Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
Qwik is a performance-focused JavaScript framework. Versions prior to 1.19.2 improperly inferred arrays from dotted form
defu is software that allows uers to assign default properties recursively. Prior to version 6.1.5, applications that pa
[email protected] and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/f
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs allowed ce
JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal as
Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadg
Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive con
seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versio
A vulnerability was determined in brikcss merge up to 1.3.0. This affects an unknown part. Executing a manipulation of t
A vulnerability was determined in 1024bit extend-deep up to 0.1.6. The impacted element is an unknown function of the fi
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core
@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to
A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite.extend/jqxBaseFramework.exte
A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider
A weakness has been identified in ractivejs ractive up to 1.4.4. Impacted is the function Ractive#set of the component K
A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the function deepExtend of th
AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a prototype pollution vulnerab
ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed c
n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated user with t
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contain
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulne
Maker.js is a 2D vector line drawing and shape modeling for CNC and laser cutters. In versions up to and including 0.19.
Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server commun
Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions.
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulne
In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` rec
Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, a prototype pollution vulnerability allo
Dottie provides nested object access and manipulation in JavaScript. Versions 2.0.4 through 2.0.6 contain an incomplete
Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Mo
A weakness has been identified in apidevtools json-schema-ref-parser up to 15.3.5. This impacts the function Refs.set/Po
A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the function ObjectUtils.mutate
A weakness has been identified in antv layout 2.0.0. This impacts the function setNestedValue in the library lib/util/ob
A vulnerability was found in svgdotjs svg.js up to 3.2.5. This affects the function EventTarget.on of the file svgdotjs/
A vulnerability was determined in kofrasa mingo up to 7.2.1. This impacts the function update/updateOne/updateMany of th
A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the function nlp.extend of the f
A security vulnerability has been detected in tamagui up to 2.3.0. This affects the function updateConfig of the file co
A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This impacts the function parseP
A vulnerability was found in RobinHerbots Inputmask up to 5.0.9. Affected by this issue is the function extendDefaults/e
A vulnerability has been found in CartoDB carto-api-client 0.5.29. This impacts the function addFilter of the file src/f
A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function Se
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(roo
DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScri
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Ins
Frequently Asked Questions
What is CWE-1321?
CWE-1321 (CWE-1321) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-1321?
There are 145 CVE records associated with CWE-1321 in our database. Of these, 24 are critical severity, 50 are high severity, and 50 are medium severity.
How can I protect against CWE-1321 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1321 using AI-powered security agents.
Detect CWE-1321 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-1321 vulnerabilities across your infrastructure.
Get Started