6.5

CVSS3.1

CVE-2025-57351 -

A prototype pollution vulnerability exists in the ts-fns package versions prior to 13.0.7, where insufficient validation of user-provided keys in the assign function allows attackers to manipulate the Object.prototype chain. By leveraging this flaw, adversaries may inject arbitrary properties into …

πŸ“… Published: Sept. 24, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-57348 -

The node-cube package (prior to version 5.0.0) contains a vulnerability in its handling of prototype chain initialization, which could allow an attacker to inject properties into the prototype of built-in objects. This issue, categorized under CWE-1321, arises from improper validation of user-suppl…

πŸ“… Published: Sept. 24, 2025, midnight πŸ”„ Last Modified: Oct. 17, 2025, 2:50 p.m.

7.5

CVSS3.1

CVE-2025-57330 -

The web3-core-subscriptions is a package designed to manages web3 subscriptions. A Prototype Pollution vulnerability in the attachToObject function of web3-core-subscriptions version 1.10.4 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing…

πŸ“… Published: Sept. 24, 2025, midnight πŸ”„ Last Modified: Oct. 17, 2025, 2:54 p.m.

7.5

CVSS3.1

CVE-2025-57329 -

web3-core-method is a package designed to creates the methods on the web3 modules. A Prototype Pollution vulnerability in the attachToObject function of web3-core-method version 1.10.4 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing deni…

πŸ“… Published: Sept. 24, 2025, midnight πŸ”„ Last Modified: Oct. 20, 2025, 4:30 p.m.

6.5

CVSS3.1

CVE-2025-57320 -

json-schema-editor-visual is a package that provides jsonschema editor. A Prototype Pollution vulnerability in the setData and deleteData function of json-schema-editor-visual versions thru 1.1.1 allows attackers to inject or delete properties on Object.prototype via supplying a crafted payload, ca…

πŸ“… Published: Sept. 24, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 3:48 p.m.

7.5

CVSS3.1

CVE-2025-57319 - fast-redact: fast-redact prototype pollution

fast-redact is a package that provides do very fast object redaction. A Prototype Pollution vulnerability in the nestedRestore function of fast-redact version 3.5.0 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) …

πŸ“… Published: Sept. 24, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-56816 -

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attackers to upload arbitrary YAML files to the config/jdbc-driver-ext.yml path. The application parses this file using SnakeYAML's unsafe load() or loadAs() method without input saniti…

πŸ“… Published: Sept. 24, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 9:06 p.m.

7.6

CVSS3.1

CVE-2025-59305 -

Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migration control functions. This can lead to data corruption or denial of service through unauthorized access to TRPC endpoints such as backgroundMigrations.all, back…

πŸ“… Published: Sept. 24, 2025, midnight πŸ”„ Last Modified: Dec. 2, 2025, 6:09 p.m.

7.5

CVSS3.1

CVE-2025-57328 -

toggle-array is a package designed to enables a property on the object at the specified index, while disabling the property on all other objects. A Prototype Pollution vulnerability in the enable and disable function of toggle-array v1.0.1 and before allows attackers to inject properties on Object.…

πŸ“… Published: Sept. 24, 2025, midnight πŸ”„ Last Modified: Oct. 20, 2025, 4:50 p.m.

7.5

CVSS3.1

CVE-2025-56241 -

Aztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the administrator password via a crafted POST request to sysAccess.asp. This allows full administrative control of the router without authentication.

πŸ“… Published: Sept. 24, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3702 of 34,919
Β« previous page Β» next page
Filters