CWE-1321: CWE-1321

155
Total CVEs
72
Critical
69
High
8.5
Avg CVSS

Yearly Trend

2026
12
2025
28
2024
35
2023
19
2022
23

Top Affected Vendors

1 Mozilla 3
2 Agoric 2
3 Deep Get Set Project 2
4 Ag Grid 2
5 Progress 2
6 Elastic 2
7 Locutus 2
8 Putil Merge Project 2
9 Debian 2
10 Mongoosejs 2

All CWE-1321 CVEs (155)

CVE-2024-38999
10.0

CVE-2024-38999 is a prototype pollution vulnerability in requirejs v2.3.6 that allows attackers to inject arbitrary properties into object prototypes,...

Jul 1, 2024
CVE-2024-39008
10.0

CVE-2024-39008 is a prototype pollution vulnerability in robinweser's fast-loops library version 1.1.3 that allows attackers to inject arbitrary prope...

Jul 1, 2024
CVE-2026-26021
9.8

CVE-2026-26021 is a prototype pollution vulnerability in the npm package set-in that allows attackers to modify Object.prototype through crafted array...

Feb 11, 2026
CVE-2025-61140
9.8

CVE-2025-61140 is a prototype pollution vulnerability in jsonpath 1.1.1 that allows attackers to modify object prototypes, potentially leading to remo...

Jan 28, 2026
CVE-2025-66456
9.8

This CVE describes a prototype pollution vulnerability in the Elysia TypeScript framework that, when combined with a separate advisory (GHSA-8vch-m3f4...

Dec 9, 2025
CVE-2025-49223
9.8

CVE-2025-49223 is a prototype pollution vulnerability in billboard.js that allows attackers to inject arbitrary properties into objects, potentially l...

Jun 4, 2025
CVE-2024-38988
9.8

CVE-2024-38988 is a prototype pollution vulnerability in alizeait unflatto versions up to 1.0.2 that allows attackers to inject arbitrary properties i...

Mar 28, 2025
CVE-2024-24292
9.8

This CVE describes a Prototype Pollution vulnerability in Aliconnect /sdk version 0.0.6 that allows attackers to execute arbitrary code through the ai...

Mar 28, 2025
CVE-2024-52441
9.8

This CVE describes a Prototype Pollution vulnerability in the Quick Learn WordPress plugin that allows attackers to inject arbitrary objects into the ...

Nov 20, 2024
CVE-2024-45435
9.8

CVE-2024-45435 is a prototype pollution vulnerability in Chartist.js that allows attackers to modify object prototypes, potentially leading to remote ...

Aug 29, 2024
CVE-2024-38989
9.8

CVE-2024-38989 is a prototype pollution vulnerability in izatop bunt's qs.js component that allows attackers to inject arbitrary properties into objec...

Aug 12, 2024
CVE-2024-38983
9.8

CVE-2024-38983 is a prototype pollution vulnerability in the alykoshin mini-deep-assign npm package version 0.0.8 that allows attackers to modify Java...

Jul 30, 2024
CVE-2024-39011
9.8

CVE-2024-39011 is a prototype pollution vulnerability in chargeover redoc v2.0.9-rc.69 that allows attackers to modify JavaScript object prototypes, p...

Jul 30, 2024
CVE-2024-36572
9.8

This CVE describes a prototype pollution vulnerability in allpro form-manager version 0.7.4 that allows attackers to inject arbitrary properties into ...

Jul 30, 2024
CVE-2024-38986
9.8

CVE-2024-38986 is a prototype pollution vulnerability in the 75lb deep-merge library version 1.1.1 that allows attackers to modify object prototypes, ...

Jul 30, 2024
CVE-2024-38996
9.8

This CVE describes a prototype pollution vulnerability in ag-grid-community and ag-grid-enterprise versions 31.3.2 via the _.mergeDeep function. Attac...

Jul 1, 2024
CVE-2024-39014
9.8

CVE-2024-39014 is a prototype pollution vulnerability in ahilfoley cahil/utils v2.3.2 that allows attackers to inject arbitrary properties into object...

Jul 1, 2024
CVE-2024-36573
9.8

CVE-2024-36573 is a prototype pollution vulnerability in almela obx versions before 0.0.4 that allows attackers to modify JavaScript object prototypes...

Jun 17, 2024
CVE-2024-36582
9.8

CVE-2024-36582 is a prototype pollution vulnerability in the alexbinary object-deep-assign npm package that allows attackers to modify object prototyp...

Jun 17, 2024
CVE-2024-30564
9.8

This vulnerability in the nora-firebase-common library allows remote attackers to execute arbitrary code by sending a crafted script to the updateStat...

Apr 18, 2024
CVE-2024-29650
9.8

CVE-2024-29650 is a prototype pollution vulnerability in @thi.ng/paths library that allows remote attackers to execute arbitrary code via the mutIn an...

Mar 25, 2024
CVE-2024-27307
9.8

This vulnerability in JSONata allows malicious expressions to override properties on the Object constructor and prototype, potentially leading to deni...

Mar 6, 2024
CVE-2023-46308
9.8

This CVE describes a prototype pollution vulnerability in plotly.js that allows attackers to modify object prototypes through plot API calls. This aff...

Jan 3, 2024
CVE-2021-26505
9.8

A prototype pollution vulnerability in hello.js version 1.18.6 allows attackers to modify JavaScript object prototypes, potentially leading to arbitra...

Aug 11, 2023
CVE-2023-3696
9.8

CVE-2023-3696 is a prototype pollution vulnerability in Mongoose ODM library versions prior to 7.3.4. This allows attackers to inject arbitrary proper...

Jul 17, 2023
CVE-2023-36475
9.8

This vulnerability in Parse Server allows attackers to perform prototype pollution attacks that can lead to remote code execution through the MongoDB ...

Jun 28, 2023
CVE-2023-2972
9.8

CVE-2023-2972 is a prototype pollution vulnerability in antfu/utils library versions prior to 0.7.3. This allows attackers to inject properties into J...

May 30, 2023
CVE-2023-30363
9.8

CVE-2023-30363 is a prototype pollution vulnerability in vConsole v3.15.0 that allows attackers to modify JavaScript object prototypes, potentially le...

Apr 26, 2023
CVE-2022-2564
9.8

CVE-2022-2564 is a prototype pollution vulnerability in Mongoose, a MongoDB object modeling tool for Node.js. It allows attackers to inject arbitrary ...

Jul 28, 2022
CVE-2022-1295
9.8

CVE-2022-1295 is a prototype pollution vulnerability in fullpage.js that allows attackers to modify JavaScript object prototypes, potentially leading ...

Apr 11, 2022
CVE-2021-44908
9.8

This CVE describes a prototype pollution vulnerability in Sails.js versions up to 1.4.0 that allows attackers to modify JavaScript object prototypes. ...

Mar 17, 2022
CVE-2022-22912
9.8

CVE-2022-22912 is a prototype pollution vulnerability in the Plist.js library's .parse() function that allows attackers to modify object prototypes. T...

Feb 17, 2022
CVE-2021-23594
9.8

The realms-shim package is vulnerable to sandbox bypass via prototype pollution, allowing attackers to modify JavaScript object prototypes and potenti...

Jan 10, 2022
CVE-2021-23543
9.8

The realms-shim package is vulnerable to sandbox bypass via prototype pollution, allowing attackers to modify JavaScript object prototypes and potenti...

Jan 10, 2022
CVE-2021-3815
9.8

CVE-2021-3815 is a prototype pollution vulnerability in utils.js that allows attackers to modify object prototypes, potentially leading to denial of s...

Dec 8, 2021
CVE-2021-3918
9.8

CVE-2021-3918 is a prototype pollution vulnerability in the json-schema library that allows attackers to modify object prototypes, potentially leading...

Nov 13, 2021
CVE-2021-23449
9.8

CVE-2021-23449 is a Prototype Pollution vulnerability in the vm2 sandbox package that allows attackers to escape the sandbox and execute arbitrary cod...

Oct 18, 2021
CVE-2021-3666
9.8

CVE-2021-3666 is a prototype pollution vulnerability in the body-parser-xml npm package that allows attackers to inject arbitrary properties into Java...

Sep 13, 2021
CVE-2021-3766
9.8

CVE-2021-3766 is a prototype pollution vulnerability in objection.js that allows attackers to modify object prototypes, potentially leading to remote ...

Sep 6, 2021
CVE-2021-3757
9.8

CVE-2021-3757 is a prototype pollution vulnerability in the immer JavaScript library that allows attackers to modify object prototypes, potentially le...

Sep 2, 2021
CVE-2021-25953
9.8

CVE-2021-25953 is a prototype pollution vulnerability in the 'putil-merge' npm package that allows attackers to modify object prototypes, potentially ...

Jul 14, 2021
CVE-2021-25952
9.8

This is a prototype pollution vulnerability in the 'just-safe-set' npm package that allows attackers to modify object prototypes, potentially leading ...

Jul 7, 2021
CVE-2021-25948
9.8

CVE-2021-25948 is a prototype pollution vulnerability in the 'expand-hash' npm package that allows attackers to modify JavaScript object prototypes. T...

Jun 10, 2021
CVE-2021-25947
9.8

This is a prototype pollution vulnerability in the 'nestie' JavaScript library that allows attackers to modify object prototypes, potentially leading ...

Jun 3, 2021
CVE-2021-26707
9.8

CVE-2021-26707 is a prototype pollution vulnerability in the merge-deep Node.js library that allows attackers to modify Object.prototype properties. T...

Jun 2, 2021
CVE-2021-25945
9.8

CVE-2021-25945 is a prototype pollution vulnerability in the 'js-extend' npm package that allows attackers to modify JavaScript object prototypes, pot...

May 26, 2021
CVE-2021-25944
9.8

CVE-2021-25944 is a prototype pollution vulnerability in the 'deep-defaults' npm package versions 1.0.0 through 1.0.5. This allows attackers to modify...

May 25, 2021
CVE-2021-25946
9.8

CVE-2021-25946 is a prototype pollution vulnerability in nconf-toml, a Node.js configuration file parser. It allows attackers to modify object prototy...

May 25, 2021
CVE-2021-25941
9.8

CVE-2021-25941 is a prototype pollution vulnerability in the 'deep-override' npm package versions 1.0.0 through 1.0.1. This allows attackers to modify...

May 14, 2021
CVE-2021-25927
9.8

CVE-2021-25927 is a prototype pollution vulnerability in the 'safe-flat' npm package versions 2.0.0 through 2.0.1. This allows attackers to modify obj...

Apr 26, 2021

About CWE-1321 (CWE-1321)

Our database tracks 155 CVEs classified as CWE-1321, with 72 rated critical and 69 rated high severity. The average CVSS score for CWE-1321 vulnerabilities is 8.5.

External reference: View CWE-1321 on MITRE CWE →

Monitor CWE-1321 Vulnerabilities

Get alerted when new CWE-1321 CVEs affect your infrastructure.

Start Monitoring Free