NerdJS
26 записей с упоминанием · 0 за 12 месяцев · 0 в CISA KEV
Имена — свободный текст из записей CNA; один человек может встречаться в разных написаниях. Напишите нам для исправления.
Записи с упоминанием
Исследователи| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-7768Эксплойта нет | The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.grpc · grpc · CWE-1321 | Критическая9,8 | — | 4,2 % | 11 нояб. 2020 г. |
39Наблюдать | CVE-2020-7737Эксплойта нет | All versions of package safetydance are vulnerable to Prototype Pollution via the set function.safetydance project · safetydance · CWE-1321 | Критическая9,8 | — | 1,4 % | 2 окт. 2020 г. |
39Наблюдать | CVE-2020-7736Эксплойта нет | The package bmoor before 0.8.12 are vulnerable to Prototype Pollution via the set function.bmoor project · bmoor · CWE-1321 | Критическая9,8 | — | 1,5 % | 2 окт. 2020 г. |
40В плане | CVE-2020-7727Эксплойта нет | All versions of package gedi are vulnerable to Prototype Pollution via the set function.gedi project · gedi · CWE-1321 | Критическая9,8 | — | 1,9 % | 1 сент. 2020 г. |
40В плане | CVE-2020-7726Эксплойта нет | All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function.safe-object2 project · safe-object2 · CWE-1321 | Критическая9,8 | — | 1,9 % | 1 сент. 2020 г. |
40В плане | CVE-2020-7725Эксплойта нет | All versions of package worksmith are vulnerable to Prototype Pollution via the setValue function.guidesmiths · worksmith · CWE-1321 | Критическая9,8 | — | 1,9 % | 1 сент. 2020 г. |
40В плане | CVE-2020-7724Эксплойта нет | All versions of package tiny-conf are vulnerable to Prototype Pollution via the set function.tiny-conf project · tiny-conf · CWE-1321 | Критическая9,8 | — | 1,9 % | 1 сент. 2020 г. |
40В плане | CVE-2020-7723Эксплойта нет | All versions of package promisehelpers are vulnerable to Prototype Pollution via the insert function.yola · promisehelpers · CWE-1321 | Критическая9,8 | — | 1,9 % | 1 сент. 2020 г. |
40В плане | CVE-2020-7722Эксплойта нет | All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function.nodee-utils project · nodee-utils · CWE-1321 | Критическая9,8 | — | 1,9 % | 1 сент. 2020 г. |
40В плане | CVE-2020-7721Эксплойта нет | All versions of package node-oojs are vulnerable to Prototype Pollution via the setPath function.node-oojs project · node-oojs · CWE-1321 | Критическая9,8 | — | 1,9 % | 1 сент. 2020 г. |
30Наблюдать | CVE-2020-7720Эксплойта нет | The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function.digitalbazaar · forge · CWE-1321 | Высокая7,3 | — | 3,2 % | 1 сент. 2020 г. |
40В плане | CVE-2020-7719Эксплойта нет | Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.locutus · locutus · CWE-1321 | Критическая9,8 | — | 2,8 % | 1 сент. 2020 г. |
40В плане | CVE-2020-7718Эксплойта нет | All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions.gammautils project · gammautils · CWE-1321 | Критическая9,8 | — | 1,9 % | 1 сент. 2020 г. |
40В плане | CVE-2020-7717Эксплойта нет | All versions of package dot-notes are vulnerable to Prototype Pollution via the create function.dot-notes project · dot-notes · CWE-1321 | Критическая9,8 | — | 1,9 % | 1 сент. 2020 г. |
40В плане | CVE-2020-7716Эксплойта нет | All versions of package deeps are vulnerable to Prototype Pollution via the set function.invertase · deeps · CWE-1321 | Критическая9,8 | — | 1,9 % | 1 сент. 2020 г. |
40В плане | CVE-2020-7715Эксплойта нет | All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function.deep-get-set project · deep-get-set · CWE-1321 | Критическая9,8 | — | 2,0 % | 1 сент. 2020 г. |
40В плане | CVE-2020-7714Эксплойта нет | All versions of package confucious are vulnerable to Prototype Pollution via the set function.realseriousgames · confucious · CWE-1321 | Критическая9,8 | — | 1,9 % | 1 сент. 2020 г. |
40В плане | CVE-2020-7713Эксплойта нет | All versions of package arr-flatten-unflatten are vulnerable to Prototype Pollution via the constructor.arr-flatten-unflatten project · arr-flatten-unflatten · CWE-1321 | Критическая9,8 | — | 1,9 % | 1 сент. 2020 г. |
40В плане | CVE-2020-7708Эксплойта нет | The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via the set, unSet, pushirrelon · \@irrelon\/path · CWE-1321 | Критическая9,8 | — | 2,8 % | 18 авг. 2020 г. |
40В плане | CVE-2020-7707Эксплойта нет | The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.property-expr project · property-expr · CWE-1321 | Критическая9,8 | — | 3,4 % | 18 авг. 2020 г. |
40В плане | CVE-2020-7706Эксплойта нет | The package connie-lang before 0.1.1 are vulnerable to Prototype Pollution in the configuration language library used by connie.connie-lang project · connie-lang · CWE-1321 | Критическая9,8 | — | 2,8 % | 18 авг. 2020 г. |
40В плане | CVE-2020-7704Эксплойта нет | The package linux-cmdline before 1.0.1 are vulnerable to Prototype Pollution via the constructor.linux-cmdline project · linux-cmdline · CWE-1321 | Критическая9,8 | — | 2,7 % | 17 авг. 2020 г. |
40В плане | CVE-2020-7703Эксплойта нет | All versions of package nis-utils are vulnerable to Prototype Pollution via the setValue function.nis-utils project · nis-utils · CWE-1321 | Критическая9,8 | — | 1,9 % | 17 авг. 2020 г. |
40В плане | CVE-2020-7702Эксплойта нет | All versions of package templ8 are vulnerable to Prototype Pollution via the parse function.templ8 project · templ8 · CWE-1321 | Критическая9,8 | — | 1,9 % | 17 авг. 2020 г. |
40В плане | CVE-2020-7701Эксплойта нет | madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue.springtree · madlib-object-utils · CWE-1321 | Критическая9,8 | — | 2,1 % | 14 авг. 2020 г. |
- CVE-2020-776840В плане
The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %grpc · grpc11 нояб. 2020 г.
- CVE-2020-773739Наблюдать
All versions of package safetydance are vulnerable to Prototype Pollution via the set function.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %safetydance project · safetydance2 окт. 2020 г.
- CVE-2020-773639Наблюдать
The package bmoor before 0.8.12 are vulnerable to Prototype Pollution via the set function.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bmoor project · bmoor2 окт. 2020 г.
- CVE-2020-772740В плане
All versions of package gedi are vulnerable to Prototype Pollution via the set function.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %gedi project · gedi1 сент. 2020 г.
- CVE-2020-772640В плане
All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %safe-object2 project · safe-object21 сент. 2020 г.
- CVE-2020-772540В плане
All versions of package worksmith are vulnerable to Prototype Pollution via the setValue function.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %guidesmiths · worksmith1 сент. 2020 г.
- CVE-2020-772440В плане
All versions of package tiny-conf are vulnerable to Prototype Pollution via the set function.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %tiny-conf project · tiny-conf1 сент. 2020 г.
- CVE-2020-772340В плане
All versions of package promisehelpers are vulnerable to Prototype Pollution via the insert function.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %yola · promisehelpers1 сент. 2020 г.
- CVE-2020-772240В плане
All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nodee-utils project · nodee-utils1 сент. 2020 г.
- CVE-2020-772140В плане
All versions of package node-oojs are vulnerable to Prototype Pollution via the setPath function.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %node-oojs project · node-oojs1 сент. 2020 г.
- CVE-2020-772030Наблюдать
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function.
ВысокаяCVSS 7,3Эксплойта нетEPSS 3 %digitalbazaar · forge1 сент. 2020 г.
- CVE-2020-771940В плане
Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %locutus · locutus1 сент. 2020 г.
- CVE-2020-771840В плане
All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %gammautils project · gammautils1 сент. 2020 г.
- CVE-2020-771740В плане
All versions of package dot-notes are vulnerable to Prototype Pollution via the create function.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %dot-notes project · dot-notes1 сент. 2020 г.
- CVE-2020-771640В плане
All versions of package deeps are vulnerable to Prototype Pollution via the set function.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %invertase · deeps1 сент. 2020 г.
- CVE-2020-771540В плане
All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %deep-get-set project · deep-get-set1 сент. 2020 г.
- CVE-2020-771440В плане
All versions of package confucious are vulnerable to Prototype Pollution via the set function.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %realseriousgames · confucious1 сент. 2020 г.
- CVE-2020-771340В плане
All versions of package arr-flatten-unflatten are vulnerable to Prototype Pollution via the constructor.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %arr-flatten-unflatten project · arr-flatten-unflatten1 сент. 2020 г.
- CVE-2020-770840В плане
The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via the set, unSet, push
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %irrelon · \@irrelon\/path18 авг. 2020 г.
- CVE-2020-770740В плане
The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %property-expr project · property-expr18 авг. 2020 г.
- CVE-2020-770640В плане
The package connie-lang before 0.1.1 are vulnerable to Prototype Pollution in the configuration language library used by connie.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %connie-lang project · connie-lang18 авг. 2020 г.
- CVE-2020-770440В плане
The package linux-cmdline before 1.0.1 are vulnerable to Prototype Pollution via the constructor.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %linux-cmdline project · linux-cmdline17 авг. 2020 г.
- CVE-2020-770340В плане
All versions of package nis-utils are vulnerable to Prototype Pollution via the setValue function.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nis-utils project · nis-utils17 авг. 2020 г.
- CVE-2020-770240В плане
All versions of package templ8 are vulnerable to Prototype Pollution via the parse function.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %templ8 project · templ817 авг. 2020 г.
- CVE-2020-770140В плане
madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %springtree · madlib-object-utils14 авг. 2020 г.