Skip to main content

CWE archive

CWE-1321 CVEs

Programmatic archive

537 CVEs tagged with CWE-1321160 Critical, 218 High, 143 Medium, 16 Low, 0 Unrated.

CVE-2026-65913

Published Jul 23, 2026

DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype propertie…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-46681

Published Jul 21, 2026

@nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility library. Prior to version 0.14.0, the _copyProps function in lib/src/object/copy.ts uses for...in to iterate o…

CVSS 7.2 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-16266

Published Jul 21, 2026

Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attacker can modify the JavaScript prototype ch…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-53592

Published Jul 20, 2026

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A Prototype Pollution condition in the `getQueryParam` function `/public/js/main.js` and was add…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-16151

Published Jul 18, 2026

A vulnerability has been found in CartoDB carto-api-client 0.5.29. This impacts the function addFilter of the file src/filters.ts. Such manipulation of the argument column leads t…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-16150

Published Jul 18, 2026

A vulnerability was found in RobinHerbots Inputmask up to 5.0.9. Affected by this issue is the function extendDefaults/extendDefinitions/extendAliases in the library lib/dependenc…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-54335

Published Jul 17, 2026

Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In 5.0.44 and earlier, the _.merge(target, source) utility exported by @f…

CVSS 3.7 · Low
evidence mentions
4
Buzz score
21.1

CVE-2026-48819

Published Jul 17, 2026

Hey API is an ecosystem for turning API specifications into production-ready code. Prior to 0.97.3, dist/clients/core/params.ts ships a runtime template copied into generated SDKs…

CVSS 4.8 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-16008

Published Jul 17, 2026

A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This impacts the function parsePropertyDependencies of the file src/keywords/propertyDepend…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-45325

Published Jul 16, 2026

Gestor de Oferta is a web application for managing mobility service offerings. Prior to 20260509.0340.15, @tmlmobilidade/utils has a prototype pollution vulnerability in setValueA…

CVSS 8.2 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-48795

Published Jul 15, 2026

AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompletely fixed CVE-2026-25754 because nested multipart field p…

CVSS 8.6 · High
evidence mentions
5
Buzz score
22.9

CVE-2026-49459

Published Jul 14, 2026

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attribu…

CVSS 6.1 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-15702

Published Jul 14, 2026

A security vulnerability has been detected in tamagui up to 2.3.0. This affects the function updateConfig of the file code/core/web/src/config.ts. Such manipulation leads to impro…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-15699

Published Jul 14, 2026

A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the function nlp.extend of the file src/API/extend.js of the component Public Root API. The…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-15698

Published Jul 14, 2026

A vulnerability was determined in kofrasa mingo up to 7.2.1. This impacts the function update/updateOne/updateMany of the component Update API. Executing a manipulation of the arg…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-15697

Published Jul 14, 2026

A vulnerability was found in svgdotjs svg.js up to 3.2.5. This affects the function EventTarget.on of the file svgdotjs/svg.js of the component npm Package API. Performing a manip…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-15607

Published Jul 13, 2026

A vulnerability was detected in tanstack db up to 0.6.8. Affected by this vulnerability is the function select of the file src/query/compiler/select.ts of the component Alias Path…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-15598

Published Jul 13, 2026

A weakness has been identified in antv layout 2.0.0. This impacts the function setNestedValue in the library lib/util/object.js. Executing a manipulation of the argument path can…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-15538

Published Jul 13, 2026

A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the function ObjectUtils.mutateFieldData of the component API. This manipulation of the ar…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
27.3

CVE-2026-56763

Published Jul 11, 2026

Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially crafted form field names to create objects with __proto__ properties. When parse…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-15195

Published Jul 9, 2026

A weakness has been identified in apidevtools json-schema-ref-parser up to 15.3.5. This impacts the function Refs.set/Pointer.set in the library lib/pointer.ts. Executing a manipu…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-59206

Published Jul 9, 2026

n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated user with the default workflow:create permission could pollute Object.…

CVSS 7.1 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-15187

Published Jul 9, 2026

A security flaw has been discovered in enquirer up to 2.4.1. Affected is the function Enquirer.set of the component Public Package API. The manipulation of the argument question.n…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-59876

Published Jul 8, 2026

protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text Format extension parsed string-keyed map entries using ordinar…

CVSS 4.8 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-57439

Published Jul 8, 2026

CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.2.0, the Series Chart operation accepts __proto__ as a key while parsing user-supplied…

CVSS 5.0 · Medium
evidence mentions
5
Buzz score
22.9
Showing 1-25 of 537 CVEsPage 1 of 22