Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2192300
AlmaLinux
5906
Alpaquita
15522
Alpine
4594
Android
3674
Azure Linux
17170
BellSoft Hardened Containers
744
Bitnami
9227
Chainguard
1022161
CleanStart
3529
CRAN
14
crates.io
2730
Debian
67887
Echo
6683
GHC
3
GIT
107254
GitHub Actions
55
Go
9202
Hackage
32
Hex
357
Julia
1713
Linux
29602
Mageia
6222
Maven
7011
MinimOS
143505
npm
228723
NuGet
1867
opam
29
openEuler
8800
openSUSE
14377
OSS-Fuzz
4006
Packagist
7091
Pub
11
PyPI
25149
Red Hat
23271
Rocky Linux
4279
Root
19517
RubyGems
5325
SUSE
23075
SwiftURL
60
TuxCare
9421
Ubuntu
64999
VSCode
21
Wolfi
287482
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-mj3g-7xcc-x4vh
npm/@phun-ky/defaults-deep
@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging
31 Jul
Fix available
Severity - 7.3 (High)
MAL-2026-959
npm/format-defaults
Malicious code in format-defaults (npm)
20 Feb
No fix available
GHSA-q2x5-4xjx-c6p9
npm/@backstage/backend-defaults
Backstage has a Possible SSRF when reading from allowed URL's in `backend.reading.allow`
21 Jan
Fix available
Severity - 3.5 (Low)
GHSA-rq6q-wr2q-7pgp
npm/@backstage/backend-defaults
npm/@backstage/plugin-scaffolder-backend
npm/@backstage/plugin-scaffolder-node
Backstage has a Possible Symlink Path Traversal in Scaffolder Actions
21 Jan
Fix available
Severity - 7.1 (High)
GHSA-79h2-v6hh-wq23
npm/@ndhoule/defaults
@ndhoule/defaults prototype pollution
06 Feb 2025
No fix available
Severity - 7.5 (High)
MAL-2022-2691
npm/electron-secure-defaults
Malicious code in electron-secure-defaults (npm)
20 Jun 2022
No fix available
GHSA-h6xg-rg33-9mf4
npm/deep-defaults
deep-defaults vulnerable to prototype pollution
24 May 2022
No fix available
Severity - 9.8 (Critical)
GHSA-pjxw-22xf-6pwc
npm/defaults-deep
Prototype Pollution in defaults-deep
07 Feb 2019
No fix available
Severity - 9.8 (Critical)
GHSA-cqp5-m4pq-gfgp
npm/defaults-deep
Prototype Pollution in defaults-deep
26 Jul 2018
Fix available
Severity - 8.8 (High)
npm - OSV