Vulnerabilities (CVE)

Filtered by CWE-1321
Total 272 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-7637 1 Class-transformer Project 1 Class-transformer 2023-12-10 5.0 MEDIUM 5.3 MEDIUM
class-transformer before 0.3.1 allow attackers to perform Prototype Pollution. The classToPlainFromExist function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
CVE-2020-7644 1 Fun-map Project 1 Fun-map 2023-12-10 6.8 MEDIUM 8.1 HIGH
fun-map through 3.3.1 is vulnerable to Prototype Pollution. The function assocInM could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
CVE-2020-7726 1 Safe-object2 Project 1 Safe-object2 2023-12-10 7.5 HIGH 9.8 CRITICAL
All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function.
CVE-2020-7704 1 Linux-cmdline Project 1 Linux-cmdline 2023-12-10 7.5 HIGH 9.8 CRITICAL
The package linux-cmdline before 1.0.1 are vulnerable to Prototype Pollution via the constructor.
CVE-2020-7715 1 Deep-get-set Project 1 Deep-get-set 2023-12-10 7.5 HIGH 9.8 CRITICAL
All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function.
CVE-2020-7600 1 Querymen Project 1 Querymen 2023-12-10 5.0 MEDIUM 5.3 MEDIUM
querymen prior to 2.1.4 allows modification of object properties. The parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. This could be abused for Prototype Pollution attacks.
CVE-2020-7639 1 Dot Project 1 Dot 2023-12-10 5.0 MEDIUM 5.3 MEDIUM
eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
CVE-2020-7713 1 Arr-flatten-unflatten Project 1 Arr-flatten-unflatten 2023-12-10 7.5 HIGH 9.8 CRITICAL
All versions of package arr-flatten-unflatten are vulnerable to Prototype Pollution via the constructor.
CVE-2020-11066 1 Typo3 1 Typo3 2023-12-10 6.4 MEDIUM 10.0 CRITICAL
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, calling unserialize() on malicious user-submitted content can lead to modification of dynamically-determined object attributes and result in triggering deletion of an arbitrary directory in the file system, if it is writable for the web server. It can also trigger message submission via email using the identity of the web site (mail relay). Another insecure deserialization vulnerability is required to actually exploit mentioned aspects. This has been fixed in 9.5.17 and 10.4.2.
CVE-2020-7714 1 Realseriousgames 1 Confucious 2023-12-10 7.5 HIGH 9.8 CRITICAL
All versions of package confucious are vulnerable to Prototype Pollution via the set function.
CVE-2020-7723 1 Yola 1 Promisehelpers 2023-12-10 7.5 HIGH 9.8 CRITICAL
All versions of package promisehelpers are vulnerable to Prototype Pollution via the insert function.
CVE-2020-7616 1 Express-mock-middleware Project 1 Express-mock-middleware 2023-12-10 5.0 MEDIUM 5.3 MEDIUM
express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding or modifying properties of the `Object.prototype`. Exploitation of this vulnerability requires creation of a new directory where an attack code can be placed which will then be exported by `express-mock-middleware`. As such, this is considered to be a low risk.
CVE-2020-7706 1 Connie-lang Project 1 Connie-lang 2023-12-10 7.5 HIGH 9.8 CRITICAL
The package connie-lang before 0.1.1 are vulnerable to Prototype Pollution in the configuration language library used by connie.
CVE-2020-7718 1 Gammautils Project 1 Gammautils 2023-12-10 7.5 HIGH 9.8 CRITICAL
All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions.
CVE-2020-7722 1 Nodee-utils Project 1 Nodee-utils 2023-12-10 7.5 HIGH 9.8 CRITICAL
All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function.
CVE-2020-7700 1 Php.js Project 1 Php.js 2023-12-10 7.5 HIGH 9.8 CRITICAL
All versions of phpjs are vulnerable to Prototype Pollution via parse_str.
CVE-2020-7608 1 Yargs 1 Yargs-parser 2023-12-10 4.6 MEDIUM 5.3 MEDIUM
yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.
CVE-2020-15366 1 Ajv.js 1 Ajv 2023-12-10 6.8 MEDIUM 5.6 MEDIUM
An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an untrusted schema should be a denial of service, not execution of code.)
CVE-2020-7716 1 Invertase 1 Deeps 2023-12-10 7.5 HIGH 9.8 CRITICAL
All versions of package deeps are vulnerable to Prototype Pollution via the set function.
CVE-2020-7703 1 Nis-utils Project 1 Nis-utils 2023-12-10 7.5 HIGH 9.8 CRITICAL
All versions of package nis-utils are vulnerable to Prototype Pollution via the setValue function.