CWE-471 · 38 kayıt
Modification of Assumed-Immutable Data (MAID)
Bu sınıftaki CVE’ler
38 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-8147İstismar yok | Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that may result in remotutils-extend project · utils-extend · CWE-471 | Kritik9,8 | — | %3,1 | 3 Nis 2020 |
40Planlayın | CVE-2020-8158Kavram kanıtı | Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further typeorm · typeorm · CWE-471 | Kritik9,8 | — | %2,1 | 18 Eyl 2020 |
39İzleyin | CVE-2022-25893İstismar yok | Arbitrary Code Executionvm2 project · vm2 · CWE-471 | Kritik9,8 | — | %1,4 | 21 Ara 2022 |
39İzleyin | CVE-2026-50481İstismar yok | Azure Active Directory Elevation of Privilege Vulnerabilitymicrosoft · azure active directory · CWE-471 | Kritik9,9 | — | %0,8 | 6 Ağu 2026 |
38İzleyin | CVE-2022-21824İstismar yok | Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "propertiesnodejs · node.js · CWE-471 | Yüksek8,2 | — | %21,5 | 24 Şub 2022 |
36İzleyin | CVE-2018-3728İstismar yok | hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge' hapijs · hoek · CWE-471 | Yüksek8,8 | — | %4,2 | 30 Mar 2018 |
36İzleyin | CVE-2018-3719İstismar yok | mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious usemixin-deep project · mixin-deep · CWE-471 | Yüksek8,8 | — | %2,1 | 6 Haz 2018 |
36İzleyin | CVE-2018-3722İstismar yok | merge-deep node module before 3.0.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious usemerge-deep project · merge-deep · CWE-471 | Yüksek8,8 | — | %2,0 | 6 Haz 2018 |
36İzleyin | CVE-2018-3723İstismar yok | defaults-deep node module before 0.2.4 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious defaults-deep project · defaults-deep · CWE-471 | Yüksek8,8 | — | %2,0 | 6 Haz 2018 |
36İzleyin | CVE-2018-3720İstismar yok | assign-deep node module before 0.4.7 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious usassign-deep project · assign-deep · CWE-471 | Yüksek8,8 | — | %2,0 | 6 Haz 2018 |
35İzleyin | CVE-2025-33136İstismar yok | IBM Aspera Faspex data modificationibm · aspera faspex · CWE-471 | Yüksek8,8 | — | %0,3 | 22 May 2025 |
34İzleyin | CVE-2020-26237İstismar yok | Prototype Pollution in highlight.jshighlightjs · highlight.js · CWE-471 | Yüksek8,7 | — | %1,3 | 24 Kas 2020 |
34İzleyin | CVE-2024-9876İstismar yok | Application is vulnerable to Privilege escalationabb · anc · CWE-471 | Yüksek8,5 | — | %0,3 | 30 Nis 2025 |
33İzleyin | CVE-2024-55551İstismar yok | An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10).exasol · jdbc driver · CWE-471 | Yüksek8,3 | — | %0,6 | 19 Mar 2025 |
33İzleyin | CVE-2022-2390İstismar yok | Mutable pending intent in Google Play services SDKgoogle · google play services software development kit · CWE-471 | Yüksek8,4 | — | %0,1 | 12 Ağu 2022 |
32İzleyin | GHSA-m9hw-7xfv-wqg7İstismar yok | Prototype Pollution in json-logic-jsnpm · json-logic-js · CWE-471 | Yüksek8,0 | — | — | 12 Kas 2020 |
30İzleyin | CVE-2020-8116İstismar yok | Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbidot-prop project · dot-prop · CWE-471 | Yüksek7,3 | — | %3,1 | 4 Şub 2020 |
30İzleyin | CVE-2020-8268İstismar yok | Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties ofjson8-merge-patch project · json8-merge-patch · CWE-471 | Yüksek7,5 | — | %1,3 | 9 Kas 2020 |
29İzleyin | CVE-2023-2904İstismar yok | The External Visitor Manager portal of HID’s SAFE versions 5.8.0 through 5.11.3 are vulnerable to manipulation within web fields in the applhidglobal · safe · CWE-471 | Yüksek7,3 | — | %0,6 | 7 Haz 2023 |
29İzleyin | GHSA-q42p-pg8m-cqh6İstismar yok | Prototype Pollution in handlebarsnpm · handlebars · CWE-471 | Yüksek7,3 | — | — | 5 Haz 2019 |
28İzleyin | CVE-2026-44798İstismar yok | Nautobot: GitRepository.current_head field should not be writable through REST APInetworktocode · nautobot · CWE-471 | Yüksek7,1 | — | %0,5 | 28 May 2026 |
27İzleyin | CVE-2018-3721İstismar yok | lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and merlodash · lodash · CWE-471 | Orta6,5 | — | %2,4 | 6 Haz 2018 |
26İzleyin | CVE-2023-43697İstismar yok | Modification of Assumed-Immutable Data (MAID) in RDT400 in SICK APU allows an unprivileged remote attacker to make the site unable to load sick · apu0200 firmware · CWE-471 | Orta6,5 | — | %0,6 | 9 Eki 2023 |
26İzleyin | CVE-2024-34517İstismar yok | The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin acceneo4j · neo4j · CWE-471 | Orta6,5 | — | %0,6 | 7 May 2024 |
26İzleyin | CVE-2021-37177İstismar yok | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2).siemens · sinema remote connect server · CWE-471 | Orta6,5 | — | %0,4 | 14 Eyl 2021 |
- CVE-2020-814740Planlayın
Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that may result in remot
KritikCVSS 9,8İstismar yokEPSS %3utils-extend project · utils-extend3 Nis 2020
- CVE-2020-815840Planlayın
Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further
KritikCVSS 9,8Kavram kanıtıEPSS %2typeorm · typeorm18 Eyl 2020
- CVE-2022-2589339İzleyin
Arbitrary Code Execution
KritikCVSS 9,8İstismar yokEPSS %1vm2 project · vm221 Ara 2022
- CVE-2026-5048139İzleyin
Azure Active Directory Elevation of Privilege Vulnerability
KritikCVSS 9,9İstismar yokEPSS %1microsoft · azure active directory6 Ağu 2026
- CVE-2022-2182438İzleyin
Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties
YüksekCVSS 8,2İstismar yokEPSS %22nodejs · node.js24 Şub 2022
- CVE-2018-372836İzleyin
hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge'
YüksekCVSS 8,8İstismar yokEPSS %4hapijs · hoek30 Mar 2018
- CVE-2018-371936İzleyin
mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious use
YüksekCVSS 8,8İstismar yokEPSS %2mixin-deep project · mixin-deep6 Haz 2018
- CVE-2018-372236İzleyin
merge-deep node module before 3.0.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious use
YüksekCVSS 8,8İstismar yokEPSS %2merge-deep project · merge-deep6 Haz 2018
- CVE-2018-372336İzleyin
defaults-deep node module before 0.2.4 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious
YüksekCVSS 8,8İstismar yokEPSS %2defaults-deep project · defaults-deep6 Haz 2018
- CVE-2018-372036İzleyin
assign-deep node module before 0.4.7 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious us
YüksekCVSS 8,8İstismar yokEPSS %2assign-deep project · assign-deep6 Haz 2018
- CVE-2025-3313635İzleyin
IBM Aspera Faspex data modification
YüksekCVSS 8,8İstismar yokEPSS %0ibm · aspera faspex22 May 2025
- CVE-2020-2623734İzleyin
Prototype Pollution in highlight.js
YüksekCVSS 8,7İstismar yokEPSS %1highlightjs · highlight.js24 Kas 2020
- CVE-2024-987634İzleyin
Application is vulnerable to Privilege escalation
YüksekCVSS 8,5İstismar yokEPSS %0abb · anc30 Nis 2025
- CVE-2024-5555133İzleyin
An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10).
YüksekCVSS 8,3İstismar yokEPSS %1exasol · jdbc driver19 Mar 2025
- CVE-2022-239033İzleyin
Mutable pending intent in Google Play services SDK
YüksekCVSS 8,4İstismar yokEPSS %0google · google play services software development kit12 Ağu 2022
- GHSA-m9hw-7xfv-wqg732İzleyin
Prototype Pollution in json-logic-js
YüksekCVSS 8,0İstismar yoknpm · json-logic-js12 Kas 2020
- CVE-2020-811630İzleyin
Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbi
YüksekCVSS 7,3İstismar yokEPSS %3dot-prop project · dot-prop4 Şub 2020
- CVE-2020-826830İzleyin
Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of
YüksekCVSS 7,5İstismar yokEPSS %1json8-merge-patch project · json8-merge-patch9 Kas 2020
- CVE-2023-290429İzleyin
The External Visitor Manager portal of HID’s SAFE versions 5.8.0 through 5.11.3 are vulnerable to manipulation within web fields in the appl
YüksekCVSS 7,3İstismar yokEPSS %1hidglobal · safe7 Haz 2023
- GHSA-q42p-pg8m-cqh629İzleyin
Prototype Pollution in handlebars
YüksekCVSS 7,3İstismar yoknpm · handlebars5 Haz 2019
- CVE-2026-4479828İzleyin
Nautobot: GitRepository.current_head field should not be writable through REST API
YüksekCVSS 7,1İstismar yokEPSS %0networktocode · nautobot28 May 2026
- CVE-2018-372127İzleyin
lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mer
OrtaCVSS 6,5İstismar yokEPSS %2lodash · lodash6 Haz 2018
- CVE-2023-4369726İzleyin
Modification of Assumed-Immutable Data (MAID) in RDT400 in SICK APU allows an unprivileged remote attacker to make the site unable to load
OrtaCVSS 6,5İstismar yokEPSS %1sick · apu0200 firmware9 Eki 2023
- CVE-2024-3451726İzleyin
The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin acce
OrtaCVSS 6,5İstismar yokEPSS %1neo4j · neo4j7 May 2024
- CVE-2021-3717726İzleyin
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2).
OrtaCVSS 6,5İstismar yokEPSS %0siemens · sinema remote connect server14 Eyl 2021