CWE-1321: CWE-1321
Yearly Trend
Top Affected Vendors
All CWE-1321 CVEs (156)
This CVE describes a prototype pollution vulnerability in dot-properties v1.0.1's lib.parse function that allows attackers to cause Denial of Service ...
Feb 5, 2025This CVE describes a prototype pollution vulnerability in the fieldsToJson function of node-opcua-alarm-condition v2.134.0. Attackers can exploit this...
Feb 5, 2025This vulnerability allows attackers to perform prototype pollution in the lib.deep function of @ndhoule/defaults library version 2.0.1, potentially ca...
Feb 5, 2025CVE-2024-57067 is a prototype pollution vulnerability in dot-qs v0.2.0's lib.parse function that allows attackers to inject malicious properties into ...
Feb 5, 2025This vulnerability is a prototype pollution flaw in expand-object v0.4.2 that allows attackers to inject properties into JavaScript object prototypes....
Feb 5, 2025A prototype pollution vulnerability in php-parser's lib.combine function allows attackers to manipulate object prototypes by supplying crafted payload...
Feb 5, 2025A prototype pollution vulnerability in module-from-string v3.3.1's lib.requireFromString function allows attackers to inject malicious properties into...
Feb 5, 2025This vulnerability is a prototype pollution flaw in php-date-formatter v1.3.6 that allows attackers to inject malicious properties into JavaScript obj...
Feb 5, 2025A prototype pollution vulnerability in the lib.setValue function of @syncfusion/ej2-spreadsheet version 27.2.2 allows attackers to cause Denial of Ser...
Feb 5, 2025A prototype pollution vulnerability in the lib.createPath function of utile v0.3.0 allows attackers to manipulate JavaScript object prototypes, potent...
Feb 5, 2025This CVE describes a prototype pollution vulnerability in the Bun JavaScript runtime. Attackers can exploit this by passing malicious objects to Bun's...
Dec 18, 2024A prototype pollution vulnerability in QNAP operating systems allows attackers to modify object prototypes, potentially causing system crashes via net...
Jan 5, 2024CVE-2023-45282 is a prototype pollution vulnerability in NASA Open MCT (openmct) that allows attackers to modify JavaScript object prototypes through ...
Oct 6, 2023CVE-2023-26132 is a prototype pollution vulnerability in the dottie JavaScript library that allows attackers to modify object prototypes, potentially ...
Jun 10, 2023CVE-2023-26121 is a prototype pollution vulnerability in the safe-eval npm package that allows attackers to modify JavaScript object prototypes, poten...
Apr 11, 2023This vulnerability allows attackers to perform prototype pollution attacks via the extend function in collection.js. It affects applications using col...
Mar 18, 2023This vulnerability in the dot-lens JavaScript package allows attackers to perform prototype pollution attacks via the set() function. This can enable ...
Mar 6, 2023CVE-2023-26102 is a prototype pollution vulnerability in the rangy JavaScript library that allows attackers to modify object prototypes through the ex...
Feb 24, 2023CVE-2021-23373 is a prototype pollution vulnerability in the set-deep-prop npm package that allows attackers to modify object prototypes, potentially ...
Jul 25, 2022CVE-2022-21231 is a prototype pollution vulnerability in the deep-get-set npm package that allows attackers to modify object prototypes, potentially l...
Jun 24, 2022CVE-2022-21190 is a prototype pollution vulnerability in the convict configuration management library for Node.js that allows attackers to modify obje...
May 13, 2022CVE-2022-25324 is a Denial of Service vulnerability in the bignum npm package where improper type checking in the .powm function causes V8 engine cras...
May 6, 2022CVE-2022-22143 is a prototype pollution vulnerability in the convict configuration management library for Node.js. It allows attackers to modify objec...
May 1, 2022CVE-2022-24279 is a prototype pollution vulnerability in madlib-object-utils package versions before 0.1.8. Attackers can exploit the setValue method ...
Apr 15, 2022CVE-2022-25352 is a prototype pollution vulnerability in the libnested JavaScript library that allows attackers to modify object prototypes, potential...
Mar 17, 2022This vulnerability in fastify-multipart allows attackers to crash Node.js applications by sending multipart form data with a 'name=constructor' proper...
Feb 11, 2022CVE-2021-23507 is a prototype pollution vulnerability in the object-path-set npm package that allows attackers to modify JavaScript object prototypes....
Feb 4, 2022This vulnerability allows attackers to perform prototype pollution attacks via the 'set' method in min-dash, enabling them to modify object prototypes...
Jan 21, 2022CVE-2021-3805 is a prototype pollution vulnerability in the object-path npm package that allows attackers to modify JavaScript object prototypes, pote...
Sep 17, 2021CVE-2026-23736 is a prototype pollution vulnerability in seroval's JSON deserialization functionality that allows attackers to modify JavaScript objec...
Jan 21, 2026The npm package `expr-eval` is vulnerable to prototype pollution, allowing attackers to modify JavaScript object prototypes. This can lead to arbitrar...
Nov 14, 2025This CVE describes a prototype pollution vulnerability in the @std/toml Deno Standard Library. Attackers can inject malicious properties into object p...
Aug 14, 2025CVE-2025-3197 is a prototype pollution vulnerability in the expand-object npm package that allows attackers to modify JavaScript object prototypes by ...
Apr 4, 2025CVE-2024-39003 is a prototype pollution vulnerability in amoyjs amoy common v1.0.10 that allows attackers to inject arbitrary properties into objects....
Jul 1, 2024CVE-2023-26135 is a prototype pollution vulnerability in the flatnest npm package that allows attackers to modify object prototypes, potentially leadi...
Jun 30, 2023CVE-2020-28461 is a prototype pollution vulnerability in the js-ini package that allows attackers to inject malicious properties into JavaScript objec...
Jul 25, 2022CVE-2020-28471 is a prototype pollution vulnerability in the properties-reader npm package that allows attackers to inject arbitrary properties into J...
Jul 25, 2022CVE-2022-21803 is a prototype pollution vulnerability in the nconf configuration management library when using the memory engine. Attackers can inject...
Apr 12, 2022A prototype pollution vulnerability in AdonisJS multipart form-data parsing allows remote attackers to manipulate object prototypes at runtime. This c...
Feb 6, 2026This vulnerability allows authenticated remote attackers to conduct server-side prototype pollution attacks in EdgeConnect SD-WAN Orchestrator's web m...
Jul 24, 2024CVE-2022-3901 is a prototype pollution vulnerability in Visioweb.js 1.10.6 that allows attackers to inject malicious properties into JavaScript object...
Feb 20, 2023This CVE describes a prototype pollution vulnerability in the sequelize-typescript library versions prior to 2.1.6. Attackers can inject malicious pro...
Nov 24, 2023The Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 when builds are triggered ...
May 2, 2024Maker.js versions up to 0.19.1 contain a prototype pollution vulnerability in the extendObject function that allows attackers to modify object prototy...
Jan 28, 2026CVE-2024-39853 is a prototype pollution vulnerability in adolph_dudu ratio-swiper version 0.0.2 that allows attackers to inject arbitrary properties i...
Jul 1, 2024CVE-2024-39001 is a prototype pollution vulnerability in ag-grid-enterprise v31.3.2 that allows attackers to inject arbitrary properties via the _Modu...
Jul 1, 2024This CVE describes a prototype pollution vulnerability in Rollbar.js's merge() function when rollbar.configure() is called with untrusted input. Attac...
Oct 23, 2025CVE-2024-36578 is a prototype pollution vulnerability in akbr update 1.0.0 that allows attackers to modify object prototypes, potentially leading to d...
Jun 17, 2024Lodash versions 4.0.0 through 4.17.22 contain a prototype pollution vulnerability in _.unset and _.omit functions. Attackers can craft paths to delete...
Jan 21, 2026This CVE describes a prototype pollution vulnerability in js-yaml, a JavaScript YAML parser. Attackers can modify object prototypes by injecting malic...
Nov 13, 2025About CWE-1321 (CWE-1321)
Our database tracks 156 CVEs classified as CWE-1321, with 73 rated critical and 69 rated high severity. The average CVSS score for CWE-1321 vulnerabilities is 8.5.
External reference: View CWE-1321 on MITRE CWE →
Monitor CWE-1321 Vulnerabilities
Get alerted when new CWE-1321 CVEs affect your infrastructure.
Start Monitoring Free