CWE-1321: CWE-1321
Yearly Trend
Top Affected Vendors
All CWE-1321 CVEs (155)
CVE-2024-38999 is a prototype pollution vulnerability in requirejs v2.3.6 that allows attackers to inject arbitrary properties into object prototypes,...
Jul 1, 2024CVE-2024-39008 is a prototype pollution vulnerability in robinweser's fast-loops library version 1.1.3 that allows attackers to inject arbitrary prope...
Jul 1, 2024CVE-2026-26021 is a prototype pollution vulnerability in the npm package set-in that allows attackers to modify Object.prototype through crafted array...
Feb 11, 2026CVE-2025-61140 is a prototype pollution vulnerability in jsonpath 1.1.1 that allows attackers to modify object prototypes, potentially leading to remo...
Jan 28, 2026This CVE describes a prototype pollution vulnerability in the Elysia TypeScript framework that, when combined with a separate advisory (GHSA-8vch-m3f4...
Dec 9, 2025CVE-2025-49223 is a prototype pollution vulnerability in billboard.js that allows attackers to inject arbitrary properties into objects, potentially l...
Jun 4, 2025CVE-2024-38988 is a prototype pollution vulnerability in alizeait unflatto versions up to 1.0.2 that allows attackers to inject arbitrary properties i...
Mar 28, 2025This CVE describes a Prototype Pollution vulnerability in Aliconnect /sdk version 0.0.6 that allows attackers to execute arbitrary code through the ai...
Mar 28, 2025This CVE describes a Prototype Pollution vulnerability in the Quick Learn WordPress plugin that allows attackers to inject arbitrary objects into the ...
Nov 20, 2024CVE-2024-45435 is a prototype pollution vulnerability in Chartist.js that allows attackers to modify object prototypes, potentially leading to remote ...
Aug 29, 2024CVE-2024-38989 is a prototype pollution vulnerability in izatop bunt's qs.js component that allows attackers to inject arbitrary properties into objec...
Aug 12, 2024CVE-2024-38983 is a prototype pollution vulnerability in the alykoshin mini-deep-assign npm package version 0.0.8 that allows attackers to modify Java...
Jul 30, 2024CVE-2024-39011 is a prototype pollution vulnerability in chargeover redoc v2.0.9-rc.69 that allows attackers to modify JavaScript object prototypes, p...
Jul 30, 2024This CVE describes a prototype pollution vulnerability in allpro form-manager version 0.7.4 that allows attackers to inject arbitrary properties into ...
Jul 30, 2024CVE-2024-38986 is a prototype pollution vulnerability in the 75lb deep-merge library version 1.1.1 that allows attackers to modify object prototypes, ...
Jul 30, 2024This CVE describes a prototype pollution vulnerability in ag-grid-community and ag-grid-enterprise versions 31.3.2 via the _.mergeDeep function. Attac...
Jul 1, 2024CVE-2024-39014 is a prototype pollution vulnerability in ahilfoley cahil/utils v2.3.2 that allows attackers to inject arbitrary properties into object...
Jul 1, 2024CVE-2024-36573 is a prototype pollution vulnerability in almela obx versions before 0.0.4 that allows attackers to modify JavaScript object prototypes...
Jun 17, 2024CVE-2024-36582 is a prototype pollution vulnerability in the alexbinary object-deep-assign npm package that allows attackers to modify object prototyp...
Jun 17, 2024This vulnerability in the nora-firebase-common library allows remote attackers to execute arbitrary code by sending a crafted script to the updateStat...
Apr 18, 2024CVE-2024-29650 is a prototype pollution vulnerability in @thi.ng/paths library that allows remote attackers to execute arbitrary code via the mutIn an...
Mar 25, 2024This vulnerability in JSONata allows malicious expressions to override properties on the Object constructor and prototype, potentially leading to deni...
Mar 6, 2024This CVE describes a prototype pollution vulnerability in plotly.js that allows attackers to modify object prototypes through plot API calls. This aff...
Jan 3, 2024A prototype pollution vulnerability in hello.js version 1.18.6 allows attackers to modify JavaScript object prototypes, potentially leading to arbitra...
Aug 11, 2023CVE-2023-3696 is a prototype pollution vulnerability in Mongoose ODM library versions prior to 7.3.4. This allows attackers to inject arbitrary proper...
Jul 17, 2023This vulnerability in Parse Server allows attackers to perform prototype pollution attacks that can lead to remote code execution through the MongoDB ...
Jun 28, 2023CVE-2023-2972 is a prototype pollution vulnerability in antfu/utils library versions prior to 0.7.3. This allows attackers to inject properties into J...
May 30, 2023CVE-2023-30363 is a prototype pollution vulnerability in vConsole v3.15.0 that allows attackers to modify JavaScript object prototypes, potentially le...
Apr 26, 2023CVE-2022-2564 is a prototype pollution vulnerability in Mongoose, a MongoDB object modeling tool for Node.js. It allows attackers to inject arbitrary ...
Jul 28, 2022CVE-2022-1295 is a prototype pollution vulnerability in fullpage.js that allows attackers to modify JavaScript object prototypes, potentially leading ...
Apr 11, 2022This CVE describes a prototype pollution vulnerability in Sails.js versions up to 1.4.0 that allows attackers to modify JavaScript object prototypes. ...
Mar 17, 2022CVE-2022-22912 is a prototype pollution vulnerability in the Plist.js library's .parse() function that allows attackers to modify object prototypes. T...
Feb 17, 2022The realms-shim package is vulnerable to sandbox bypass via prototype pollution, allowing attackers to modify JavaScript object prototypes and potenti...
Jan 10, 2022The realms-shim package is vulnerable to sandbox bypass via prototype pollution, allowing attackers to modify JavaScript object prototypes and potenti...
Jan 10, 2022CVE-2021-3815 is a prototype pollution vulnerability in utils.js that allows attackers to modify object prototypes, potentially leading to denial of s...
Dec 8, 2021CVE-2021-3918 is a prototype pollution vulnerability in the json-schema library that allows attackers to modify object prototypes, potentially leading...
Nov 13, 2021CVE-2021-23449 is a Prototype Pollution vulnerability in the vm2 sandbox package that allows attackers to escape the sandbox and execute arbitrary cod...
Oct 18, 2021CVE-2021-3666 is a prototype pollution vulnerability in the body-parser-xml npm package that allows attackers to inject arbitrary properties into Java...
Sep 13, 2021CVE-2021-3766 is a prototype pollution vulnerability in objection.js that allows attackers to modify object prototypes, potentially leading to remote ...
Sep 6, 2021CVE-2021-3757 is a prototype pollution vulnerability in the immer JavaScript library that allows attackers to modify object prototypes, potentially le...
Sep 2, 2021CVE-2021-25953 is a prototype pollution vulnerability in the 'putil-merge' npm package that allows attackers to modify object prototypes, potentially ...
Jul 14, 2021This is a prototype pollution vulnerability in the 'just-safe-set' npm package that allows attackers to modify object prototypes, potentially leading ...
Jul 7, 2021CVE-2021-25948 is a prototype pollution vulnerability in the 'expand-hash' npm package that allows attackers to modify JavaScript object prototypes. T...
Jun 10, 2021This is a prototype pollution vulnerability in the 'nestie' JavaScript library that allows attackers to modify object prototypes, potentially leading ...
Jun 3, 2021CVE-2021-26707 is a prototype pollution vulnerability in the merge-deep Node.js library that allows attackers to modify Object.prototype properties. T...
Jun 2, 2021CVE-2021-25945 is a prototype pollution vulnerability in the 'js-extend' npm package that allows attackers to modify JavaScript object prototypes, pot...
May 26, 2021CVE-2021-25944 is a prototype pollution vulnerability in the 'deep-defaults' npm package versions 1.0.0 through 1.0.5. This allows attackers to modify...
May 25, 2021CVE-2021-25946 is a prototype pollution vulnerability in nconf-toml, a Node.js configuration file parser. It allows attackers to modify object prototy...
May 25, 2021CVE-2021-25941 is a prototype pollution vulnerability in the 'deep-override' npm package versions 1.0.0 through 1.0.1. This allows attackers to modify...
May 14, 2021CVE-2021-25927 is a prototype pollution vulnerability in the 'safe-flat' npm package versions 2.0.0 through 2.0.1. This allows attackers to modify obj...
Apr 26, 2021About CWE-1321 (CWE-1321)
Our database tracks 155 CVEs classified as CWE-1321, with 72 rated critical and 69 rated high severity. The average CVSS score for CWE-1321 vulnerabilities is 8.5.
External reference: View CWE-1321 on MITRE CWE →
Monitor CWE-1321 Vulnerabilities
Get alerted when new CWE-1321 CVEs affect your infrastructure.
Start Monitoring Free