CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.
138 vulnerabilities with CWE-915
CVE-2025-68109
CRITICAL
ChurchCRM < 6.5.3 - Remote Code Execution via Database Restore File Upload
CVSS 9.1
CVE-2025-66451
MEDIUM
LibreChat < 0.8.1 - Improperly Controlled Modification of Dynamically-Determined Object Attributes via PATCH Endpoint
CVSS 6.5
CVE-2025-9315
MEDIUM
MXsecurity Series - Unauthenticated RCE
CVE-2025-66400
MEDIUM
mdast-util-to-hast <13.2.1 - Info Disclosure
CVSS 5.3
CVE-2025-13081
MEDIUM
Drupal 8.0.0-10.4.8, 10.5.0-10.5.5, 11.0.0-11.1.8, 11.2.0-11.2.7 - Object Injection
CVSS 5.9
CVE-2025-52656
HIGH
HCL MyXalytics: 6.6 - Info Disclosure
CVSS 7.6
CVE-2025-7104
HIGH
danny-avila/librechat - Mass Assignment
CVSS 7.5
CVE-2025-58367
CRITICAL
deepdiff 5.0.0-8.6.0 - Remote Code Execution via Delta Class Pollution and Pickle Deserialization
CVE-2025-6107
LOW
comfyanonymous comfyui <0.3.40 - Code Injection
CVSS 3.1
CVE-2025-49597
LOW
goodby-csv < 1.4.3 - Gadget Chain for Remote Code Execution via Insecure Deserialization
CVSS 3.9
CVE-2025-31674
HIGH
Drupal Drupal core <10.3.13-11.1.3 - Object Injection
CVSS 7.5
CVE-2025-30358
HIGH
Mesop < 0.14.1 - Class Pollution leading to Denial of Service and Identity Confusion
CVSS 8.1
CVE-2025-2304
CRITICAL
Camaleon CMS < 2.9.1 - Privilege Escalation via Mass Assignment in UsersController
CVE-2025-24370
CRITICAL
django-unicorn < 0.62.0 - Python Class Pollution via set_property_value
CVE-2024-57708
MEDIUM
OneTrust SDK 6.33.0 - Denial of Service via Prototype Pollution
CVSS 5.7
CVE-2024-10359
MEDIUM
danny-avila/librechat <0.7.5-rc2 - Code Injection
CVSS 4.6
CVE-2024-55638
CRITICAL
Drupal 7.0-7.101, 8.8.0-10.2.10, 10.3.0-10.3.8 - Deserialization of Untrusted Data
CVSS 9.8
CVE-2024-55637
CRITICAL
Drupal 8.0.0-10.2.10 10.3.0-10.3.8 11.0.0-11.0.7 - Object Injection via Insecure Deserialization
CVSS 9.8
CVE-2024-55636
CRITICAL
Drupal 8.0.0-10.2.10 10.3.0-10.3.8 11.0.0-11.0.7 - Object Injection via Insecure Deserialization
CVSS 9.8
CVE-2024-5452
CRITICAL
pytorch_lightning < 2.3.3 - Remote Code Execution via Deepdiff Delta Dunder Attribute Bypass
CVSS 9.8
CVE-2024-0404
CRITICAL
Mintplex-Labs Anything-LLM - Privilege Escalation
CVSS 9.1
CVE-2024-3283
HIGH
AnythingLLM < 1.0.0 - Authenticated Privilege Escalation via Mass Assignment in Admin System Preferences
CVSS 7.2
CVE-2023-39983
MEDIUM
MXsecurity <1.0.1 - Info Disclosure
CVSS 5.3
CVE-2023-32079
HIGH
Netmaker <0.17.1 and 0.18.6 - Privilege Escalation
CVSS 8.8
CVE-2023-0574
MEDIUM
YugabyteDB Managed 2.0.0.0-2.13.0.0 - Server-Side Request Forgery
CVSS 6.8
Details
Vulnerabilities
138