Latest CVE Feed
-
9.8
CRITICALCVE-2021-23448
All versions of package config-handler are vulnerable to Prototype Pollution when loading config files.... Read more
Affected Products : config-handler- Published: Oct. 11, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-23447
This affects the package teddy before 0.5.9. A type confusion vulnerability can be used to bypass input sanitization when the model content is an array (instead of a string).... Read more
Affected Products : teddy- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-23446
The package handsontable before 10.0.0; the package handsontable from 0 and before 10.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) in Handsontable.helper.isNumeric function.... Read more
Affected Products : handsontable- Published: Sep. 29, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-23445
This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.... Read more
Affected Products : datatables.net- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23444
This affects the package jointjs before 3.4.2. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 when the user-provided keys used in the path parameter are arrays in the setByPath function.... Read more
Affected Products : jointjs- Published: Sep. 21, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-23443
This affects the package edge.js before 5.3.2. A type confusion vulnerability can be used to bypass input sanitization when the input to be rendered is an array (instead of a string or a SafeValue), even if {{ }} are used.... Read more
Affected Products : edge- Published: Sep. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23442
This affects all versions of package @cookiex/deep. The global proto object can be polluted using the __proto__ object.... Read more
Affected Products : cookiex-deep- Published: Sep. 17, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23440
This affects the package set-value before <2.0.1, >=3.0.0 <4.0.1. A type confusion vulnerability can lead to a bypass of CVE-2019-10747 when the user-provided keys used in the path parameter are arrays.... Read more
- Published: Sep. 12, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-23439
This affects the package file-upload-with-preview before 4.2.0. A file containing malicious JavaScript code in the name can be uploaded (a user needs to be tricked into uploading such a file).... Read more
- Published: Sep. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23438
This affects the package mpath before 0.8.4. A type confusion vulnerability can lead to a bypass of CVE-2018-16490. In particular, the condition ignoreProperties.indexOf(parts[i]) !== -1 returns -1 if parts[i] is ['__proto__']. This is because the method ... Read more
Affected Products : mpath- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-23437
The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.... Read more
- Published: Sep. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23436
This affects the package immer before 9.0.6. A type confusion vulnerability can lead to a bypass of CVE-2020-28477 when the user-provided keys used in the path parameter are arrays. In particular, this bypass is possible because the condition (p === "__pr... Read more
Affected Products : immer- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2021-23435
This affects the package clearance before 2.5.0. The vulnerability can be possible when users are able to set the value of session[:return_to]. If the value used for return_to contains multiple leading slashes (/////example.com) the user ends up being red... Read more
Affected Products : clearance- Published: Sep. 12, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-23434
This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the path parameter are arrays. In particular, the condition currentPath === '__proto__' returns fals... Read more
- Published: Aug. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23433
The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in src/SearchParameters/index.jsSearchParameters._parseNumbers without any protection against prototype properties. Note that this vulnera... Read more
Affected Products : algoliasearch-helper- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23432
This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge()... Read more
- Published: Aug. 24, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-23431
The package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in various forms.... Read more
- Published: Aug. 24, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-23430
All versions of package startserver are vulnerable to Directory Traversal due to missing sanitization.... Read more
Affected Products : startserver- Published: Aug. 24, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-23429
All versions of package transpile are vulnerable to Denial of Service (DoS) due to a lack of input sanitization or whitelisting, coupled with improper exception handling in the .to() function.... Read more
Affected Products : transpile- Published: Aug. 24, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23428
This affects all versions of package elFinder.NetCore. The Path.Combine(...) method is used to create an absolute file path. Due to missing sanitation of the user input and a missing check of the generated path its possible to escape the Files directory v... Read more
Affected Products : elfinder.netcore- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024