vmall.com 66 packages

Last scanned on Jan 19 at 08:39 AM
lodash 4.17.16VulnerableOutdated
Lodash modular utilities.
License
MIT
Footprint
8 KB
Vulnerabilities
Command Injection in lodash
Affected versions >=0 <4.17.21
Regular Expression Denial of Service (ReDoS) in lodash
Affected versions >=0 <4.17.21
Prototype Pollution in lodash
Affected versions >=3.7.0 <4.17.19
Matched Modules
Version distribution in production
3 846
4.17.16
946
4.17.21
337
4.17.20
322
4.17.15
302
4.17.19
301
4.17.13
next-auth 3.24.1 - 3.29.10VulnerableOutdated
Authentication for Next.js
es5-ext 0.10.24 - 0.10.49VulnerableOutdated
ECMAScript extensions and shims
tslib 1.2.0 - 2.4.1Outdated
Runtime library for TypeScript helper functions
color-convert 1.8.2 - 2.0.1
Plain color conversion functions
escape-string-regexp 4.0.0 - 5.0.0
Escape RegExp special characters
isarray 1.0.0 - 2.0.5
Array#isArray for older browsers
react-is 16.3.0 - 16.13.1Outdated
Brand checking of React Elements.
qs 6.10.0 - 6.10.1Outdated
A querystring parser that supports nesting and arrays, with a depth limit
buffer 4.6.0 - 4.9.2Outdated
Node.js Buffer API, for the browser
@babel/runtime 7.9.6 - 7.12.18Outdated
babel's modular runtime helpers
+1
hzoo
existentialism
nicolo-ribaudo
get-intrinsic 1.1.0 - 1.1.1Outdated
Get and robustly cache all JS language-level intrinsics at first require time
function-bind 1.1.0 - 1.1.1Outdated
Implementation of Function.prototype.bind
is-arrayish 0.3.1 - 0.3.2
Determines if an object can be used as an array
axios 0.21.4Outdated
Promise based HTTP client for the browser and node.js
call-bind 1.0.2Outdated
Robustly `.call.bind()` a function
object-inspect 1.12.0 - 1.12.1Outdated
string representations of objects in node and the browser
has-symbols 1.0.2 - 1.0.3
Determine if the JS environment has Symbol support. Supports spec, or shams.
side-channel 1.0.4Outdated
Store information about any JS value in a side channel. Uses WeakMap if available.
base64-js 1.3.0 - 1.5.1
Base64 encoding/decoding in pure JS
deepmerge 4.2.2Outdated
A library for deep (recursive) merging of Javascript objects
core-js 3.18.2 - 3.18.3Outdated
Standard library
scheduler 0.15.0 - 0.23.0Outdated
Cooperative scheduler for the browser environment.
has 1.0.1 - 1.0.3Outdated
Object.prototype.hasOwnProperty.call shortcut
tarruda
tarruda
prop-types 15.8.0 - 15.8.1
Runtime type checking for React props and similar objects.
react 16.13.0 - 17.0.2Outdated
React is a JavaScript library for building user interfaces.
color 3.1.0 - 3.2.1Outdated
Color conversion and manipulation with CSS string support
color-string 1.5.3 - 1.9.1
Parser and generator for CSS color strings
hoist-non-react-statics 3.3.1 - 3.3.2
Copies non-react specific statics from a child component to a parent component
mridgway
mridgway
simple-swizzle 0.2.1 - 0.2.2
Simply swizzle your arguments
promise 8.1.0Outdated
Bare bones Promises/A+ implementation
forbeslindesay
then-promise-bot
classnames 2.3.0 - 2.3.1Outdated
A simple utility for conditionally joining classNames together
query-string 6.5.0 - 7.1.3Outdated
Parse and stringify URL query strings
whatwg-fetch 3.4.0 - 3.6.2Outdated
A window.fetch polyfill.
jakechampion
mattandrews
mislav
lodash-es 4.17.21
Lodash exported as ES modules.
redux 4.0.1 - 4.2.0Outdated
Predictable state container for JavaScript apps
timers-browserify 2.0.9Outdated
timers module for browserify
filter-obj 1.1.0Outdated
Filter object keys and values into a new object
@xmldom/xmldom 0.7.0 - 0.8.6Outdated
A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.
split-on-first 1.0.0 - 2.0.0Outdated
Split a string on the first occurance of a given separator
i18next 17.0.0 - 17.0.18Outdated
i18next internationalization framework
array-find-index 1.0.1 - 1.0.2
ES2015 `Array#findIndex()` ponyfill
hyphenate-style-name 1.0.3 - 1.0.4
Hyphenates a camelcased CSS property name
is-function 1.0.2
is that thing a function? Use this module to find out
react-i18next 11.7.3 - 12.1.4Outdated
Internationalization for react done right. Using the i18next i18n ecosystem.
@apollo/client 3.0.0 - 3.7.4Outdated
A fully-featured caching GraphQL client.
react-scripts 0.4.2Outdated
Configuration and scripts for Create React App.
+1
fb
timer
iansu
inline-style-prefixer 5.1.2 - 6.0.1Outdated
Run-time Autoprefixer for JavaScript style objects
create-react-class 15.7.0
Legacy API for creating React components.
rc-select 14.1.11 - 14.2.0Outdated
React Select
safe-json-parse 2.0.0 - 4.0.0
Parse JSON safely without throwing
raynos
raynos
mobx-react-lite 2.0.0 - 3.1.4Outdated
Lightweight React bindings for MobX based on React 16.8+ and Hooks
keycode 2.1.2 - 2.2.1
Convert between keyboard keycodes and keynames and vice versa.
@videojs/vhs-utils 3.0.2 - 4.0.0
Objects and functions shared throughtout @videojs/http-streaming code
mux.js 6.0.0 - 6.2.0Outdated
A collection of lightweight utilities for inspecting and manipulating video container formats.
video.js 5.12.0 - 7.21.1Outdated
An HTML5 video player that supports HLS and DASH with a common API and skin.
react-native-web 0.14.10 - 0.14.13Outdated
React Native for Web
url-toolkit 2.2.4 - 2.2.5
Build an absolute URL from a base URL and a relative URL (RFC 1808). No dependencies!
m3u8-parser 4.6.0 - 4.8.0Outdated
m3u8 parser
mpd-parser 0.20.0 - 0.22.1Outdated
mpd parser
videojs-vtt.js 0.15.0 - 0.15.4Outdated
A JavaScript implementation of the WebVTT specification, forked from vtt.js for use with Video.js
normalize-css-color 1.0.2
Normalize a subset of CSS color values into integers
intelligibabble
intelligibabble
deepcopy 2.0.0 - 2.1.0
deep copy data
sasaplus1
sasaplus1
@tannin/plural-forms 1.0.0 - 1.1.0
Compiles a function to compute the plural forms index for a given value
aduth
aduth
lottie-api 1.0.0 - 1.0.2Outdated
A library to edit lottie-web animations dynamically
airnan
airnan
@dhmk/utils 1.0.0 - 4.2.2Outdated
A collection of frequently used functions and primitives