Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 34

Количество 34

rocky логотип

RLSA-2026:24331

около 2 месяцев назад

Important: cockpit-image-builder security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-24331

16 дней назад

ELSA-2026-24331: cockpit-image-builder security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2026-4800

4 месяца назад

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2026-4800

4 месяца назад

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-4800

4 месяца назад

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2026-4800

4 месяца назад

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHS ...

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2025-13465

6 месяцев назад

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2025-13465

6 месяцев назад

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2025-13465

6 месяцев назад

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-13465

6 месяцев назад

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype poll ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-r5fr-rjxr-66jc

4 месяца назад

lodash vulnerable to Code Injection via `_.template` imports key names

CVSS3: 8.1
EPSS: Низкий
oracle-oval логотип

ELSA-2026-19167

около 1 месяца назад

ELSA-2026-19167: pcs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-19008

15 дней назад

ELSA-2026-19008: pcs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-10713

3 месяца назад

ELSA-2026-10713: pcs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-10710

3 месяца назад

ELSA-2026-10710: pcs security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2026-09406

4 месяца назад

Уязвимость библиотеки Lodash, связанная с неверным управлением генерацией кода, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20336-1

5 месяцев назад

Security update for cockpit-podman

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20244-1

5 месяцев назад

Security update for cockpit-machines, cockpit

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20185-1

6 месяцев назад

Security update for cockpit-packages

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20182-1

6 месяцев назад

Security update for cockpit

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2026:24331

Important: cockpit-image-builder security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-24331

ELSA-2026-24331: cockpit-image-builder security update (IMPORTANT)

16 дней назад
ubuntu логотип
CVE-2026-4800

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
3%
Низкий
4 месяца назад
redhat логотип
CVE-2026-4800

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
3%
Низкий
4 месяца назад
nvd логотип
CVE-2026-4800

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
3%
Низкий
4 месяца назад
debian логотип
CVE-2026-4800

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHS ...

CVSS3: 8.1
3%
Низкий
4 месяца назад
ubuntu логотип
CVE-2025-13465

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23

CVSS3: 5.3
2%
Низкий
6 месяцев назад
redhat логотип
CVE-2025-13465

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23

CVSS3: 8.2
2%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-13465

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23

CVSS3: 5.3
2%
Низкий
6 месяцев назад
debian логотип
CVE-2025-13465

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype poll ...

CVSS3: 5.3
2%
Низкий
6 месяцев назад
github логотип
GHSA-r5fr-rjxr-66jc

lodash vulnerable to Code Injection via `_.template` imports key names

CVSS3: 8.1
3%
Низкий
4 месяца назад
oracle-oval логотип
ELSA-2026-19167

ELSA-2026-19167: pcs security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-19008

ELSA-2026-19008: pcs security update (IMPORTANT)

15 дней назад
oracle-oval логотип
ELSA-2026-10713

ELSA-2026-10713: pcs security update (IMPORTANT)

3 месяца назад
oracle-oval логотип
ELSA-2026-10710

ELSA-2026-10710: pcs security update (IMPORTANT)

3 месяца назад
fstec логотип
BDU:2026-09406

Уязвимость библиотеки Lodash, связанная с неверным управлением генерацией кода, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.1
3%
Низкий
4 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20336-1

Security update for cockpit-podman

2%
Низкий
5 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20244-1

Security update for cockpit-machines, cockpit

2%
Низкий
5 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20185-1

Security update for cockpit-packages

2%
Низкий
6 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20182-1

Security update for cockpit

2%
Низкий
6 месяцев назад

Уязвимостей на страницу