Skip to main content

CWE archive

CWE-1321 CVEs

Programmatic archive

548 CVEs tagged with CWE-1321161 Critical, 220 High, 150 Medium, 17 Low, 0 Unrated.

CVE-2020-7770

Published Nov 12, 2020

This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly check the key being set, leadi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7768

Published Nov 11, 2020

The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7766

Published Nov 10, 2020

This affects all versions of package json-ptr. The issue occurs in the set operation (https://flitbit.github.io/json-ptr/classes/_src_pointer_.jsonpointer.htmlset) when the force…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7746

Published Oct 29, 2020

This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing options (or the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7748

Published Oct 20, 2020

This affects the package @tsed/core before 5.65.7. This vulnerability relates to the deepExtend function which is used as part of the utils directory. Depending on if user input i…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7743

Published Oct 13, 2020

The package mathjs before 7.5.1 are vulnerable to Prototype Pollution via the deepExtend function that runs upon configuration updates.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8158

Published Sep 18, 2020

Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection atta…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-7727

Published Sep 1, 2020

All versions of package gedi are vulnerable to Prototype Pollution via the set function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-7725

Published Sep 1, 2020

All versions of package worksmith are vulnerable to Prototype Pollution via the setValue function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-7723

Published Sep 1, 2020

All versions of package promisehelpers are vulnerable to Prototype Pollution via the insert function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-7720

Published Sep 1, 2020

The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable function…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-7719

Published Sep 1, 2020

Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-7716

Published Sep 1, 2020

All versions of package deeps are vulnerable to Prototype Pollution via the set function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 476-500 of 548 CVEsPage 20 of 22