Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Prototype Pollution in parse-nested-form-data via `__proto__` in FormData field names
Prototype pollution in form-data-objectizer via bracket-notation form keys
deepobj: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
RVF: Prototype pollution in @rvf/set-get reachable via @rvf/core preprocessFormData (HTTP form data)
Velocity.js: Prototype Pollution in #set path assignment
Prototype pollution in csv parsing
Versions of the package jsondiffpatch before 0
vm2: Sandbox escape
protobufjs: Prototype injection in generated message constructors
protobufjs: Process-wide denial of service through unsafe option paths
multiparty vulnerable to Denial of Service via Prototype Pollution leading to Uncaught Exception
Prototype pollution and path traversal in i18next-http-middleware via user-controlled language and namespace parameters
Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijacking
n8n: XML Node Prototype Pollution to RCE
n8n: Prototype Pollution in XML Webhook Body Parser Leads to RCE
Evolver: Prototype Pollution via `Object.assign()` in mailbox store operations
Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
Axios: Header Injection via Prototype Pollution
Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
Showing 1 - 20 of 1,000+ results