CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Parent: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

473 vulnerabilities with CWE-1321
CVE-2023-26136 MEDIUM
Tough-Cookie <4.1.3 - Prototype Pollution
CVSS 6.5
CVE-2023-26135 HIGH
flatnest - Info Disclosure
CVSS 7.3
CVE-2023-36475 CRITICAL
Parse Server <5.5.2, 6.2.1 - RCE
CVSS 9.8
CVE-2023-26133 HIGH
progressbar.js - Info Disclosure
CVSS 8.2
CVE-2023-26132 HIGH
Package dottie <2.0.4 - Info Disclosure
CVSS 7.5
CVE-2023-2972 CRITICAL
Antfu Utils < 0.7.3 - Prototype Pollution
CVSS 9.8
CVE-2023-32305 HIGH
Aiven < 1.1.9 - Prototype Pollution
CVSS 8.8
CVE-2023-2582 MEDIUM
Strikingly - Prototype Pollution
CVSS 6.1
CVE-2023-30857 LOW
Aedart Ion < 0.6.1 - Prototype Pollution
CVSS 3.7
CVE-2023-30363 CRITICAL
Tencent Vconsole < 3.15.1 - Prototype Pollution
CVSS 9.8
CVE-2023-30533 HIGH
Sheetjs < 0.19.3 - Prototype Pollution
CVSS 7.8
CVE-2023-26122 HIGH
safe-eval - Sandbox Bypass
CVSS 8.8
CVE-2023-26121 HIGH
safe-eval - Info Disclosure
CVSS 7.5
CVE-2023-0842 MEDIUM
Xml2js < 0.5.0 - Prototype Pollution
CVSS 5.3
CVE-2023-28427 HIGH
matrix-js-sdk <24.0.0 - Info Disclosure
CVSS 8.2
CVE-2023-28103 HIGH
Matrix-react-sdk < 3.69.0 - Prototype Pollution
CVSS 8.2
CVE-2023-26113 HIGH
collection.js <6.8.1 - Info Disclosure
CVSS 7.5
CVE-2023-26106 HIGH
dot-lens - Info Disclosure
CVSS 7.5
CVE-2023-26105 HIGH
Package Utilities - Prototype Pollution
CVSS 7.5
CVE-2023-26102 HIGH
Rangy - Info Disclosure
CVSS 7.5
CVE-2023-23917 HIGH
Rocket.Chat server <5.2.0 - RCE
CVSS 8.8
CVE-2022-36060 HIGH
matrix-react-sdk <3.53.0 - DoS
CVSS 8.2
CVE-2022-36059 HIGH
matrix-js-sdk <19.4.0 - Info Disclosure
CVSS 8.2
CVE-2022-3901 HIGH
Visioglobe Visioweb - Prototype Pollution
CVSS 7.2
CVE-2022-4742 MEDIUM
Json-pointer < 2022-2-17 - Prototype Pollution
CVSS 6.3
Details
Vulnerabilities 473