CWE-915 · 113 записей
Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE этого класса
113 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
47В плане | CVE-2024-5452Proof of concept | RCE via Property/Class Pollution in lightning-ai/pytorch-lightninglightningai · pytorch lightning · CWE-915 | Критическая9,8 | — | 26,8 % | 6 июн. 2024 г. |
42В плане | CVE-2026-33453Proof of concept | Apache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Executionapache · camel · CWE-915 | Критическая10,0 | — | 7,2 % | 27 апр. 2026 г. |
41В плане | CVE-2026-50160Proof of concept | Mass Assignment via Onboarding Endpoint Allows Unauthenticated JWT_SECRET Overwritehoppscotch · hoppscotch · CWE-915 | Критическая10,0 | — | 1,7 % | 1 июл. 2026 г. |
40В плане | CVE-2022-43441Эксплойта нет | A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1.ghost · sqlite3 · CWE-915 | Критическая9,8 | — | 2,4 % | 16 мар. 2023 г. |
40В плане | CVE-2021-21304Эксплойта нет | Prototype Pollution in Dynamoosedynamoosejs · dynamoose · CWE-915 | Критическая9,8 | — | 1,9 % | 8 февр. 2021 г. |
40В плане | CVE-2022-24802Эксплойта нет | Prototype Pollution in deepmerge-tsdeepmerge-ts project · deepmerge-ts · CWE-915 | Критическая9,8 | — | 1,7 % | 31 мар. 2022 г. |
40В плане | CVE-2020-11066Эксплойта нет | Improperly Controlled Modification of Dynamically-Determined Object Attributes in TYPO3 CMStypo3 · typo3 · CWE-915 | Критическая10,0 | — | 1,5 % | 13 мая 2020 г. |
40В плане | CVE-2025-58367Эксплойта нет | DeepDiff is vulnerable to DoS and Remote Code Execution via Delta class pollutionseperman · deepdiff · CWE-915 | Критическая10,0 | — | 1,1 % | 5 сент. 2025 г. |
39Наблюдать | CVE-2022-31106Эксплойта нет | Prototype Pollution in underscore.deepclever · underscore.deep · CWE-915 | Критическая9,8 | — | 1,1 % | 28 июн. 2022 г. |
39Наблюдать | CVE-2024-55638Эксплойта нет | Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-008drupal · drupal · CWE-915 | Критическая9,8 | — | 1,0 % | 9 дек. 2024 г. |
39Наблюдать | CVE-2024-55636Эксплойта нет | Drupal core - Less critical - Gadget chain - SA-CORE-2024-006drupal · drupal · CWE-915 | Критическая9,8 | — | 0,9 % | 9 дек. 2024 г. |
39Наблюдать | CVE-2024-55637Эксплойта нет | Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-007drupal · drupal · CWE-915 | Критическая9,8 | — | 0,8 % | 9 дек. 2024 г. |
39Наблюдать | CVE-2026-12535Эксплойта нет | Formatter Field - Critical - PHP object injection - SA-CONTRIB-2026-048zroger · formatter field · CWE-915 | Критическая9,8 | — | 0,6 % | 10 июл. 2026 г. |
39Наблюдать | CVE-2026-9726Эксплойта нет | Drupal AlternativeCommerce (Basket) - Highly critical - Arbitrary PHP code execution - SA-CONTRIB-2026-038alternativecommerce · alternativecommerce · CWE-915 | Критическая9,8 | — | 0,6 % | 10 июл. 2026 г. |
38Наблюдать | CVE-2026-54351Эксплойта нет | Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Overridebudibase · budibase · CWE-915 | Критическая9,6 | — | 0,5 % | 26 июн. 2026 г. |
37Наблюдать | CVE-2026-72710Эксплойта нет | SPIP < 4.4.18 RCE via editer_objet.php Job Queue Injectionspip · spip · CWE-915 | Критическая9,3 | — | 1,1 % | 11 сент. 2026 г. |
37Наблюдать | CVE-2026-34406Эксплойта нет | APTRS: Privilege Escalation via Mass Assignment of is_superuser in User Edit Endpointaptrs · aptrs · CWE-915 | Критическая9,4 | — | 0,8 % | 31 мар. 2026 г. |
37Наблюдать | CVE-2025-2304Proof of concept | Camaleon CMS Privilege Escalationowen2345 · camaleon-cms · CWE-915 | Критическая9,4 | — | 0,6 % | 14 мар. 2025 г. |
37Наблюдать | CVE-2025-24370Эксплойта нет | Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypassadamghill · django-unicorn · CWE-915 | Критическая9,3 | — | 0,5 % | 3 февр. 2025 г. |
36Наблюдать | CVE-2026-42044Эксплойта нет | Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`axios · axios · CWE-915 | Критическая9,1 | — | 0,9 % | 24 апр. 2026 г. |
36Наблюдать | CVE-2024-0404Эксплойта нет | Mass Assignment Vulnerability in mintplex-labs/anything-llmmintplexlabs · anythingllm · CWE-915 | Критическая9,1 | — | 0,8 % | 15 апр. 2024 г. |
36Наблюдать | CVE-2026-48150Эксплойта нет | Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assignbudibase · budibase · CWE-915 | Критическая9,0 | — | 0,5 % | 27 мая 2026 г. |
36Наблюдать | CVE-2026-34179Эксплойта нет | Update of type field in restricted TLS certificate allows privilege escalation to cluster admincanonical · lxd · CWE-915 | Критическая9,1 | — | 0,4 % | 9 апр. 2026 г. |
35Наблюдать | CVE-2021-21368Эксплойта нет | msgpack5 is a msgpack v5 implementation for node.js and the browser.msgpack5 project · msgpack5 · CWE-915 | Высокая8,8 | — | 1,6 % | 12 мар. 2021 г. |
35Наблюдать | CVE-2023-32079Эксплойта нет | Netmaker Privilige Escalation Vulnerabilitynetmaker · netmaker · CWE-915 | Высокая8,8 | — | 0,9 % | 24 авг. 2023 г. |
- CVE-2024-545247В плане
RCE via Property/Class Pollution in lightning-ai/pytorch-lightning
КритическаяCVSS 9,8Proof of conceptEPSS 27 %lightningai · pytorch lightning6 июн. 2024 г.
- CVE-2026-3345342В плане
Apache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution
КритическаяCVSS 10,0Proof of conceptEPSS 7 %apache · camel27 апр. 2026 г.
- CVE-2026-5016041В плане
Mass Assignment via Onboarding Endpoint Allows Unauthenticated JWT_SECRET Overwrite
КритическаяCVSS 10,0Proof of conceptEPSS 2 %hoppscotch · hoppscotch1 июл. 2026 г.
- CVE-2022-4344140В плане
A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %ghost · sqlite316 мар. 2023 г.
- CVE-2021-2130440В плане
Prototype Pollution in Dynamoose
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %dynamoosejs · dynamoose8 февр. 2021 г.
- CVE-2022-2480240В плане
Prototype Pollution in deepmerge-ts
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %deepmerge-ts project · deepmerge-ts31 мар. 2022 г.
- CVE-2020-1106640В плане
Improperly Controlled Modification of Dynamically-Determined Object Attributes in TYPO3 CMS
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %typo3 · typo313 мая 2020 г.
- CVE-2025-5836740В плане
DeepDiff is vulnerable to DoS and Remote Code Execution via Delta class pollution
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %seperman · deepdiff5 сент. 2025 г.
- CVE-2022-3110639Наблюдать
Prototype Pollution in underscore.deep
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %clever · underscore.deep28 июн. 2022 г.
- CVE-2024-5563839Наблюдать
Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-008
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %drupal · drupal9 дек. 2024 г.
- CVE-2024-5563639Наблюдать
Drupal core - Less critical - Gadget chain - SA-CORE-2024-006
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %drupal · drupal9 дек. 2024 г.
- CVE-2024-5563739Наблюдать
Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-007
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %drupal · drupal9 дек. 2024 г.
- CVE-2026-1253539Наблюдать
Formatter Field - Critical - PHP object injection - SA-CONTRIB-2026-048
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zroger · formatter field10 июл. 2026 г.
- CVE-2026-972639Наблюдать
Drupal AlternativeCommerce (Basket) - Highly critical - Arbitrary PHP code execution - SA-CONTRIB-2026-038
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %alternativecommerce · alternativecommerce10 июл. 2026 г.
- CVE-2026-5435138Наблюдать
Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override
КритическаяCVSS 9,6Эксплойта нетEPSS 0 %budibase · budibase26 июн. 2026 г.
- CVE-2026-7271037Наблюдать
SPIP < 4.4.18 RCE via editer_objet.php Job Queue Injection
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %spip · spip11 сент. 2026 г.
- CVE-2026-3440637Наблюдать
APTRS: Privilege Escalation via Mass Assignment of is_superuser in User Edit Endpoint
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %aptrs · aptrs31 мар. 2026 г.
- CVE-2025-230437Наблюдать
Camaleon CMS Privilege Escalation
КритическаяCVSS 9,4Proof of conceptEPSS 1 %owen2345 · camaleon-cms14 мар. 2025 г.
- CVE-2025-2437037Наблюдать
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %adamghill · django-unicorn3 февр. 2025 г.
- CVE-2026-4204436Наблюдать
Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %axios · axios24 апр. 2026 г.
- CVE-2024-040436Наблюдать
Mass Assignment Vulnerability in mintplex-labs/anything-llm
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %mintplexlabs · anythingllm15 апр. 2024 г.
- CVE-2026-4815036Наблюдать
Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %budibase · budibase27 мая 2026 г.
- CVE-2026-3417936Наблюдать
Update of type field in restricted TLS certificate allows privilege escalation to cluster admin
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %canonical · lxd9 апр. 2026 г.
- CVE-2021-2136835Наблюдать
msgpack5 is a msgpack v5 implementation for node.js and the browser.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %msgpack5 project · msgpack512 мар. 2021 г.
- CVE-2023-3207935Наблюдать
Netmaker Privilige Escalation Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %netmaker · netmaker24 авг. 2023 г.