Skip to content
Noroxi

NerdJS

26 credited records · 0 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.

    CriticalCVSS 9.8No exploitEPSS 4%

    grpc · grpcNov 11, 2020

  • CVE-2020-7737
    39Monitor

    All versions of package safetydance are vulnerable to Prototype Pollution via the set function.

    CriticalCVSS 9.8No exploitEPSS 1%

    safetydance project · safetydanceOct 2, 2020

  • CVE-2020-7736
    39Monitor

    The package bmoor before 0.8.12 are vulnerable to Prototype Pollution via the set function.

    CriticalCVSS 9.8No exploitEPSS 1%

    bmoor project · bmoorOct 2, 2020

  • All versions of package gedi are vulnerable to Prototype Pollution via the set function.

    CriticalCVSS 9.8No exploitEPSS 2%

    gedi project · gediSep 1, 2020

  • All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function.

    CriticalCVSS 9.8No exploitEPSS 2%

    safe-object2 project · safe-object2Sep 1, 2020

  • All versions of package worksmith are vulnerable to Prototype Pollution via the setValue function.

    CriticalCVSS 9.8No exploitEPSS 2%

    guidesmiths · worksmithSep 1, 2020

  • All versions of package tiny-conf are vulnerable to Prototype Pollution via the set function.

    CriticalCVSS 9.8No exploitEPSS 2%

    tiny-conf project · tiny-confSep 1, 2020

  • All versions of package promisehelpers are vulnerable to Prototype Pollution via the insert function.

    CriticalCVSS 9.8No exploitEPSS 2%

    yola · promisehelpersSep 1, 2020

  • All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function.

    CriticalCVSS 9.8No exploitEPSS 2%

    nodee-utils project · nodee-utilsSep 1, 2020

  • All versions of package node-oojs are vulnerable to Prototype Pollution via the setPath function.

    CriticalCVSS 9.8No exploitEPSS 2%

    node-oojs project · node-oojsSep 1, 2020

  • CVE-2020-7720
    30Monitor

    The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function.

    HighCVSS 7.3No exploitEPSS 3%

    digitalbazaar · forgeSep 1, 2020

  • Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.

    CriticalCVSS 9.8No exploitEPSS 3%

    locutus · locutusSep 1, 2020

  • All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions.

    CriticalCVSS 9.8No exploitEPSS 2%

    gammautils project · gammautilsSep 1, 2020

  • All versions of package dot-notes are vulnerable to Prototype Pollution via the create function.

    CriticalCVSS 9.8No exploitEPSS 2%

    dot-notes project · dot-notesSep 1, 2020

  • All versions of package deeps are vulnerable to Prototype Pollution via the set function.

    CriticalCVSS 9.8No exploitEPSS 2%

    invertase · deepsSep 1, 2020

  • All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function.

    CriticalCVSS 9.8No exploitEPSS 2%

    deep-get-set project · deep-get-setSep 1, 2020

  • All versions of package confucious are vulnerable to Prototype Pollution via the set function.

    CriticalCVSS 9.8No exploitEPSS 2%

    realseriousgames · confuciousSep 1, 2020

  • All versions of package arr-flatten-unflatten are vulnerable to Prototype Pollution via the constructor.

    CriticalCVSS 9.8No exploitEPSS 2%

    arr-flatten-unflatten project · arr-flatten-unflattenSep 1, 2020

  • The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via the set, unSet, push

    CriticalCVSS 9.8No exploitEPSS 3%

    irrelon · \@irrelon\/pathAug 18, 2020

  • The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.

    CriticalCVSS 9.8No exploitEPSS 3%

    property-expr project · property-exprAug 18, 2020

  • The package connie-lang before 0.1.1 are vulnerable to Prototype Pollution in the configuration language library used by connie.

    CriticalCVSS 9.8No exploitEPSS 3%

    connie-lang project · connie-langAug 18, 2020

  • The package linux-cmdline before 1.0.1 are vulnerable to Prototype Pollution via the constructor.

    CriticalCVSS 9.8No exploitEPSS 3%

    linux-cmdline project · linux-cmdlineAug 17, 2020

  • All versions of package nis-utils are vulnerable to Prototype Pollution via the setValue function.

    CriticalCVSS 9.8No exploitEPSS 2%

    nis-utils project · nis-utilsAug 17, 2020

  • All versions of package templ8 are vulnerable to Prototype Pollution via the parse function.

    CriticalCVSS 9.8No exploitEPSS 2%

    templ8 project · templ8Aug 17, 2020

  • madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue.

    CriticalCVSS 9.8No exploitEPSS 2%

    springtree · madlib-object-utilsAug 14, 2020