CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Parent: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

501 vulnerabilities with CWE-1321
CVE-2023-26139 HIGH
underscore-keypath <0.0.11 - Prototype Pollution
CVSS 7.5
CVE-2023-3696 CRITICAL
mongoose < 5.13.20 and 7.0.0-7.3.3 - Prototype Pollution
CVSS 9.8
CVE-2023-36665 CRITICAL
protobuf.js <7.2.5 - Prototype Pollution
CVSS 9.8
CVE-2023-26136 MEDIUM
Tough-Cookie <4.1.3 - Prototype Pollution
CVSS 6.5
CVE-2023-26135 HIGH
flatnest - Prototype Pollution via nest() Function
CVSS 7.3
CVE-2023-36475 CRITICAL
Parse Server < 5.5.2 - Remote Code Execution via Prototype Pollution
CVSS 9.8
CVE-2023-26133 HIGH
progressbar.js < 1.1.1 - Prototype Pollution via extend() Function
CVSS 8.2
CVE-2023-26132 HIGH
Package dottie <2.0.4 - Info Disclosure
CVSS 7.5
CVE-2023-2972 CRITICAL
antfu/utils < 0.7.3 - Prototype Pollution
CVSS 9.8
CVE-2023-32305 HIGH
aiven-extras < 1.1.9 - Privilege Escalation via Unqualified Function Name Collision
CVSS 8.8
CVE-2023-2582 MEDIUM
Strikingly CMS - Prototype Pollution leading to Reflected Cross-Site Scripting via URL Fragment Parsing
CVSS 6.1
CVE-2023-30857 LOW
aedart/ion < 0.6.1 - Prototype Pollution in MetadataRecord Merge
CVSS 3.7
CVE-2023-30363 CRITICAL
vConsole < 3.15.1 - Prototype Pollution via setOptions in core.ts
CVSS 9.8
CVE-2023-30533 HIGH
SheetJS Community Edition < 0.19.3 - Prototype Pollution via Crafted File
CVSS 7.8
CVE-2023-26122 HIGH
safe-eval < 0.4.1 - Sandbox Bypass via Prototype Pollution
CVSS 8.8
CVE-2023-26121 HIGH
safe-eval < 0.4.1 - Prototype Pollution via safeEval Function
CVSS 7.5
CVE-2023-0842 MEDIUM
xml2js 0.4.23 - Prototype Pollution via __proto__ Property
CVSS 5.3
CVE-2023-28427 HIGH
matrix-js-sdk <24.0.0 - Info Disclosure
CVSS 8.2
CVE-2023-28103 HIGH
matrix-react-sdk < 3.69.0 - Prototype Pollution via Remote Server Data
CVSS 8.2
CVE-2023-26113 HIGH
collection.js <6.8.1 - Info Disclosure
CVSS 7.5
CVE-2023-26106 HIGH
dot-lens < 1.2.3 - Prototype Pollution via set() Function
CVSS 7.5
CVE-2023-26105 HIGH
Package Utilities - Prototype Pollution
CVSS 7.5
CVE-2023-26102 HIGH
rangy - Prototype Pollution via extend() Function
CVSS 7.5
CVE-2023-23917 HIGH
Rocket.Chat < 5.2.0 - Prototype Pollution leading to Remote Code Execution
CVSS 8.8
CVE-2022-36060 HIGH
matrix-react-sdk < 3.53.0 - Denial of Service via Prototype Pollution
CVSS 8.2
Details
Vulnerabilities 501