|
195291
|
7.5 |
HIGH
Network
|
proto_project
|
proto
|
This affects all versions of package Proto. It is possible to inject pollute the object property of an application using Proto by leveraging the merge function.
|
NVD-CWE-Other
|
CVE-2021-23426
|
2024-11-21 14:51 |
2021-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195292
|
8.6 |
HIGH
Network
|
object-path_project debian
|
object-path debian_linux
|
This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the path parameter are arrays. In particular…
|
CWE-843
Type Confusion
|
CVE-2021-23434
|
2024-11-21 14:51 |
2021-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195293
|
9.8 |
CRITICAL
Network
|
mootools_project
|
mootools
|
This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge()
|
NVD-CWE-noinfo
|
CVE-2021-23432
|
2024-11-21 14:51 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195294
|
8.8 |
HIGH
Network
|
joplinapp
|
joplin
|
The package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in various forms.
|
CWE-352
Origin Validation Error
|
CVE-2021-23431
|
2024-11-21 14:51 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195295
|
7.5 |
HIGH
Network
|
startserver_project
|
startserver
|
All versions of package startserver are vulnerable to Directory Traversal due to missing sanitization.
|
CWE-22
Path Traversal
|
CVE-2021-23430
|
2024-11-21 14:51 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195296
|
7.5 |
HIGH
Network
|
transpile_project
|
transpile
|
All versions of package transpile are vulnerable to Denial of Service (DoS) due to a lack of input sanitization or whitelisting, coupled with improper exception handling in the .to() function.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2021-23429
|
2024-11-21 14:51 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195297
|
9.8 |
CRITICAL
Network
|
pac-resolver_project
|
pac-resolver
|
This affects the package pac-resolver before 5.0.0. This can occur when used with untrusted input, due to unsafe PAC file handling. **NOTE:** The fix for this vulnerability is applied in the node-deg…
|
NVD-CWE-noinfo
|
CVE-2021-23406
|
2024-11-21 14:51 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195298
|
5.3 |
MEDIUM
Network
|
trim-off-newlines_project
|
trim-off-newlines
|
All versions of package trim-off-newlines are vulnerable to Regular Expression Denial of Service (ReDoS) via string processing.
|
NVD-CWE-noinfo
|
CVE-2021-23425
|
2024-11-21 14:51 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195299
|
7.5 |
HIGH
Network
|
ansi-html_project
|
ansi-html
|
This affects all versions of package ansi-html. If an attacker provides a malicious string, it will get stuck processing the input for an extremely long time.
|
NVD-CWE-noinfo
|
CVE-2021-23424
|
2024-11-21 14:51 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195300
|
7.5 |
HIGH
Network
|
bikeshed_project
|
bikeshed
|
This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing include, include-code or include-raw block is processed. The contents of arbitrary files could …
|
CWE-22
Path Traversal
|
CVE-2021-23423
|
2024-11-21 14:51 |
2021-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|