Skip to main content

CWE archive

CWE-1321 CVEs

Programmatic archive

548 CVEs tagged with CWE-1321161 Critical, 220 High, 150 Medium, 17 Low, 0 Unrated.

CVE-2026-15698

Published Jul 14, 2026

A vulnerability was determined in kofrasa mingo up to 7.2.1. This impacts the function update/updateOne/updateMany of the component Update API. Executing a manipulation of the arg…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-15697

Published Jul 14, 2026

A vulnerability was found in svgdotjs svg.js up to 3.2.5. This affects the function EventTarget.on of the file svgdotjs/svg.js of the component npm Package API. Performing a manip…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-15607

Published Jul 13, 2026

A vulnerability was detected in tanstack db up to 0.6.8. Affected by this vulnerability is the function select of the file src/query/compiler/select.ts of the component Alias Path…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-15598

Published Jul 13, 2026

A weakness has been identified in antv layout 2.0.0. This impacts the function setNestedValue in the library lib/util/object.js. Executing a manipulation of the argument path can…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-15538

Published Jul 13, 2026

A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the function ObjectUtils.mutateFieldData of the component API. This manipulation of the ar…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
27.3

CVE-2026-56763

Published Jul 11, 2026

Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially crafted form field names to create objects with __proto__ properties. When parse…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-15195

Published Jul 9, 2026

A weakness has been identified in apidevtools json-schema-ref-parser up to 15.3.5. This impacts the function Refs.set/Pointer.set in the library lib/pointer.ts. Executing a manipu…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-59206

Published Jul 9, 2026

n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated user with the default workflow:create permission could pollute Object.…

CVSS 7.1 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-15187

Published Jul 9, 2026

A security flaw has been discovered in enquirer up to 2.4.1. Affected is the function Enquirer.set of the component Public Package API. The manipulation of the argument question.n…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-59876

Published Jul 8, 2026

protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text Format extension parsed string-keyed map entries using ordinar…

CVSS 4.8 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-57439

Published Jul 8, 2026

CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.2.0, the Series Chart operation accepts __proto__ as a key while parsing user-supplied…

CVSS 5.0 · Medium
evidence mentions
5
Buzz score
22.9

CVE-2026-55886

Published Jul 1, 2026

Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. Versions prior to 4.12.26 are vulnerable to Prototype Pollution through Jodit…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-54756

Published Jul 1, 2026

Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. In versions prior to 4.12.18, Jodit.configure(options) — and the internal Con…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-57926

Published Jun 26, 2026

In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack

CVSS 2.6 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-54639

Published Jun 24, 2026

Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulnerability starting in version 4.3.0 and prior to version 5.4.4. Impact users hav…

CVSS 8.8 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-54306

Published Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, a prototype pollution vulnerability allowed a crafted public webhook payload to inject attacker-con…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44791

Published Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could bypass the pat…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44789

Published Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could achieve global…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
16.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-54312

Published Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with permission to create or modify workflows could achieve global prototype pollution v…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-55388

Published Jun 22, 2026

piscina is a node.js worker pool implementation. Prior to 6.0.0-rc.2, 5.2.0, and 4.9.3, piscina's constructor and run() paths read the filename option via plain member access. Bot…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-49252

Published Jun 18, 2026

deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. Versions prior to 10.0.5 are vulnerable to Prototype Pollution…

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-53676

Published Jun 17, 2026

ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed context by a user who can log in to the affected product wit…

CVSS 8.6 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-48714

Published Jun 15, 2026

i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. In versions prior to 3.9.7, the missingKeyHandler blocked…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-48713

Published Jun 15, 2026

Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing translation keys (e.g. via i18next-http-middleware's mis…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-12209

Published Jun 15, 2026

A security vulnerability has been detected in RubyLouvre avalon up to 2.2.10. The impacted element is an unknown function of the file src/filters/index.js of the component Templat…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4
Showing 26-50 of 548 CVEsPage 2 of 22