Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
Merge
CRITICAL 9.8
CVE-2021-23397
All versions of package @ianwalter/merge are vulnerable to Prototype Pollution via the main (merge) function. Maintainer suggests using @generates/me…
No fix yet
Fix from $2,300
2022-07-25
Merge
CRITICAL 9.8
CVE-2021-3645
merge is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Fix: 1.0.2+
Fix from $2,300
2021-09-10
Merge
CRITICAL 9.8
CVE-2020-28499
All versions of package merge are vulnerable to Prototype Pollution via _recursiveMerge .
Fix: 2.1.1+
Fix from $2,300
2021-02-18
Merge
HIGH 7.5
CVE-2018-16469
The merge.recursive function in the merge package <1.2.1 can be tricked into adding or modifying properties of the Object prototype. These properties…
Fix: 1.2.1+
Fix from $1,950
2018-10-30