 are vulnerable to Prototype Pollution via the constructor.linux-cmdline project · linux-cmdline · CWE-1321 | Critical9.8 | — | 2.7% | Aug 17, 2020 |
40Plan | CVE-2020-7703No exploit | All versions of package nis-utils are vulnerable to Prototype Pollution via the setValue function.nis-utils project · nis-utils · CWE-1321 | Critical9.8 | — | 1.9% | Aug 17, 2020 |
40Plan | CVE-2020-7702No exploit | All versions of package templ8 are vulnerable to Prototype Pollution via the parse function.templ8 project · templ8 · CWE-1321 | Critical9.8 | — | 1.9% | Aug 17, 2020 |
40Plan | CVE-2020-7701No exploit | madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue.springtree · madlib-object-utils · CWE-1321 | Critical9.8 | — | 2.1% | Aug 14, 2020 |
- CVE-2020-776840Plan
The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.
CriticalCVSS 9.8No exploitEPSS 4%grpc · grpcNov 11, 2020
- CVE-2020-773739Monitor
All versions of package safetydance are vulnerable to Prototype Pollution via the set function.
CriticalCVSS 9.8No exploitEPSS 1%safetydance project · safetydanceOct 2, 2020
- CVE-2020-773639Monitor
The package bmoor before 0.8.12 are vulnerable to Prototype Pollution via the set function.
CriticalCVSS 9.8No exploitEPSS 1%bmoor project · bmoorOct 2, 2020
- CVE-2020-772740Plan
All versions of package gedi are vulnerable to Prototype Pollution via the set function.
CriticalCVSS 9.8No exploitEPSS 2%gedi project · gediSep 1, 2020
- CVE-2020-772640Plan
All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function.
CriticalCVSS 9.8No exploitEPSS 2%safe-object2 project · safe-object2Sep 1, 2020
- CVE-2020-772540Plan
All versions of package worksmith are vulnerable to Prototype Pollution via the setValue function.
CriticalCVSS 9.8No exploitEPSS 2%guidesmiths · worksmithSep 1, 2020
- CVE-2020-772440Plan
All versions of package tiny-conf are vulnerable to Prototype Pollution via the set function.
CriticalCVSS 9.8No exploitEPSS 2%tiny-conf project · tiny-confSep 1, 2020
- CVE-2020-772340Plan
All versions of package promisehelpers are vulnerable to Prototype Pollution via the insert function.
CriticalCVSS 9.8No exploitEPSS 2%yola · promisehelpersSep 1, 2020
- CVE-2020-772240Plan
All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function.
CriticalCVSS 9.8No exploitEPSS 2%nodee-utils project · nodee-utilsSep 1, 2020
- CVE-2020-772140Plan
All versions of package node-oojs are vulnerable to Prototype Pollution via the setPath function.
CriticalCVSS 9.8No exploitEPSS 2%node-oojs project · node-oojsSep 1, 2020
- CVE-2020-772030Monitor
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function.
HighCVSS 7.3No exploitEPSS 3%digitalbazaar · forgeSep 1, 2020
- CVE-2020-771940Plan
Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.
CriticalCVSS 9.8No exploitEPSS 3%locutus · locutusSep 1, 2020
- CVE-2020-771840Plan
All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions.
CriticalCVSS 9.8No exploitEPSS 2%gammautils project · gammautilsSep 1, 2020
- CVE-2020-771740Plan
All versions of package dot-notes are vulnerable to Prototype Pollution via the create function.
CriticalCVSS 9.8No exploitEPSS 2%dot-notes project · dot-notesSep 1, 2020
- CVE-2020-771640Plan
All versions of package deeps are vulnerable to Prototype Pollution via the set function.
CriticalCVSS 9.8No exploitEPSS 2%invertase · deepsSep 1, 2020
- CVE-2020-771540Plan
All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function.
CriticalCVSS 9.8No exploitEPSS 2%deep-get-set project · deep-get-setSep 1, 2020
- CVE-2020-771440Plan
All versions of package confucious are vulnerable to Prototype Pollution via the set function.
CriticalCVSS 9.8No exploitEPSS 2%realseriousgames · confuciousSep 1, 2020
- CVE-2020-771340Plan
All versions of package arr-flatten-unflatten are vulnerable to Prototype Pollution via the constructor.
CriticalCVSS 9.8No exploitEPSS 2%arr-flatten-unflatten project · arr-flatten-unflattenSep 1, 2020
- CVE-2020-770840Plan
The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via the set, unSet, push
CriticalCVSS 9.8No exploitEPSS 3%irrelon · \@irrelon\/pathAug 18, 2020
- CVE-2020-770740Plan
The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.
CriticalCVSS 9.8No exploitEPSS 3%property-expr project · property-exprAug 18, 2020
- CVE-2020-770640Plan
The package connie-lang before 0.1.1 are vulnerable to Prototype Pollution in the configuration language library used by connie.
CriticalCVSS 9.8No exploitEPSS 3%connie-lang project · connie-langAug 18, 2020
- CVE-2020-770440Plan
The package linux-cmdline before 1.0.1 are vulnerable to Prototype Pollution via the constructor.
CriticalCVSS 9.8No exploitEPSS 3%linux-cmdline project · linux-cmdlineAug 17, 2020
- CVE-2020-770340Plan
All versions of package nis-utils are vulnerable to Prototype Pollution via the setValue function.
CriticalCVSS 9.8No exploitEPSS 2%nis-utils project · nis-utilsAug 17, 2020
- CVE-2020-770240Plan
All versions of package templ8 are vulnerable to Prototype Pollution via the parse function.
CriticalCVSS 9.8No exploitEPSS 2%templ8 project · templ8Aug 17, 2020
- CVE-2020-770140Plan
madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue.
CriticalCVSS 9.8No exploitEPSS 2%springtree · madlib-object-utilsAug 14, 2020