CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
501 vulnerabilities with CWE-1321
CVE-2020-7608
MEDIUM
yargs-parser < 5.0.1 and 6.0.0-13.1.2 - Prototype Pollution via __proto__ Payload
CVSS 5.3
CVE-2020-7600
MEDIUM
querymen < 2.1.4 - Prototype Pollution via Unsanitized Handler Parameters
CVSS 5.3
CVE-2020-7598
MEDIUM
minimist < 1.2.2 - Prototype Pollution via Constructor or __proto__ Payload
CVSS 5.6
CVE-2020-5258
HIGH
dojo < 1.11.10 - Prototype Pollution via deepCopy Method
CVSS 7.7
CVE-2020-8116
HIGH
dot-prop <4.2.1, <5.1.1 - Prototype Pollution
CVSS 7.3
CVE-2019-0230
CRITICAL
Apache Struts 2.0.0-2.5.20 - Remote Code Execution via Forced Double OGNL Evaluation
CVSS 9.8
CVE-2019-10808
HIGH
utilitify < 1.0.3 - Prototype Pollution via Merge Method
CVSS 8.8
CVE-2019-10806
MEDIUM
vega < 1.13.1 - Prototype Pollution via vega.mergeConfig
CVSS 4.3
CVE-2019-19919
CRITICAL
handlebars.js - Prototype Pollution leading to Remote Code Execution
CVSS 9.8
CVE-2019-10768
HIGH
AngularJS < 1.7.9 - Prototype Pollution via merge() Function
CVSS 7.5
CVE-2019-17317
HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Object Injection via UpgradeWizard Module
CVSS 7.2
CVE-2019-17316
HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Object Injection via Import Module
CVSS 8.8
CVE-2019-17315
HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Object Injection in Administration Module
CVSS 7.2
CVE-2019-16328
HIGH
rpyc 4.1.0-4.1.1 - Remote Code Execution via Prototype Pollution
CVSS 7.5
CVE-2019-10745
HIGH
assign-deep < 0.4.8 - Prototype Pollution via Constructor or __proto__ Payload
CVSS 7.5
CVE-2019-14379
CRITICAL
jackson-databind < 2.9.9.2 - Remote Code Execution via Default Typing with Ehcache
CVSS 9.8
CVE-2019-10744
CRITICAL
lodash < 4.17.12 - Prototype Pollution via defaultsDeep Function
CVSS 9.1
CVE-2019-11358
MEDIUM
jQuery < 3.4.0 - Prototype Pollution via jQuery.extend
CVSS 6.1
CVE-2019-9061
HIGH
CMS Made Simple < 2.2.8 - Authenticated Object Injection via Module Installation
CVSS 8.8
CVE-2019-9058
HIGH
CMS Made Simple < 2.2.8 - Authenticated Object Injection via sel_groups Parameter
CVSS 7.2
CVE-2018-19274
HIGH
phpBB < 3.2.4 - Authenticated Remote Code Execution via Phar Deserialization
CVSS 7.2
CVE-2018-19296
HIGH
PHPMailer <5.2.27, <6.0.6 - Code Injection
CVSS 8.8
CVE-2018-3721
MEDIUM
lodash < 4.17.5 - Prototype Pollution via __proto__ in defaultsDeep, merge, and mergeWith
CVSS 6.5
CVE-2018-11135
HIGH
Quest KACE System Management Appliance 8.0.318 - Authenticated PHP Object Injection via /adminui/error_details.php
CVSS 8.8
CVE-2018-6195
HIGH
Splashing Images < 2.1.1 - Authenticated PHP Object Injection via Session Parameter
CVSS 7.2
Details
Vulnerabilities
501