İçeriğe atla
Noroxi

CWE-471 · 38 kayıt

Modification of Assumed-Immutable Data (MAID)

Bu sınıftaki CVE’ler

38 kayıt

  • CVE-2020-8147
    40Planlayın

    Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that may result in remot

    KritikCVSS 9,8İstismar yokEPSS %3

    utils-extend project · utils-extend3 Nis 2020

  • CVE-2020-8158
    40Planlayın

    Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further

    KritikCVSS 9,8Kavram kanıtıEPSS %2

    typeorm · typeorm18 Eyl 2020

  • CVE-2022-25893
    39İzleyin

    Arbitrary Code Execution

    KritikCVSS 9,8İstismar yokEPSS %1

    vm2 project · vm221 Ara 2022

  • CVE-2026-50481
    39İzleyin

    Azure Active Directory Elevation of Privilege Vulnerability

    KritikCVSS 9,9İstismar yokEPSS %1

    microsoft · azure active directory6 Ağu 2026

  • CVE-2022-21824
    38İzleyin

    Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties

    YüksekCVSS 8,2İstismar yokEPSS %22

    nodejs · node.js24 Şub 2022

  • CVE-2018-3728
    36İzleyin

    hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge'

    YüksekCVSS 8,8İstismar yokEPSS %4

    hapijs · hoek30 Mar 2018

  • CVE-2018-3719
    36İzleyin

    mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious use

    YüksekCVSS 8,8İstismar yokEPSS %2

    mixin-deep project · mixin-deep6 Haz 2018

  • CVE-2018-3722
    36İzleyin

    merge-deep node module before 3.0.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious use

    YüksekCVSS 8,8İstismar yokEPSS %2

    merge-deep project · merge-deep6 Haz 2018

  • CVE-2018-3723
    36İzleyin

    defaults-deep node module before 0.2.4 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious

    YüksekCVSS 8,8İstismar yokEPSS %2

    defaults-deep project · defaults-deep6 Haz 2018

  • CVE-2018-3720
    36İzleyin

    assign-deep node module before 0.4.7 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious us

    YüksekCVSS 8,8İstismar yokEPSS %2

    assign-deep project · assign-deep6 Haz 2018

  • CVE-2025-33136
    35İzleyin

    IBM Aspera Faspex data modification

    YüksekCVSS 8,8İstismar yokEPSS %0

    ibm · aspera faspex22 May 2025

  • CVE-2020-26237
    34İzleyin

    Prototype Pollution in highlight.js

    YüksekCVSS 8,7İstismar yokEPSS %1

    highlightjs · highlight.js24 Kas 2020

  • CVE-2024-9876
    34İzleyin

    Application is vulnerable to Privilege escalation

    YüksekCVSS 8,5İstismar yokEPSS %0

    abb · anc30 Nis 2025

  • CVE-2024-55551
    33İzleyin

    An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10).

    YüksekCVSS 8,3İstismar yokEPSS %1

    exasol · jdbc driver19 Mar 2025

  • CVE-2022-2390
    33İzleyin

    Mutable pending intent in Google Play services SDK

    YüksekCVSS 8,4İstismar yokEPSS %0

    google · google play services software development kit12 Ağu 2022

  • Prototype Pollution in json-logic-js

    YüksekCVSS 8,0İstismar yok

    npm · json-logic-js12 Kas 2020

  • CVE-2020-8116
    30İzleyin

    Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbi

    YüksekCVSS 7,3İstismar yokEPSS %3

    dot-prop project · dot-prop4 Şub 2020

  • CVE-2020-8268
    30İzleyin

    Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of

    YüksekCVSS 7,5İstismar yokEPSS %1

    json8-merge-patch project · json8-merge-patch9 Kas 2020

  • CVE-2023-2904
    29İzleyin

    The External Visitor Manager portal of HID’s SAFE versions 5.8.0 through 5.11.3 are vulnerable to manipulation within web fields in the appl

    YüksekCVSS 7,3İstismar yokEPSS %1

    hidglobal · safe7 Haz 2023

  • Prototype Pollution in handlebars

    YüksekCVSS 7,3İstismar yok

    npm · handlebars5 Haz 2019

  • CVE-2026-44798
    28İzleyin

    Nautobot: GitRepository.current_head field should not be writable through REST API

    YüksekCVSS 7,1İstismar yokEPSS %0

    networktocode · nautobot28 May 2026

  • CVE-2018-3721
    27İzleyin

    lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mer

    OrtaCVSS 6,5İstismar yokEPSS %2

    lodash · lodash6 Haz 2018

  • CVE-2023-43697
    26İzleyin

    Modification of Assumed-Immutable Data (MAID) in RDT400 in SICK APU allows an unprivileged remote attacker to make the site unable to load

    OrtaCVSS 6,5İstismar yokEPSS %1

    sick · apu0200 firmware9 Eki 2023

  • CVE-2024-34517
    26İzleyin

    The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin acce

    OrtaCVSS 6,5İstismar yokEPSS %1

    neo4j · neo4j7 May 2024

  • CVE-2021-37177
    26İzleyin

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2).

    OrtaCVSS 6,5İstismar yokEPSS %0

    siemens · sinema remote connect server14 Eyl 2021

Tüm zafiyet sınıfları