Vulnerabilities
Summary — last 7 days
New vulnerabilities2,685▼ 177 vs. last week
Critical / high1,223▼ 305 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 186 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | High (7.5) | 0.64% | — | Mootools | 1/3/2023 | 6/17/2026 | MooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector parser that is vulnerable to Regular Expression Denial of Service (ReDoS). An attack requires that an attacker can inject a string into a CSS selector at runtime, which is quite common with e.g. jQuery… | |
| Modified | Critical (9.8) | 0.89% | — | Mootools Project Mootools | 8/24/2021 | 6/17/2026 | This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge() | |
| Modified | High (8.8) | 1.4% | — | Mootools-more | 4/23/2021 | 6/17/2026 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in mootools-more 1.6.0 allows a malicious user to inject properties into Object.prototype. |