Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2218927
AlmaLinux
5946
Alpaquita
16105
Alpine
4618
Android
3677
Azure Linux
17673
BellSoft Hardened Containers
754
Bitnami
9325
Chainguard
1035449
CleanStart
3983
CRAN
14
crates.io
2739
Debian
68630
Echo
7522
GHC
3
GIT
108492
GitHub Actions
55
Go
9245
Hackage
33
Hex
364
Julia
1713
Linux
29975
Mageia
6232
Maven
7046
MinimOS
146695
npm
229015
NuGet
1869
opam
29
openEuler
8800
openSUSE
14498
OSS-Fuzz
4014
Packagist
7100
Pub
11
PyPI
25220
Red Hat
23413
Rocky Linux
4317
Root
19607
RubyGems
5326
SUSE
23390
SwiftURL
60
TuxCare
9662
Ubuntu
65637
VSCode
21
Wolfi
290650
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-mj3g-7xcc-x4vh
npm/@phun-ky/defaults-deep
@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging
31 Jul
Fix available
Severity - 7.3 (High)
MAL-2026-959
npm/format-defaults
Malicious code in format-defaults (npm)
20 Feb
No fix available
GHSA-q2x5-4xjx-c6p9
npm/@backstage/backend-defaults
Backstage has a Possible SSRF when reading from allowed URL's in `backend.reading.allow`
21 Jan
Fix available
Severity - 3.5 (Low)
GHSA-rq6q-wr2q-7pgp
npm/@backstage/backend-defaults
npm/@backstage/plugin-scaffolder-backend
npm/@backstage/plugin-scaffolder-node
Backstage has a Possible Symlink Path Traversal in Scaffolder Actions
21 Jan
Fix available
Severity - 7.1 (High)
GHSA-79h2-v6hh-wq23
npm/@ndhoule/defaults
@ndhoule/defaults prototype pollution
06 Feb 2025
No fix available
Severity - 7.5 (High)
MAL-2022-2691
npm/electron-secure-defaults
Malicious code in electron-secure-defaults (npm)
20 Jun 2022
No fix available
GHSA-h6xg-rg33-9mf4
npm/deep-defaults
deep-defaults vulnerable to prototype pollution
24 May 2022
No fix available
Severity - 9.8 (Critical)
GHSA-pjxw-22xf-6pwc
npm/defaults-deep
Prototype Pollution in defaults-deep
07 Feb 2019
No fix available
Severity - 9.8 (Critical)
GHSA-cqp5-m4pq-gfgp
npm/defaults-deep
Prototype Pollution in defaults-deep
26 Jul 2018
Fix available
Severity - 8.8 (High)
npm - OSV