Vulnerabilities
7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-23702 | The package object-extend from 0.0.0 are vulnerable to Prototype Pollution via object-extend. The package object-extend from 0.0.0 are vulnerable to Prototype Pollution via object-extend. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2021-25945 | Prototype pollution vulnerability in 'js-extend' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution Prototype pollution vulnerability in 'js-extend' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution. NVD description · AI analysis pending | 9.8 | 3% | PoC |
| — | |
| CVE-2020-7673 | node-extend through 0.2.0 is vulnerable to Arbitrary Code Execution. node-extend through 0.2.0 is vulnerable to Arbitrary Code Execution. User input provided to the argument `A` of `extend` function`(A,B,as,isAargs)` located within `lib/extend.js` is executed by the `eval` function, resulting in code execution. NVD description · AI analysis pending | 9.8 | 3% | PoC |
| — | |
| CVE-2020-8147 | Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that may result in remote code execution or Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using utils-extend. NVD description · AI analysis pending | 9.8 | 3% | PoC |
| — | |
| CVE-2018-16492 | A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prototype. A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prototype. NVD description · AI analysis pending | 9.8 | 3% | PoC |
| — | |
| CVE-2018-16489 | A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through its functions. A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through its functions. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2018-3750 | The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can contr The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — |