boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1321

Weakness type CWE-1321 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1351311

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▆█▇█▃

2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 0 · 2026-03 2 · 2026-04 6 · 2026-05 8 · 2026-06 20 · 2026-07 30 · 2026-08 26 · 2026-09 29 · 2026-10 8

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-346218.681.7KEVAcrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Pr…
CVE-2025-134656.978.4—Prototype Pollution Vulnerability in Lodash _.unset and _.omit functions
CVE-2026-290638.775.0—Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Proto…
CVE-2026-444957.762.8—Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config…
CVE-2026-332288.961.2—flatted: Prototype Pollution via parse()
CVE-2026-466257.561.1—JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute i…
CVE-2026-422649.160.4—Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection…
CVE-2026-444948.759.3—Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
CVE-2026-420337.459.1—Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request…
CVE-2026-420449.157.1—Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
CVE-2026-615349.156.4—Yayson: Prototype pollution in the Store/LegacyStore deserialization
CVE-2026-4400510.056.0—vm2: Sandbox escape
CVE-2026-420416.555.4—Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge S…
CVE-2026-536768.655.1——
CVE-2024-215298.853.4——
CVE-2026-856259.252.8—sift 17.1.3 Prototype Pollution Remote Code Execution via $where
CVE-2026-786545.552.1—cleverbrush framework/deep deepExtend.ts deepExtend prototype pollution
CVE-2024-214897.851.7——
CVE-2026-633768.250.9—toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__proto__` K…
CVE-2026-818875.150.8—Livewire DOM-based cross-site scripting during client-side state handling

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
axios17
n8n-io9
adobe4
apache3
hapijs3
apostrophecms2
builderio2
cure532
i18next2
mermaid-js2
middleapi2
piscinajs2
thomaspoignant2
tinylibs2
xdan2