Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2026-4800
Impact:
The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but di…
Lodash
4.18.0+
MEDIUM 5.3
CVE-2026-2950
Impact:
Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: …
Lodash
4.17.23+
MEDIUM 5.3
CVE-2025-13465
Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths w…
Lodash
4.17.23+
MEDIUM 5.3
CVE-2020-28500EPSS 7%
Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
Lodash
4.17.21+
HIGH 7.4
CVE-2020-8203EPSS 5%
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
Lodash
4.17.20+
MEDIUM 6.5
CVE-2019-1010266
lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler.…
Lodash
4.17.11+
MEDIUM 5.6
CVE-2018-16487
A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or…
Lodash
4.17.11+