CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
501 vulnerabilities with CWE-1321
CVE-2024-39018
MEDIUM
cat5th key-serializer 0.2.5 - Prototype Pollution via Query Function
CVSS 6.3
CVE-2024-39016
HIGH
che3vinci c3/utils-1 - Prototype Pollution
CVSS 8.1
CVE-2024-39014
CRITICAL
cahil/utils <2.3.2 - Code Injection
CVSS 9.8
CVE-2024-39013
CRITICAL
2o3t-utility <0.1.2 - Code Injection
CVSS 9.8
CVE-2024-39008
CRITICAL
fast-loops < 1.1.4 - Prototype Pollution via objectMergeDeep Function
CVSS 10.0
CVE-2024-39003
HIGH
amoyjs common v1.0.10 - Prototype Pollution via setValue Function
CVSS 7.3
CVE-2024-39001
MEDIUM
ag-grid < 31.3.4 - Prototype Pollution via _ModuleSupport.jsonApply
CVSS 6.3
CVE-2024-39000
MEDIUM
swiper - Prototype Pollution via Parse Function
CVSS 6.5
CVE-2024-38999
CRITICAL
requirejs < 2.3.7 - Prototype Pollution via s.contexts._.configure Function
CVSS 10.0
CVE-2024-38997
MEDIUM
ratio-swiper 0.0.2 - Prototype Pollution via extendDefaults Function
CVSS 6.5
CVE-2024-38996
CRITICAL
ag-grid < 31.3.4 - Prototype Pollution via _.mergeDeep Function
CVSS 9.8
CVE-2024-38994
HIGH
amoyjs common 1.0.10 - Prototype Pollution via extend Function
CVSS 7.3
CVE-2024-38992
HIGH
airvertco frappejs 0.0.11 - Prototype Pollution via registerView Function
CVSS 8.8
CVE-2024-38991
HIGH
akbr patch-into 1.0.1 - Prototype Pollution via patchInto Function
CVSS 8.8
CVE-2024-38987
MEDIUM
aofl cli-lib 3.14.0 - Prototype Pollution via defaultsDeep Component
CVSS 6.3
CVE-2024-36578
MEDIUM
akbr update <1.0.0 - Info Disclosure
CVSS 5.9
CVE-2024-36577
HIGH
aphp js-object-resolver <3.1.1 - Info Disclosure
CVSS 8.3
CVE-2024-36574
MEDIUM
flatten-json 1.0.1 - Prototype Pollution via unflattenJSON Function
CVSS 6.3
CVE-2024-36573
CRITICAL
almela obx < 0.0.4 - Prototype Pollution via obx/build/index.js
CVSS 9.8
CVE-2024-36582
CRITICAL
alexbinary object-deep-assign <1.0.11 - Info Disclosure
CVSS 9.8
CVE-2024-36583
HIGH
Byond Real Accessor <=1.0.0 - Code Injection
CVSS 8.1
CVE-2024-36580
CRITICAL
cdr0/sg 1.0.10 - Prototype Pollution
CVSS 9.8
CVE-2024-21512
HIGH
mysql2 < 3.9.8 - Prototype Pollution via nestTables Input
CVSS 8.2
CVE-2024-29651
HIGH
API Dev Tools json-schema-ref-parser <11.1.0 - RCE
CVSS 8.1
CVE-2024-24293
HIGH
@bit/loader 10.0.3 - Prototype Pollution via M Function e Argument
CVSS 8.8
Details
Vulnerabilities
501