Перейти к содержимому
Noroxi

CWE-915 · 113 записей

Improperly Controlled Modification of Dynamically-Determined Object Attributes

CVE этого класса

113 записей

  • CVE-2024-5452
    47В плане

    RCE via Property/Class Pollution in lightning-ai/pytorch-lightning

    КритическаяCVSS 9,8Proof of conceptEPSS 27 %

    lightningai · pytorch lightning6 июн. 2024 г.

  • CVE-2026-33453
    42В плане

    Apache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution

    КритическаяCVSS 10,0Proof of conceptEPSS 7 %

    apache · camel27 апр. 2026 г.

  • CVE-2026-50160
    41В плане

    Mass Assignment via Onboarding Endpoint Allows Unauthenticated JWT_SECRET Overwrite

    КритическаяCVSS 10,0Proof of conceptEPSS 2 %

    hoppscotch · hoppscotch1 июл. 2026 г.

  • CVE-2022-43441
    40В плане

    A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    ghost · sqlite316 мар. 2023 г.

  • CVE-2021-21304
    40В плане

    Prototype Pollution in Dynamoose

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    dynamoosejs · dynamoose8 февр. 2021 г.

  • CVE-2022-24802
    40В плане

    Prototype Pollution in deepmerge-ts

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    deepmerge-ts project · deepmerge-ts31 мар. 2022 г.

  • CVE-2020-11066
    40В плане

    Improperly Controlled Modification of Dynamically-Determined Object Attributes in TYPO3 CMS

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    typo3 · typo313 мая 2020 г.

  • CVE-2025-58367
    40В плане

    DeepDiff is vulnerable to DoS and Remote Code Execution via Delta class pollution

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    seperman · deepdiff5 сент. 2025 г.

  • CVE-2022-31106
    39Наблюдать

    Prototype Pollution in underscore.deep

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    clever · underscore.deep28 июн. 2022 г.

  • CVE-2024-55638
    39Наблюдать

    Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-008

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    drupal · drupal9 дек. 2024 г.

  • CVE-2024-55636
    39Наблюдать

    Drupal core - Less critical - Gadget chain - SA-CORE-2024-006

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    drupal · drupal9 дек. 2024 г.

  • CVE-2024-55637
    39Наблюдать

    Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-007

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    drupal · drupal9 дек. 2024 г.

  • CVE-2026-12535
    39Наблюдать

    Formatter Field - Critical - PHP object injection - SA-CONTRIB-2026-048

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    zroger · formatter field10 июл. 2026 г.

  • CVE-2026-9726
    39Наблюдать

    Drupal AlternativeCommerce (Basket) - Highly critical - Arbitrary PHP code execution - SA-CONTRIB-2026-038

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    alternativecommerce · alternativecommerce10 июл. 2026 г.

  • CVE-2026-54351
    38Наблюдать

    Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override

    КритическаяCVSS 9,6Эксплойта нетEPSS 0 %

    budibase · budibase26 июн. 2026 г.

  • CVE-2026-72710
    37Наблюдать

    SPIP < 4.4.18 RCE via editer_objet.php Job Queue Injection

    КритическаяCVSS 9,3Эксплойта нетEPSS 1 %

    spip · spip11 сент. 2026 г.

  • CVE-2026-34406
    37Наблюдать

    APTRS: Privilege Escalation via Mass Assignment of is_superuser in User Edit Endpoint

    КритическаяCVSS 9,4Эксплойта нетEPSS 1 %

    aptrs · aptrs31 мар. 2026 г.

  • CVE-2025-2304
    37Наблюдать

    Camaleon CMS Privilege Escalation

    КритическаяCVSS 9,4Proof of conceptEPSS 1 %

    owen2345 · camaleon-cms14 мар. 2025 г.

  • CVE-2025-24370
    37Наблюдать

    Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    adamghill · django-unicorn3 февр. 2025 г.

  • CVE-2026-42044
    36Наблюдать

    Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    axios · axios24 апр. 2026 г.

  • CVE-2024-0404
    36Наблюдать

    Mass Assignment Vulnerability in mintplex-labs/anything-llm

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    mintplexlabs · anythingllm15 апр. 2024 г.

  • CVE-2026-48150
    36Наблюдать

    Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign

    КритическаяCVSS 9,0Эксплойта нетEPSS 0 %

    budibase · budibase27 мая 2026 г.

  • CVE-2026-34179
    36Наблюдать

    Update of type field in restricted TLS certificate allows privilege escalation to cluster admin

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    canonical · lxd9 апр. 2026 г.

  • CVE-2021-21368
    35Наблюдать

    msgpack5 is a msgpack v5 implementation for node.js and the browser.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    msgpack5 project · msgpack512 мар. 2021 г.

  • CVE-2023-32079
    35Наблюдать

    Netmaker Privilige Escalation Vulnerability

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    netmaker · netmaker24 авг. 2023 г.

Все классы уязвимостей