CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Parent: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

473 vulnerabilities with CWE-1321
CVE-2022-37265 CRITICAL
Steal - Prototype Pollution
CVSS 9.8
CVE-2022-37258 CRITICAL
Steal - Prototype Pollution
CVSS 9.8
CVE-2022-37264 CRITICAL
Steal - Prototype Pollution
CVSS 9.8
CVE-2022-37266 CRITICAL
Steal - Prototype Pollution
CVSS 9.8
CVE-2022-37257 CRITICAL
Steal - Prototype Pollution
CVSS 9.8
CVE-2022-2625 HIGH
PostgreSQL - RCE
CVSS 8.0
CVE-2022-25907 HIGH
Typescript Deep Merge < 2.0.2 - Prototype Pollution
CVSS 7.5
CVE-2022-2564 CRITICAL
automattic/mongoose <6.4.6 - Info Disclosure
CVSS 9.8
CVE-2022-31106 HIGH
Underscore.deep <0.5.3 - Prototype Pollution
CVSS 8.3
CVE-2022-21231 HIGH
Deep-get-set - Prototype Pollution
CVSS 7.5
CVE-2022-25871 MEDIUM
Querymen - Prototype Pollution
CVSS 5.9
CVE-2022-21213 HIGH
Mout < 1.2.4 - Prototype Pollution
CVSS 7.5
CVE-2022-25878 HIGH
Protobufjs < 6.11.3 - Prototype Pollution
CVSS 8.2
CVE-2022-25862 MEDIUM
Sds - Prototype Pollution
CVSS 4.0
CVE-2022-21190 HIGH
Mozilla Convict < 6.2.3 - Prototype Pollution
CVSS 7.5
CVE-2022-25324 HIGH
Bignum - Prototype Pollution
CVSS 7.5
CVE-2022-25301 HIGH
Jsgui-lang-essentials - Prototype Pollution
CVSS 7.7
CVE-2022-25645 MEDIUM
Dset < 3.1.2 - Prototype Pollution
CVSS 6.5
CVE-2022-22143 HIGH
convict <6.2.2 - Prototype Pollution
CVSS 7.5
CVE-2022-21189 HIGH
Dexie < 3.2.2 - Prototype Pollution
CVSS 7.3
CVE-2022-24279 HIGH
madlib-object-utils <0.1.8 - Prototype Pollution
CVSS 7.5
CVE-2022-21803 HIGH
Nconf < 0.11.4 - Prototype Pollution
CVSS 7.3
CVE-2022-1295 CRITICAL
Fullpage < 4.0.2 - Prototype Pollution
CVSS 9.8
CVE-2022-24802 HIGH
Deepmerge-ts < 4.0.2 - Prototype Pollution
CVSS 8.1
CVE-2022-26260 CRITICAL
Simple-Plist <1.3.0 - Info Disclosure
CVSS 9.8
Details
Vulnerabilities 473