Vulnerabilities

Summary — last 7 days

New vulnerabilities2,685▼ 177 vs. last week
Critical / high1,223▼ 305 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 186 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (7.5)0.64%—Mootools1/3/20236/17/2026
MooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector parser that is vulnerable to Regular Expression Denial of Service (ReDoS). An attack requires that an attacker can inject a string into a CSS selector at runtime, which is quite common with e.g. jQuery…
ModifiedCritical (9.8)0.89%—Mootools Project Mootools8/24/20216/17/2026
This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge()
ModifiedHigh (8.8)1.4%—Mootools-more4/23/20216/17/2026
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in mootools-more 1.6.0 allows a malicious user to inject properties into Object.prototype.
Orbitaley — Vulnerabilities