Lucene search

K

Clever Security Vulnerabilities

cve
cve

CVE-2017-11429

Clever saml2-js 2.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAM...

9.8CVSS

8.6AI Score

0.011EPSS

2019-04-17 02:29 PM
45
cve
cve

CVE-2022-31106

Underscore.deep is a collection of Underscore mixins that operate on nested objects. Versions of underscore.deep prior to version 0.5.3 are vulnerable to a prototype pollution vulnerability. An attacker can craft a malicious payload and pass it to deepFromFlat, which would pollute any future Object...

9.8CVSS

9.4AI Score

0.002EPSS

2022-06-28 06:15 PM
28
6