ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-23574
All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions.

All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions. This is an incomplete fix of [CVE-2020-28442](https://snyk.io/vuln/SNYK-JS-JSDATA-1023655).

NVD description · AI analysis pending
9.82% PoC ×3
  • js-data js-data
CVE-2020-28442
All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn function.

All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn function.

NVD description · AI analysis pending
9.82% PoC ×3
  • js-data js-data