CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
501 vulnerabilities with CWE-1321
CVE-2023-26139
HIGH
underscore-keypath <0.0.11 - Prototype Pollution
CVSS 7.5
CVE-2023-3696
CRITICAL
mongoose < 5.13.20 and 7.0.0-7.3.3 - Prototype Pollution
CVSS 9.8
CVE-2023-36665
CRITICAL
protobuf.js <7.2.5 - Prototype Pollution
CVSS 9.8
CVE-2023-26136
MEDIUM
Tough-Cookie <4.1.3 - Prototype Pollution
CVSS 6.5
CVE-2023-26135
HIGH
flatnest - Prototype Pollution via nest() Function
CVSS 7.3
CVE-2023-36475
CRITICAL
Parse Server < 5.5.2 - Remote Code Execution via Prototype Pollution
CVSS 9.8
CVE-2023-26133
HIGH
progressbar.js < 1.1.1 - Prototype Pollution via extend() Function
CVSS 8.2
CVE-2023-26132
HIGH
Package dottie <2.0.4 - Info Disclosure
CVSS 7.5
CVE-2023-2972
CRITICAL
antfu/utils < 0.7.3 - Prototype Pollution
CVSS 9.8
CVE-2023-32305
HIGH
aiven-extras < 1.1.9 - Privilege Escalation via Unqualified Function Name Collision
CVSS 8.8
CVE-2023-2582
MEDIUM
Strikingly CMS - Prototype Pollution leading to Reflected Cross-Site Scripting via URL Fragment Parsing
CVSS 6.1
CVE-2023-30857
LOW
aedart/ion < 0.6.1 - Prototype Pollution in MetadataRecord Merge
CVSS 3.7
CVE-2023-30363
CRITICAL
vConsole < 3.15.1 - Prototype Pollution via setOptions in core.ts
CVSS 9.8
CVE-2023-30533
HIGH
SheetJS Community Edition < 0.19.3 - Prototype Pollution via Crafted File
CVSS 7.8
CVE-2023-26122
HIGH
safe-eval < 0.4.1 - Sandbox Bypass via Prototype Pollution
CVSS 8.8
CVE-2023-26121
HIGH
safe-eval < 0.4.1 - Prototype Pollution via safeEval Function
CVSS 7.5
CVE-2023-0842
MEDIUM
xml2js 0.4.23 - Prototype Pollution via __proto__ Property
CVSS 5.3
CVE-2023-28427
HIGH
matrix-js-sdk <24.0.0 - Info Disclosure
CVSS 8.2
CVE-2023-28103
HIGH
matrix-react-sdk < 3.69.0 - Prototype Pollution via Remote Server Data
CVSS 8.2
CVE-2023-26113
HIGH
collection.js <6.8.1 - Info Disclosure
CVSS 7.5
CVE-2023-26106
HIGH
dot-lens < 1.2.3 - Prototype Pollution via set() Function
CVSS 7.5
CVE-2023-26105
HIGH
Package Utilities - Prototype Pollution
CVSS 7.5
CVE-2023-26102
HIGH
rangy - Prototype Pollution via extend() Function
CVSS 7.5
CVE-2023-23917
HIGH
Rocket.Chat < 5.2.0 - Prototype Pollution leading to Remote Code Execution
CVSS 8.8
CVE-2022-36060
HIGH
matrix-react-sdk < 3.53.0 - Denial of Service via Prototype Pollution
CVSS 8.2
Details
Vulnerabilities
501