boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1321

Weakness type CWE-1321 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
85810

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▆█▅

2025-09 1 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 0 · 2026-03 2 · 2026-04 3 · 2026-05 8 · 2026-06 20 · 2026-07 30 · 2026-08 16

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-134656.972.8Prototype Pollution Vulnerability in Lodash _.unset and _.omit functions
CVE-2026-444948.761.3Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
CVE-2026-290638.759.4Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Proto…
CVE-2026-447899.456.2n8n: HTTP Request Node Pagination Prototype Pollution to RCE
CVE-2026-4400510.054.8vm2: Sandbox escape
CVE-2026-332288.954.0flatted: Prototype Pollution via parse()
CVE-2026-420337.454.0Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request…
CVE-2026-444957.753.0Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config…
CVE-2024-215298.852.0
CVE-2026-422647.450.9Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection…
CVE-2024-215487.748.2
CVE-2024-214897.848.1
CVE-2026-447919.447.7n8n: XML Node Prototype Pollution Patch Bypass
CVE-2026-420416.546.6Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge S…
CVE-2026-536768.646.2
CVE-2026-420446.545.5Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
CVE-2026-466257.541.5JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute i…
CVE-2026-449669.841.1Velocity.js: Prototype Pollution in #set path assignment
CVE-2025-31937.539.7
CVE-2026-492529.938.9deepstream is vulnerable to prototype pollution

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
axios11
n8n-io7
apostrophecms2
cure532
i18next2
mermaid-js2
xdan2
@rvf1
adonisjs1
airjp731
antv1
apidevtools1
automattic1
browserslist1
cartodb1