Nedb is a lightweight, embedded JavaScript database library used in Node.js applications, with a narrow vulnerability footprint concentrated around its core product. The durable signal centers on prototype-pollution weaknesses in object-handling code, a vulnerability class characteristic of dynamic-language libraries where object properties can be unexpectedly modified through untrusted input. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nedb Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23395MEDIUM This affects all versions of package nedb. The library could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor.prototype payload. | Jun 15, 2021 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nedb Project.
Media articles that mention a CVE ID that affects a product developed by Nedb Project — matched by CVE ID, not by vendor name.