Latest CVE Feed
-
9.8
CRITICALCVE-2021-23436
This affects the package immer before 9.0.6. A type confusion vulnerability can lead to a bypass of CVE-2020-28477 when the user-provided keys used in the path parameter are arrays. In particular, this bypass is possible because the condition (p === "__pr... Read more
Affected Products : immer- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23419
This affects the package open-graph before 0.2.6. The function parse could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor payload.... Read more
Affected Products : open-graph- Published: Aug. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23452
This affects all versions of package x-assign. The global proto object can be polluted using the __proto__ object.... Read more
Affected Products : x-assign- Published: Oct. 20, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23450
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.... Read more
Affected Products : debian_linux weblogic_server communications_policy_management primavera_unifier dojo- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23402
All versions of package record-like-deep-assign are vulnerable to Prototype Pollution via the main functionality.... Read more
Affected Products : record-like-deep-assign- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23438
This affects the package mpath before 0.8.4. A type confusion vulnerability can lead to a bypass of CVE-2018-16490. In particular, the condition ignoreProperties.indexOf(parts[i]) !== -1 returns -1 if parts[i] is ['__proto__']. This is because the method ... Read more
Affected Products : mpath- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23378
This affects all versions of package picotts. If attacker-controlled user input is given to the say function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.... Read more
Affected Products : picotts- Published: Apr. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23381
This affects all versions of package killing. If attacker-controlled user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.... Read more
Affected Products : killing- Published: Apr. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23389
The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.... Read more
Affected Products : total.js- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23379
This affects all versions of package portkiller. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.... Read more
Affected Products : portkiller- Published: Apr. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23375
This affects all versions of package psnode. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.... Read more
Affected Products : psnode- Published: Apr. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23369
The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.... Read more
Affected Products : handlebars- Published: Apr. 12, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23374
This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitizatio... Read more
Affected Products : ps-visitor- Published: Apr. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23352
This affects the package madge before 4.0.1. It is possible to specify a custom Graphviz path via the graphVizPath option parameter which when the .image(), .svg() or .dot() functions are called, is executed by the childprocess.exec function.... Read more
Affected Products : madge- Published: Mar. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23373
All versions of package set-deep-prop are vulnerable to Prototype Pollution via the main functionality.... Read more
Affected Products : set-deep-prop- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23330
All versions of package launchpad are vulnerable to Command Injection via stop.... Read more
Affected Products : launchpad- Published: Feb. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-1910
yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Trojan horse file in the metadata of a remote repository.... Read more
- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-18922
It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.... Read more
- Published: Jun. 30, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-1437
Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value.... Read more
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23274
The Config UI component of TIBCO Software Inc.'s TIBCO API Exchange Gateway and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a... Read more
- Published: Mar. 23, 2021
- Modified: Nov. 21, 2024