Known Vulnerabilities for Lodash-es by Lodash
Listed below are 2 of the newest known vulnerabilities associated with "Lodash-es" by "Lodash".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-54737 json | @phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5... | Not Provided | 2026-07-31 | 2026-07-31 |
| CVE-2026-48795 json | AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompletely... | Not Provided | 2026-07-15 | 2026-07-16 |
| CVE-2026-44490 json | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side pro... | Not Provided | 2026-06-11 | 2026-06-11 |
| CVE-2026-4800 json | Not Provided | 2026-03-31 | 2026-07-30 | |
| CVE-2026-2950 json | Not Provided | 2026-03-31 | 2026-07-24 | |
| CVE-2025-13465 json | Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacke... | Not Provided | 2026-01-21 | 2026-07-31 |