Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
DOMPurify before 3.3.2 Prototype Pollution via USE_PROFILES
@nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for...in without hasOwnProperty
Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js
FreeScout vulnerable to prototype pollution in getQueryParam
CartoDB carto-api-client filters.ts addFilter prototype pollution
RobinHerbots Inputmask Internal Deep Merge Helper extend.js extendAliases prototype pollution
Feathersjs: Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__
Hey API: `buildClientParams` template: prototype chain substitution via unknown `$<slot>___proto__` key
sagold json-schema-library propertyDependencies.ts parsePropertyDependencies prototype pollution
Gestor de Oferta: Prototype pollution in @tmlmobilidade/utils setValueAtPath
Incomplete fix for CVE-2026-25754 in @adonisjs/bodyparser
DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
tamagui config.ts updateConfig prototype pollution
spencermountain compromise Public Root API extend.js nlp.extend prototype pollution
kofrasa mingo Update API updateMany prototype pollution
svgdotjs svg.js npm Package API EventTarget.on prototype pollution
tanstack db Alias Path select.ts select prototype pollution
antv layout object.js setNestedValue prototype pollution
primefaces primereact API ObjectUtils.mutateFieldData prototype pollution
Hono - Prototype Pollution via __proto__ Key in parseBody with dot Option
Showing 1 - 20 of 1,000+ results