Vulnerabilities
13 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-31579 | The ralphjzhang/iasset repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. The ralphjzhang/iasset repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. NVD description · AI analysis pending | 9.3 | 1% |
| — | ||
| CVE-2022-21231 | All versions of package deep-get-set are vulnerable to Prototype Pollution via the 'deep' function. All versions of package deep-get-set are vulnerable to Prototype Pollution via the 'deep' function. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7715](https://security.snyk.io/vuln/SNYK-JS-DEEPGETSET-598666) NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2022-25645 | All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if t All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path contains __proto__, constructor or protorype. By crafting a malicious object, it is possible to bypass this check and achieve prototype pollution. NVD description · AI analysis pending | 8.1 | 2% | PoC ×2 |
| — | |
| CVE-2021-23497 | This affects the package @strikeentco/set before 1.0.2. This affects the package @strikeentco/set before 1.0.2. It allows an attacker to cause a denial of service and may lead to remote code execution. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-STRIKEENTCOSET-1038821 NVD description · AI analysis pending | 9.8 | 4% | PoC |
| — | |
| CVE-2021-25952 | Prototype pollution vulnerability in ‘just-safe-set’ versions 1.0.0 through 2.2.1 allows an attacker to cause a denial of service and may lead to remote code ex Prototype pollution vulnerability in ‘just-safe-set’ versions 1.0.0 through 2.2.1 allows an attacker to cause a denial of service and may lead to remote code execution. NVD description · AI analysis pending | 9.8 | 3% | PoC |
| — | |
| CVE-2021-25915 | Prototype pollution vulnerability in 'changeset' versions 0.0.1 through 0.2.5 allows an attacker to cause a denial of service and may lead to remote code execut Prototype pollution vulnerability in 'changeset' versions 0.0.1 through 0.2.5 allows an attacker to cause a denial of service and may lead to remote code execution. NVD description · AI analysis pending | 9.8 | 4% | PoC |
| — | |
| CVE-2020-28277 | Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service and may lead to remote code execution. Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service and may lead to remote code execution. NVD description · AI analysis pending | 9.8 | 3% | PoC ×2 |
| — | |
| CVE-2020-28276 | Prototype pollution vulnerability in 'deep-set' versions 1.0.0 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution. Prototype pollution vulnerability in 'deep-set' versions 1.0.0 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution. NVD description · AI analysis pending | 9.8 | 3% | PoC ×2 |
| — | |
| CVE-2020-28267 | Prototype pollution vulnerability in '@strikeentco/set' version 1.0.0 allows attacker to cause a denial of service and may lead to remote code execution. Prototype pollution vulnerability in '@strikeentco/set' version 1.0.0 allows attacker to cause a denial of service and may lead to remote code execution. NVD description · AI analysis pending | 7.5 | 2% |
| — | ||
| CVE-2020-7715 | All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function. All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2019-15553 | An issue was discovered in the memoffset crate before 0.5.0 for Rust. An issue was discovered in the memoffset crate before 0.5.0 for Rust. offset_of and span_of can cause exposure of uninitialized memory. NVD description · AI analysis pending | 7.5 | 2% |
| — | ||
| CVE-2017-16098 | charset 1.0.0 and below are vulnerable to regular expression denial of service. charset 1.0.0 and below are vulnerable to regular expression denial of service. Input of around 50k characters is required for a slow down of around 2 seconds. Unless node was compiled using the -DHTTP_MAX_HEADER_SIZE= option the default header max length is 80kb, so the impact of the ReDoS is relatively low. NVD description · AI analysis pending | 7.5 | 2% | PoC |
| — | |
| CVE-2016-10663 | wixtoolset is a Node module wrapper around the wixtoolset binaries wixtoolset downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. wixtoolset is a Node module wrapper around the wixtoolset binaries wixtoolset downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server. NVD description · AI analysis pending | 8.1 | 2% |
| — |