scmp.com 95 packages

Last scanned on Oct 27 at 07:00 PM
lodash-es 4.17.5 - 4.17.10VulnerableOutdated
Lodash exported as ES modules.
License
MIT
Footprint
12 KB
Vulnerabilities
Prototype Pollution in lodash
Affected versions >=0 <4.17.14
Regular Expression Denial of Service (ReDoS) in lodash
Affected versions >=0 <4.17.11
Command Injection in lodash
Affected versions >=0 <4.17.21
Regular Expression Denial of Service (ReDoS) in lodash
Affected versions >=0 <4.17.21
Prototype Pollution in lodash
Affected versions >=3.7.0 <4.17.20
Matched Modules
Version distribution in production
3 519
4.17.21
1 221
4.17.20
526
4.10.0
420
4.17.11
419
4.17.15
404
4.17.10
lodash 4.17.16VulnerableOutdated
Lodash modular utilities.
axios 0.17.1 - 0.18.0VulnerableOutdated
Promise based HTTP client for the browser and node.js
jsonwebtoken 8.5.0 - 8.5.1VulnerableOutdated
JSON Web Token implementation (symmetric and asymmetric)
elliptic 6.3.1 - 6.4.1VulnerableOutdated
EC cryptography
es5-ext 0.10.24 - 0.10.49VulnerableOutdated
ECMAScript extensions and shims
semver 5.7.0 - 6.3.0Outdated
The semantic version parser used by npm.
+2
npm-cli-ops
saquibkhan
fritzy
tslib 1.2.0 - 2.4.0Outdated
Runtime library for TypeScript helper functions
ms 2.1.1Outdated
Tiny millisecond conversion utility
+5
gdborton
matheuss
rauchg
readable-stream 2.3.4 - 2.3.7Outdated
Node.js Streams, a user-land copy of the stream library from Node.js
string_decoder 1.1.0 - 1.3.0
The string_decoder module from Node core
isarray 1.0.0 - 2.0.5
Array#isArray for older browsers
inherits 2.0.3Outdated
Browser-friendly inheritance fully compatible with standard node.js inherits()
buffer 4.6.0 - 4.9.2Outdated
Node.js Buffer API, for the browser
function-bind 1.1.0 - 1.1.1Outdated
Implementation of Function.prototype.bind
core-util-is 1.0.2 - 1.0.3
The `util.is*` functions introduced in Node v0.12.
has-symbols 1.0.0 - 1.0.1Outdated
Determine if the JS environment has Symbol support. Supports spec, or shams.
base64-js 1.2.0 - 1.2.3Outdated
Base64 encoding/decoding in pure JS
events 3.0.0 - 3.3.0
Node's event emitter for all engines.
is-buffer 1.1.4 - 1.1.6Outdated
Determine if an object is a Buffer
util 0.10.0 - 0.12.5
Node.js's util module for all engines
has 1.0.1 - 1.0.3Outdated
Object.prototype.hasOwnProperty.call shortcut
tarruda
tarruda
pako 1.0.6 - 1.0.11Outdated
zlib port to javascript - fast, modularized, with browser support
jws 3.2.1 - 4.0.0
Implementation of JSON Web Signatures
jwa 1.4.1Outdated
JWA implementation (supports all JWS algorithms)
url 0.11.0Outdated
The core `url` packaged standalone for use with Browserify.
lodash.isplainobject 4.0.6
The lodash method `_.isPlainObject` exported as a module.
dayjs 1.10.5Outdated
2KB immutable date time library alternative to Moment.js with the same modern API
minimalistic-assert 1.0.0 - 1.0.1
minimalistic-assert ===
cwmma
indutny
ecdsa-sig-formatter 1.0.10 - 1.0.11
Translate ECDSA signatures between ASN.1/DER and JOSE-style concatenation
d2l-travis-deploy
d2l-travis-deploy
buffer-equal-constant-time 1.0.0 - 1.0.1
Constant-time comparison of Buffers
lodash.isstring 4.0.1
The lodash method `_.isString` exported as a module.
assert 1.0.0 - 1.5.0Outdated
The assert module from Node.js, for the browser.
sha.js 2.4.9 - 2.4.11
Streamable SHA hashes in pure javascript
dcousens
ljharb
cwmma
graphql 0.13.1 - 0.13.2Outdated
A Query Language and Runtime which can target any service.
browserify-zlib 0.2.0
Full zlib module for the browser
lodash.isboolean 3.0.1 - 3.0.3
The lodash method `_.isBoolean` exported as a module.
asn1.js 4.6.0 - 4.10.1Outdated
ASN.1 encoder and decoder
lodash.includes 4.3.0
The lodash method `_.includes` exported as a module.
hash-base 2.0.0 - 3.1.0
abstract base class for hash-streams
lodash.isnumber 3.0.1 - 3.0.3
The lodash method `_.isNumber` exported as a module.
hash.js 1.1.2 - 1.1.7
Various hash functions that could be run by both browser and node
prepend-http 2.0.0Outdated
Prepend `https://` to humanized URLs like sindresorhus.com and localhost
hmac-drbg 1.0.1
Deterministic random bit generator (hmac)
des.js 1.0.0Outdated
DES implementation
md5.js 1.1.0 - 1.3.5
node style md5 on pure JavaScript
pbkdf2 3.0.13 - 3.1.2
This library provides the functionality of PBKDF2 with the ability to use any supported hashing algorithm returned from crypto.getHashes()
parse-asn1 5.1.1Outdated
utility library for parsing asn1 files for use with browserify-sign.
+2
dcousens
ljharb
cwmma
cipher-base 1.0.4
abstract base class for crypto-streams
browserify-sign 2.4.0 - 2.8.0Outdated
adds node crypto signing for browsers
+2
dcousens
ljharb
cwmma
browserify-aes 0.4.0 - 0.8.1Outdated
aes, for browserify
stream-http 2.8.2 - 2.8.3Outdated
Streaming http in the browser
evp_bytestokey 1.0.3
The insecure key derivation algorithm from OpenSSL
browserify-rsa 3.0.0 - 4.0.1Outdated
RSA for browserify
+2
dcousens
ljharb
cwmma
timers-browserify 2.0.9Outdated
timers module for browserify
tty-browserify 0.0.0 - 0.0.1
the tty module from node core for browsers
create-ecdh 3.0.0 - 4.0.4
createECDH but browserifiable
public-encrypt 2.0.0 - 4.0.2Outdated
browserify version of publicEncrypt & privateDecrypt
+2
dcousens
ljharb
cwmma
diffie-hellman 1.1.2Outdated
pure js diffie-hellman
browserify-des 1.0.0 - 1.0.1Outdated
browserify-des ===
dcousens
ljharb
cwmma
miller-rabin 1.1.0 - 4.0.1
Miller Rabin algorithm for primality test
randomfill 1.0.0 - 1.0.4
random fill from browserify stand alone
vm-browserify 0.0.1 - 1.1.2
vm module for the browser
querystring-es3 0.2.1
Node's querystring module for all engines. (ES3 compat fork)
graphql-tag 2.9.1 - 2.11.0Outdated
A JavaScript template literal tag that parses GraphQL queries
jnwng
abernix
apollo-bot
to-arraybuffer 1.0.1
Get an ArrayBuffer from a Buffer as fast as possible
p-is-promise 3.0.0 - 4.0.0
Check if something is a promise
vue 1.0.9 - 2.7.13Outdated
The progressive JavaScript framework for building modern web UI.
set-cookie-parser 1.0.0 - 2.4.3Outdated
Parses set-cookie headers into objects
@firebase/util 0.1.0 - 1.7.2Outdated
_NOTE: This is specifically tailored for Firebase JS SDK usage, if you are not a member of the Firebase team, please avoid using this package_
+1
chholland
firebase-ops
feiyang.chen
@firebase/component 0.1.0 - 0.3.1Outdated
Firebase Component Platform
+1
chholland
firebase-ops
feiyang.chen
@firebase/logger 0.2.5 - 0.2.6Outdated
A logger package for use in the Firebase JS SDK
+1
chholland
firebase-ops
feiyang.chen
react-scripts 0.4.2Outdated
Configuration and scripts for Create React App.
+1
fb
timer
iansu
vue-router 2.6.0 - 3.1.6Outdated
> - This is the repository for Vue Router 4 (for Vue 3) > - For Vue Router 3 (for Vue 2) see [vuejs/vue-router](https://github.com/vuejs/vue-router).
yyx990803
posva
fp-ts 2.6.6 - 2.9.5Outdated
Functional programming in TypeScript
string-convert 0.2.0 - 0.2.1
String convertions
akiran
akiran
json2mq 0.2.0
Generate media query string from JSON or javascript object
akiran
akiran
parse-srcset 1.0.0 - 1.0.2
A spec-conformant JavaScript parser for the HTML5 srcset attribute
albell
albell
firebase 0.900.5 - 4.5.0Outdated
Firebase JavaScript library for web and Node.js
clipboard 2.0.3 - 2.0.4Outdated
Modern copy to clipboard. No Flash. Just 2kb
apollo-utilities 1.0.0 - 1.3.4
Utilities for working with GraphQL ASTs
+1
apollo-bot
benjamn
jbaxleyiii
apollo-link 1.2.0 - 1.2.14
Flexible, lightweight transport layer for GraphQL
jbaxleyiii
peggyrayzis
apollo-bot
mixpanel-browser 2.19.0 - 2.45.0Outdated
The official Mixpanel JavaScript browser client library
+1
mp_jthong
mixpanel-dev
tdumitrescu
react-calendar 2.11.1 - 2.13.4Outdated
Ultimate calendar for your React app.
ramda-adjunct 1.16.0 - 3.3.0Outdated
Ramda Adjunct is the most popular and most comprehensive set of utilities for use with Ramda, providing a variety of useful, well tested functions with excellent documentation.
apollo-cache-inmemory 1.0.0 - 1.6.6
Core abstract of Caching layer for Apollo Client
+1
apollo-bot
benjamn
jbaxleyiii
isbot 2.3.0 - 3.2.3Outdated
🤖/👨‍🦰 Recognise bots/crawlers/spiders using the user agent string.
vue-class-component 6.0.0 - 7.2.6
ES201X/TypeScript class decorator for Vue components
vue-property-decorator 3.2.1 - 7.2.0Outdated
property decorators for Vue Component
redux-form 6.0.3 - 8.3.8Outdated
A higher order component decorator for forms using Redux and React
photoswipe 4.1.2 - 4.1.3Outdated
JavaScript gallery
vue-lazyload 1.2.6Outdated
Vue module for lazy-loading images in your vue.js applications.
vue-clipboard2 0.3.0 - 0.3.1Outdated
A Vuejs2 & Vuejs3 binding for clipboard.js
vue-cookies 1.5.7 - 1.5.8Outdated
A simple Vue.js plugin for handling browser cookies
vue-mq 1.0.0 - 1.0.1
Handle media queries easily & build responsive design with Vue
alexandrebonaventure
alexandrebonaventure