Skip to main content

CWE archive

CWE-1321 CVEs

Programmatic archive

556 CVEs tagged with CWE-1321161 Critical, 225 High, 153 Medium, 17 Low, 0 Unrated.

CVE-2026-23929

Published Aug 18, 2026

Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__,…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-71553

Published Aug 17, 2026

ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id accepts the inherited path toString.call and passes it through…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-73654

Published Aug 13, 2026

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 3.3.8 until 4.5.6, the PUT /api/v1/runs/:runId/metadata endpoint passes attacker-c…

CVSS 8.5 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-73647

Published Aug 13, 2026

Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend() utility in ui/src/utils/extend/extend.js recursively cop…

CVSS 5.6 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-73562

Published Aug 13, 2026

Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update such as M…

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
22.9

CVE-2026-73088

Published Aug 11, 2026

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionall…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-72769

Published Aug 11, 2026

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An authenticated user able to create or edit a workflow expressio…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-72749

Published Aug 11, 2026

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the Edit Fields (Set) node. The node assigns output fields via a dot-notation path setter w…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-48170

Published Aug 7, 2026

`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `"…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-71438

Published Aug 6, 2026

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid's configuration setters (mermaid.initi…

CVSS 2.4 · Low
evidence mentions
6
Buzz score
24.5

CVE-2026-71437

Published Aug 6, 2026

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.5.0 until 11.16.1, Mermaid Architecture Diagrams are vulner…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-70610

Published Aug 5, 2026

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4, objects copied across t…

CVSS 5.4 · Medium
evidence mentions
13
Buzz score
31.4

CVE-2026-14574

Published Aug 5, 2026

In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` recursively merges preference values without rejecting prototy…

CVSS 5.7 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-67319

Published Aug 1, 2026

axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process's Object.prototype has already been pol…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-67316

Published Aug 1, 2026

axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dep…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-67314

Published Aug 1, 2026

axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js). When an…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-54737

Published Jul 31, 2026

@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5, defaultsDeep() recursively merges user-supplied obje…

CVSS 7.3 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-14893

Published Jul 28, 2026

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-66922

Published Jul 28, 2026

Pivotick used plain JavaScript objects as lookup tables indexed by caller-controlled graph node identifiers in its tree-layout and cycle-detection components. Node identifiers ma…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65913

Published Jul 23, 2026

DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype propertie…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-46681

Published Jul 21, 2026

@nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility library. Prior to version 0.14.0, the _copyProps function in lib/src/object/copy.ts uses for...in to iterate o…

CVSS 7.2 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-16266

Published Jul 21, 2026

Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attacker can modify the JavaScript prototype ch…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-53592

Published Jul 20, 2026

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A Prototype Pollution condition in the `getQueryParam` function `/public/js/main.js` and was add…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-16151

Published Jul 18, 2026

A vulnerability has been found in CartoDB carto-api-client 0.5.29. This impacts the function addFilter of the file src/filters.ts. Such manipulation of the argument column leads t…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-16150

Published Jul 18, 2026

A vulnerability was found in RobinHerbots Inputmask up to 5.0.9. Affected by this issue is the function extendDefaults/extendDefinitions/extendAliases in the library lib/dependenc…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
26.0
Showing 1-25 of 556 CVEsPage 1 of 23