js-data records
2 published records for vendor js-data.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Attack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2021-23574No exploit | All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions.js-data · js-data · CWE-1321 | Critical9.8 | — | 2.1% | Dec 24, 2021 |
40Plan | CVE-2020-28442No exploit | All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn function.js-data · js-data | Critical9.8 | — | 2.0% | Dec 15, 2020 |
- CVE-2021-2357440Plan
All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions.
CriticalCVSS 9.8No exploitEPSS 2%js-data · js-dataDec 24, 2021
- CVE-2020-2844240Plan
All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn function.
CriticalCVSS 9.8No exploitEPSS 2%js-data · js-dataDec 15, 2020