CWE-1321: CWE-1321

156
Total CVEs
73
Critical
69
High
8.5
Avg CVSS

Yearly Trend

2026
12
2025
28
2024
35
2023
19
2022
23

Top Affected Vendors

1 Mozilla 3
2 Mongoosejs 2
3 Agoric 2
4 Progress 2
5 Deep Get Set Project 2
6 Ag Grid 2
7 Elastic 2
8 Locutus 2
9 Putil Merge Project 2
10 Debian 2

All CWE-1321 CVEs (156)

CVE-2024-57084
7.5

This CVE describes a prototype pollution vulnerability in dot-properties v1.0.1's lib.parse function that allows attackers to cause Denial of Service ...

Feb 5, 2025
CVE-2024-57086
7.5

This CVE describes a prototype pollution vulnerability in the fieldsToJson function of node-opcua-alarm-condition v2.134.0. Attackers can exploit this...

Feb 5, 2025
CVE-2024-57066
7.5

This vulnerability allows attackers to perform prototype pollution in the lib.deep function of @ndhoule/defaults library version 2.0.1, potentially ca...

Feb 5, 2025
CVE-2024-57067
7.5

CVE-2024-57067 is a prototype pollution vulnerability in dot-qs v0.2.0's lib.parse function that allows attackers to inject malicious properties into ...

Feb 5, 2025
CVE-2024-57069
7.5

This vulnerability is a prototype pollution flaw in expand-object v0.4.2 that allows attackers to inject properties into JavaScript object prototypes....

Feb 5, 2025
CVE-2024-57071
7.5

A prototype pollution vulnerability in php-parser's lib.combine function allows attackers to manipulate object prototypes by supplying crafted payload...

Feb 5, 2025
CVE-2024-57072
7.5

A prototype pollution vulnerability in module-from-string v3.3.1's lib.requireFromString function allows attackers to inject malicious properties into...

Feb 5, 2025
CVE-2024-57063
7.5

This vulnerability is a prototype pollution flaw in php-date-formatter v1.3.6 that allows attackers to inject malicious properties into JavaScript obj...

Feb 5, 2025
CVE-2024-57064
7.5

A prototype pollution vulnerability in the lib.setValue function of @syncfusion/ej2-spreadsheet version 27.2.2 allows attackers to cause Denial of Ser...

Feb 5, 2025
CVE-2024-57065
7.5

A prototype pollution vulnerability in the lib.createPath function of utile v0.3.0 allows attackers to manipulate JavaScript object prototypes, potent...

Feb 5, 2025
CVE-2024-21548
7.5

This CVE describes a prototype pollution vulnerability in the Bun JavaScript runtime. Attackers can exploit this by passing malicious objects to Bun's...

Dec 18, 2024
CVE-2023-39296
7.5

A prototype pollution vulnerability in QNAP operating systems allows attackers to modify object prototypes, potentially causing system crashes via net...

Jan 5, 2024
CVE-2023-45282
7.5

CVE-2023-45282 is a prototype pollution vulnerability in NASA Open MCT (openmct) that allows attackers to modify JavaScript object prototypes through ...

Oct 6, 2023
CVE-2023-26132
7.5

CVE-2023-26132 is a prototype pollution vulnerability in the dottie JavaScript library that allows attackers to modify object prototypes, potentially ...

Jun 10, 2023
CVE-2023-26121
7.5

CVE-2023-26121 is a prototype pollution vulnerability in the safe-eval npm package that allows attackers to modify JavaScript object prototypes, poten...

Apr 11, 2023
CVE-2023-26113
7.5

This vulnerability allows attackers to perform prototype pollution attacks via the extend function in collection.js. It affects applications using col...

Mar 18, 2023
CVE-2023-26106
7.5

This vulnerability in the dot-lens JavaScript package allows attackers to perform prototype pollution attacks via the set() function. This can enable ...

Mar 6, 2023
CVE-2023-26102
7.5

CVE-2023-26102 is a prototype pollution vulnerability in the rangy JavaScript library that allows attackers to modify object prototypes through the ex...

Feb 24, 2023
CVE-2021-23373
7.5

CVE-2021-23373 is a prototype pollution vulnerability in the set-deep-prop npm package that allows attackers to modify object prototypes, potentially ...

Jul 25, 2022
CVE-2022-21231
7.5

CVE-2022-21231 is a prototype pollution vulnerability in the deep-get-set npm package that allows attackers to modify object prototypes, potentially l...

Jun 24, 2022
CVE-2022-21190
7.5

CVE-2022-21190 is a prototype pollution vulnerability in the convict configuration management library for Node.js that allows attackers to modify obje...

May 13, 2022
CVE-2022-25324
7.5

CVE-2022-25324 is a Denial of Service vulnerability in the bignum npm package where improper type checking in the .powm function causes V8 engine cras...

May 6, 2022
CVE-2022-22143
7.5

CVE-2022-22143 is a prototype pollution vulnerability in the convict configuration management library for Node.js. It allows attackers to modify objec...

May 1, 2022
CVE-2022-24279
7.5

CVE-2022-24279 is a prototype pollution vulnerability in madlib-object-utils package versions before 0.1.8. Attackers can exploit the setValue method ...

Apr 15, 2022
CVE-2022-25352
7.5

CVE-2022-25352 is a prototype pollution vulnerability in the libnested JavaScript library that allows attackers to modify object prototypes, potential...

Mar 17, 2022
CVE-2021-23597
7.5

This vulnerability in fastify-multipart allows attackers to crash Node.js applications by sending multipart form data with a 'name=constructor' proper...

Feb 11, 2022
CVE-2021-23507
7.5

CVE-2021-23507 is a prototype pollution vulnerability in the object-path-set npm package that allows attackers to modify JavaScript object prototypes....

Feb 4, 2022
CVE-2021-23460
7.5

This vulnerability allows attackers to perform prototype pollution attacks via the 'set' method in min-dash, enabling them to modify object prototypes...

Jan 21, 2022
CVE-2021-3805
7.5

CVE-2021-3805 is a prototype pollution vulnerability in the object-path npm package that allows attackers to modify JavaScript object prototypes, pote...

Sep 17, 2021
CVE-2026-23736
7.3

CVE-2026-23736 is a prototype pollution vulnerability in seroval's JSON deserialization functionality that allows attackers to modify JavaScript objec...

Jan 21, 2026
CVE-2025-13204
7.3

The npm package `expr-eval` is vulnerable to prototype pollution, allowing attackers to modify JavaScript object prototypes. This can lead to arbitrar...

Nov 14, 2025
CVE-2025-55195
7.3

This CVE describes a prototype pollution vulnerability in the @std/toml Deno Standard Library. Attackers can inject malicious properties into object p...

Aug 14, 2025
CVE-2025-3197
7.3

CVE-2025-3197 is a prototype pollution vulnerability in the expand-object npm package that allows attackers to modify JavaScript object prototypes by ...

Apr 4, 2025
CVE-2024-39003
7.3

CVE-2024-39003 is a prototype pollution vulnerability in amoyjs amoy common v1.0.10 that allows attackers to inject arbitrary properties into objects....

Jul 1, 2024
CVE-2023-26135
7.3

CVE-2023-26135 is a prototype pollution vulnerability in the flatnest npm package that allows attackers to modify object prototypes, potentially leadi...

Jun 30, 2023
CVE-2020-28461
7.3

CVE-2020-28461 is a prototype pollution vulnerability in the js-ini package that allows attackers to inject malicious properties into JavaScript objec...

Jul 25, 2022
CVE-2020-28471
7.3

CVE-2020-28471 is a prototype pollution vulnerability in the properties-reader npm package that allows attackers to inject arbitrary properties into J...

Jul 25, 2022
CVE-2022-21803
7.3

CVE-2022-21803 is a prototype pollution vulnerability in the nconf configuration management library when using the memory engine. Attackers can inject...

Apr 12, 2022
CVE-2026-25754
7.2

A prototype pollution vulnerability in AdonisJS multipart form-data parsing allows remote attackers to manipulate object prototypes at runtime. This c...

Feb 6, 2026
CVE-2024-22443
7.2

This vulnerability allows authenticated remote attackers to conduct server-side prototype pollution attacks in EdgeConnect SD-WAN Orchestrator's web m...

Jul 24, 2024
CVE-2022-3901
7.2

CVE-2022-3901 is a prototype pollution vulnerability in Visioweb.js 1.10.6 that allows attackers to inject malicious properties into JavaScript object...

Feb 20, 2023
CVE-2023-6293
7.1

This CVE describes a prototype pollution vulnerability in the sequelize-typescript library versions prior to 2.1.6. Attackers can inject malicious pro...

Nov 24, 2023
CVE-2024-34148
6.8

The Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 when builds are triggered ...

May 2, 2024
CVE-2026-24888
6.5

Maker.js versions up to 0.19.1 contain a prototype pollution vulnerability in the extendObject function that allows attackers to modify object prototy...

Jan 28, 2026
CVE-2024-39853
6.5

CVE-2024-39853 is a prototype pollution vulnerability in adolph_dudu ratio-swiper version 0.0.2 that allows attackers to inject arbitrary properties i...

Jul 1, 2024
CVE-2024-39001
6.3

CVE-2024-39001 is a prototype pollution vulnerability in ag-grid-enterprise v31.3.2 that allows attackers to inject arbitrary properties via the _Modu...

Jul 1, 2024
CVE-2025-62517
5.9

This CVE describes a prototype pollution vulnerability in Rollbar.js's merge() function when rollbar.configure() is called with untrusted input. Attac...

Oct 23, 2025
CVE-2024-36578
5.9

CVE-2024-36578 is a prototype pollution vulnerability in akbr update 1.0.0 that allows attackers to modify object prototypes, potentially leading to d...

Jun 17, 2024
CVE-2025-13465
5.3

Lodash versions 4.0.0 through 4.17.22 contain a prototype pollution vulnerability in _.unset and _.omit functions. Attackers can craft paths to delete...

Jan 21, 2026
CVE-2025-64718
5.3

This CVE describes a prototype pollution vulnerability in js-yaml, a JavaScript YAML parser. Attackers can modify object prototypes by injecting malic...

Nov 13, 2025

About CWE-1321 (CWE-1321)

Our database tracks 156 CVEs classified as CWE-1321, with 73 rated critical and 69 rated high severity. The average CVSS score for CWE-1321 vulnerabilities is 8.5.

External reference: View CWE-1321 on MITRE CWE →

Monitor CWE-1321 Vulnerabilities

Get alerted when new CWE-1321 CVEs affect your infrastructure.

Start Monitoring Free