Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

460 advisories

Loading
Prototype Pollution in @commercial/subtext High
GHSA-36c4-4r89-6whg was published for @commercial/subtext (npm) Sep 3, 2020
Improperly Controlled Modification of Object Prototype Attributes High
GHSA-6cj2-92m5-7mvp was published for think-config (npm) Aug 3, 2021
yoshino-s
Prototype Pollution in mixme High
GHSA-84p7-fh9c-6g8h was published for mixme (npm) Sep 20, 2021
Prototype Pollution in node-forge debug API. Low
GHSA-5rrq-pxf6-6jx5 was published for node-forge (npm) Jan 8, 2022
Command injection in Parse Server through prototype pollution Critical
CVE-2022-24760 was published for parse-server (npm) Mar 11, 2022
yuske cristianstaicu
musard mtrezza
yargs-parser Vulnerable to Prototype Pollution Moderate
CVE-2020-7608 was published for yargs-parser (npm) Sep 4, 2020
Prototype Pollution in algoliasearch-helper Critical
CVE-2021-23433 was published for algoliasearch-helper (npm) Nov 23, 2021
Prototype Pollution Critical
CVE-2021-25948 was published for expand-hash (npm) Jun 21, 2021
Prototype Pollution in mout High
CVE-2020-7792 was published for mout (npm) Feb 9, 2022
Prototype pollution vulnerability in js-extend Critical
CVE-2021-25945 was published for js-extend (npm) Jun 8, 2021
Prototype Pollution in set-in Critical
CVE-2022-25354 was published for set-in (npm) Mar 18, 2022
Prototype polluation in just-safe-set Critical
CVE-2021-25952 was published for just-safe-set (npm) Dec 10, 2021
Prototype Pollution in ts-nodash High
CVE-2021-23403 was published for ts-nodash (npm) Dec 10, 2021
Prototype Pollution in libnested Critical
CVE-2022-25352 was published for libnested (npm) Mar 18, 2022
Prototype Pollution in bodymen Moderate
CVE-2022-25296 was published for bodymen (npm) Mar 18, 2022
Sandbox escape in notevil and argencoders-notevil Moderate
CVE-2021-23771 was published for argencoders-notevil (npm) Mar 18, 2022
Prototype pollution in supermixer High
CVE-2020-24939 was published for supermixer (npm) Dec 10, 2021
Prototype Pollution in deepmerge-ts High
CVE-2022-24802 was published for deepmerge-ts (npm) Apr 1, 2022
Prototype Pollution in fullpage.js High
CVE-2022-1295 was published for fullpage.js (npm) Apr 12, 2022
Prototype Pollution in nconf High
CVE-2022-21803 was published for nconf (npm) Apr 13, 2022
Prototype Pollution in madlib-object-utils High
CVE-2022-24279 was published for madlib-object-utils (npm) Apr 16, 2022
Prototype Pollution in convict High
CVE-2022-22143 was published for convict (npm) Apr 20, 2022
cristianstaicu arjunshibu
Prototype Pollution in json-pointer Moderate
CVE-2021-23820 was published for json-pointer (npm) Nov 8, 2021
G-Rath
Prototype pollution in dojo High
CVE-2020-5258 was published for dojo (npm) Mar 10, 2020
ProTip! Advisories are also available from the GraphQL API