7.5

CVSS3.1

CVE-2025-57318 -

A Prototype Pollution vulnerability in the toCsv function of csvjson versions thru 5.1.0 allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.

πŸ“… Published: Sept. 24, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 3:48 p.m.

8.6

CVSS3.1

CVE-2025-57350 - csvtojson: csvtojson prototype pollution

The csvtojson package, a tool for converting CSV data to JSON with customizable parsing capabilities, contains a prototype pollution vulnerability in versions prior to 2.0.10. This issue arises due to insufficient sanitization of nested header names during the parsing process in the parser_jsonarra…

πŸ“… Published: Sept. 24, 2025, midnight πŸ”„ Last Modified: Oct. 17, 2025, 2:56 p.m.

7.5

CVSS3.1

CVE-2025-57326 -

A Prototype Pollution vulnerability in the byGroupAndType function of sassdoc-extras v2.5.1 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.

πŸ“… Published: Sept. 24, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 4:23 p.m.

7.1

CVSS3.1

CVE-2025-56815 -

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transferTo() to save the uploaded file to a path controllable by the user, and lacks strict verification of the file name.

πŸ“… Published: Sept. 24, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 9:07 p.m.

9.8

CVSS3.1

CVE-2025-56819 -

An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.

πŸ“… Published: Sept. 24, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 9:30 p.m.

7.5

CVSS3.1

CVE-2025-57323 -

mpregular is a package that provides a small program development framework based on RegularJS. A Prototype Pollution vulnerability in the mp.addEventHandler function of mpregular version 0.2.0 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, caus…

πŸ“… Published: Sept. 24, 2025, midnight πŸ”„ Last Modified: Oct. 17, 2025, 1:21 p.m.

7.5

CVSS3.1

CVE-2025-57325 -

rollbar is a package designed to effortlessly track and debug errors in JavaScript applications. This package includes advanced error tracking features and an intuitive interface to help you identify and fix issues more quickly. A Prototype Pollution vulnerability in the utility.set function of rol…

πŸ“… Published: Sept. 24, 2025, midnight πŸ”„ Last Modified: Oct. 20, 2025, 4:54 p.m.

9.8

CVSS3.1

CVE-2025-57321 -

A Prototype Pollution vulnerability in the util-deps.addFileDepend function of magix-combine-ex versions thru 1.2.10 allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.

πŸ“… Published: Sept. 24, 2025, midnight πŸ”„ Last Modified: Oct. 17, 2025, 1:24 p.m.

5.3

CVSS3.1

CVE-2025-57353 -

The Runtime components of messageformat package for Node.js before 3.0.2 contain a prototype pollution vulnerability. Due to insufficient validation of nested message keys during the processing of message data, an attacker can manipulate the prototype chain of JavaScript objects by providing specia…

πŸ“… Published: Sept. 24, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-57352 - min-document: min-document prototype pollution

A vulnerability exists in the 'min-document' package prior to version 2.19.0, stemming from improper handling of namespace operations in the removeAttributeNS method. By processing malicious input involving the __proto__ property, an attacker can manipulate the prototype chain of JavaScript objects…

πŸ“… Published: Sept. 24, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3701 of 34,919
Β« previous page Β» next page
Filters