Skip to main content

CWE archive

CWE-1321 CVEs

Programmatic archive

548 CVEs tagged with CWE-1321161 Critical, 220 High, 150 Medium, 17 Low, 0 Unrated.

CVE-2021-20088

Published Apr 23, 2021

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in mootools-more 1.6.0 allows a malicious user to inject properties into Object.prototype.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20087

Published Apr 23, 2021

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-deparam 0.5.1 allows a malicious user to inject properties into Object.prototyp…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20084

Published Apr 23, 2021

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-sparkle 1.5.2-beta allows a malicious user to inject properties into Object.pro…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25916

Published Mar 16, 2021

Prototype pollution vulnerability in 'patchmerge' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-21368

Published Mar 12, 2021

msgpack5 is a msgpack v5 implementation for node.js and the browser. In msgpack5 before versions 3.6.1, 4.5.1, and 5.2.1 there is a "Prototype Poisoning" vulnerability. When msgpa…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25915

Published Mar 9, 2021

Prototype pollution vulnerability in 'changeset' versions 0.0.1 through 0.2.5 allows an attacker to cause a denial of service and may lead to remote code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-25914

Published Mar 1, 2021

Prototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of service and may lead to remote code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-21297

Published Feb 26, 2021

Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier contains a Prototype Pollution vulnerability in the admin API. A ba…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27582

Published Feb 23, 2021

org/mitre/oauth2/web/OAuthConfirmationController.java in the OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Mass Assignment (aka Autobinding) vu…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-25913

Published Feb 8, 2021

Prototype pollution vulnerability in 'set-or-get' version 1.0.0 through 1.2.10 allows an attacker to cause a denial of service and may lead to remote code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-21304

Published Feb 8, 2021

Dynamoose is an open-source modeling tool for Amazon's DynamoDB. In Dynamoose from version 2.0.0 and before version 2.7.0 there was a prototype pollution vulnerability in the inte…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25912

Published Feb 2, 2021

Prototype pollution vulnerability in 'dotty' versions 0.0.1 through 0.1.0 allows attackers to cause a denial of service and may lead to remote code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-23329

Published Jan 31, 2021

The package nested-object-assign before 1.0.4 are vulnerable to Prototype Pollution via the default function, as demonstrated by running the PoC below.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-28460

Published Dec 22, 2020

This affects the package multi-ini before 2.1.2. It is possible to pollute an object's prototype by specifying the constructor.proto object as part of an array. This is a bypass o…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-28448

Published Dec 22, 2020

This affects the package multi-ini before 2.1.1. It is possible to pollute an object's prototype by specifying the proto object as part of an array.

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-28458

Published Dec 16, 2020

All versions of package datatables.net are vulnerable to Prototype Pollution due to an incomplete fix for https://snyk.io/vuln/SNYK-JS-DATATABLESNET-598806.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7792

Published Dec 11, 2020

This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn 'mixes objects into the target object,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7788

Published Dec 11, 2020

This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the appl…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-28271

Published Nov 12, 2020

Prototype pollution vulnerability in 'deephas' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-28270

Published Nov 12, 2020

Prototype pollution vulnerability in 'object-hierarchy-access' versions 0.2.0 through 0.32.0 allows attacker to cause a denial of service and may lead to remote code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-28269

Published Nov 12, 2020

Prototype pollution vulnerability in 'field' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 451-475 of 548 CVEsPage 19 of 22