Vulnerabilities (CVE)

Filtered by CWE-1321
Total 314 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-23760 1 Keyget Project 1 Keyget 2022-02-04 7.5 HIGH 9.8 CRITICAL
The package keyget from 0.0.0 are vulnerable to Prototype Pollution via the methods set, push, and at which could allow an attacker to cause a denial of service and may lead to remote code execution. **Note:** This vulnerability derives from an incomplete fix to [CVE-2020-28272](https://security.snyk.io/vuln/SNYK-JS-KEYGET-1048048)
CVE-2021-23558 1 Bmoor Project 1 Bmoor 2022-02-04 7.5 HIGH 9.8 CRITICAL
The package bmoor before 0.10.1 are vulnerable to Prototype Pollution due to missing sanitization in set function. **Note:** This vulnerability derives from an incomplete fix in [CVE-2020-7736](https://security.snyk.io/vuln/SNYK-JS-BMOOR-598664)
CVE-2021-23460 1 Camunda 1 Min-dash 2022-01-26 5.0 MEDIUM 7.5 HIGH
The package min-dash before 3.8.1 are vulnerable to Prototype Pollution via the set method due to missing enforcement of key types.
CVE-2021-23568 1 Eggjs 1 Extend2 2022-01-13 7.5 HIGH 9.8 CRITICAL
The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive merge.
CVE-2021-23594 1 Agoric 1 Realms-shim 2022-01-13 7.5 HIGH 10.0 CRITICAL
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.
CVE-2021-23543 1 Agoric 1 Realms-shim 2022-01-13 7.5 HIGH 9.8 CRITICAL
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.
CVE-2021-43852 1 Oroinc 1 Oroplatform 2022-01-12 6.8 MEDIUM 8.8 HIGH
OroPlatform is a PHP Business Application Platform. In affected versions by sending a specially crafted request, an attacker could inject properties into existing JavaScript language construct prototypes, such as objects. Later this injection may lead to JS code execution by libraries that are vulnerable to Prototype Pollution. This issue has been patched in version 4.2.8. Users unable to upgrade may configure a firewall to drop requests containing next strings: `__proto__` , `constructor[prototype]`, and `constructor.prototype` to mitigate this issue.
CVE-2021-23574 1 Js-data 1 Js-data 2022-01-12 7.5 HIGH 9.8 CRITICAL
All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions. This is an incomplete fix of [CVE-2020-28442](https://snyk.io/vuln/SNYK-JS-JSDATA-1023655).
CVE-2020-28270 1 Mjpclab 1 Object-hierarchy-access 2022-01-06 7.5 HIGH 9.8 CRITICAL
Prototype pollution vulnerability in 'object-hierarchy-access' versions 0.2.0 through 0.32.0 allows attacker to cause a denial of service and may lead to remote code execution.
CVE-2021-23663 1 Sey Project 1 Sey 2021-12-14 7.5 HIGH 9.8 CRITICAL
All versions of package sey are vulnerable to Prototype Pollution via the deepmerge() function.
CVE-2021-23700 1 Merge-deep2 Project 1 Merge-deep2 2021-12-14 7.5 HIGH 9.8 CRITICAL
All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function.
CVE-2021-23561 1 C2fo 1 Comb 2021-12-14 7.5 HIGH 9.8 CRITICAL
All versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function.
CVE-2021-3815 1 Utils.js Project 1 Utils.js 2021-12-10 7.5 HIGH 9.8 CRITICAL
utils.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2021-23383 2 Handlebarsjs, Netapp 2 Handlebars, E-series Performance Analyzer 2021-12-03 7.5 HIGH 9.8 CRITICAL
The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.