CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Parent: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

473 vulnerabilities with CWE-1321
CVE-2024-39013 CRITICAL
2o3t-utility <0.1.2 - Code Injection
CVSS 9.8
CVE-2024-39008 CRITICAL
NPM Fast-loops < 1.1.4 - Prototype Pollution
CVSS 10.0
CVE-2024-39003 HIGH
Amoyjs Common - Prototype Pollution
CVSS 7.3
CVE-2024-39001 MEDIUM
Ag-grid < 31.3.4 - Prototype Pollution
CVSS 6.3
CVE-2024-39000 MEDIUM
Swiper - Prototype Pollution
CVSS 6.5
CVE-2024-38999 CRITICAL
NPM Requirejs < 2.3.7 - Prototype Pollution
CVSS 10.0
CVE-2024-38997 MEDIUM
Swiper - Prototype Pollution
CVSS 6.5
CVE-2024-38996 CRITICAL
Ag-grid < 31.3.4 - Prototype Pollution
CVSS 9.8
CVE-2024-38994 HIGH
Amoyjs Common - Prototype Pollution
CVSS 7.3
CVE-2024-38992 HIGH
Airvertco Frappejs - Prototype Pollution
CVSS 8.8
CVE-2024-38991 HIGH
Akbr Patch-into - Prototype Pollution
CVSS 8.8
CVE-2024-38987 MEDIUM
Aofl Cli-lib - Prototype Pollution
CVSS 6.3
CVE-2024-36578 MEDIUM
akbr update <1.0.0 - Info Disclosure
CVSS 5.9
CVE-2024-36577 HIGH
aphp js-object-resolver <3.1.1 - Info Disclosure
CVSS 8.3
CVE-2024-36574 MEDIUM
flatten-json <1.0.1 - RCE
CVSS 6.3
CVE-2024-36573 CRITICAL
almela obx < v.0.0.4 - RCE
CVSS 9.8
CVE-2024-36582 CRITICAL
alexbinary object-deep-assign <1.0.11 - Info Disclosure
CVSS 9.8
CVE-2024-36583 HIGH
Byond Real Accessor <=1.0.0 - Code Injection
CVSS 8.1
CVE-2024-36580 CRITICAL
cdr0 sg 1.0.10 - Code Injection
CVSS 9.8
CVE-2024-21512 HIGH
NPM Mysql2 < 3.9.8 - Prototype Pollution
CVSS 8.2
CVE-2024-29651 HIGH
API Dev Tools json-schema-ref-parser <11.1.0 - RCE
CVSS 8.1
CVE-2024-24293 HIGH
BIT Loader - Prototype Pollution
CVSS 8.8
CVE-2024-34273 MEDIUM
njwt <v0.4.0 - Info Disclosure
CVSS 5.9
CVE-2024-34698 MEDIUM
Freescout < 1.8.139 - Prototype Pollution
CVSS 4.6
CVE-2024-34148 MEDIUM
Jenkins Subversion Partial Release Manager Plugin <1.0.1 - RCE
CVSS 6.8
Details
Vulnerabilities 473