CWE-1321: CWE-1321

160
Total CVEs
77
Critical
69
High
8.5
Avg CVSS

Yearly Trend

2026
12
2025
28
2024
35
2023
19
2022
23

Top Affected Vendors

1 Mozilla 3
2 Mongoosejs 2
3 Agoric 2
4 Progress 2
5 Deep Get Set Project 2
6 Ag Grid 2
7 Elastic 2
8 Locutus 2
9 Putil Merge Project 2
10 Debian 2

All CWE-1321 CVEs (160)

CVE-2025-62517
5.9

This CVE describes a prototype pollution vulnerability in Rollbar.js's merge() function when rollbar.configure() is called with untrusted input. Attac...

Oct 23, 2025
CVE-2024-36578
5.9

CVE-2024-36578 is a prototype pollution vulnerability in akbr update 1.0.0 that allows attackers to modify object prototypes, potentially leading to d...

Jun 17, 2024
CVE-2025-13465
5.3

Lodash versions 4.0.0 through 4.17.22 contain a prototype pollution vulnerability in _.unset and _.omit functions. Attackers can craft paths to delete...

Jan 21, 2026
CVE-2025-64718
5.3

This CVE describes a prototype pollution vulnerability in js-yaml, a JavaScript YAML parser. Attackers can modify object prototypes by injecting malic...

Nov 13, 2025
CVE-2026-24766
4.9

An authenticated user with org-level-creator permissions in NocoDB can exploit prototype pollution in the connection test endpoint, causing all databa...

Jan 28, 2026
CVE-2024-45277
4.3

The SAP HANA Node.js client package versions 2.0.0 through 2.21.30 are vulnerable to prototype pollution when using the nestTables feature. This allow...

Oct 8, 2024
CVE-2024-54156
4.2

This CVE describes a prototype pollution vulnerability in JetBrains YouTrack issue tracking software. Attackers can manipulate JavaScript object proto...

Dec 4, 2024
CVE-2024-11628
4.1

This CVE describes a prototype pollution vulnerability in Progress Telerik Kendo UI for Vue components. Attackers can manipulate global prototype obje...

Feb 12, 2025
CVE-2024-12629
4.1

This CVE describes a prototype pollution vulnerability in Progress Telerik KendoReact components where attackers can inject malicious properties into ...

Feb 12, 2025
CVE-2025-13158
N/A

This CVE describes a prototype pollution vulnerability in apidoc-core that allows remote attackers to modify JavaScript object prototypes through malf...

Dec 26, 2025

About CWE-1321 (CWE-1321)

Our database tracks 160 CVEs classified as CWE-1321, with 77 rated critical and 69 rated high severity. The average CVSS score for CWE-1321 vulnerabilities is 8.5.

External reference: View CWE-1321 on MITRE CWE →

Monitor CWE-1321 Vulnerabilities

Get alerted when new CWE-1321 CVEs affect your infrastructure.

Start Monitoring Free