Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-1321
Weakness type CWE-1321 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 135 | 131 | 1 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▆█▇█▃
2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 0 · 2026-03 2 · 2026-04 6 · 2026-05 8 · 2026-06 20 · 2026-07 30 · 2026-08 26 · 2026-09 29 · 2026-10 8
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-34621 | 8.6 | 81.7 | KEV | Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Pr… |
| CVE-2025-13465 | 6.9 | 78.4 | — | Prototype Pollution Vulnerability in Lodash _.unset and _.omit functions |
| CVE-2026-29063 | 8.7 | 75.0 | — | Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Proto… |
| CVE-2026-44495 | 7.7 | 62.8 | — | Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config… |
| CVE-2026-33228 | 8.9 | 61.2 | — | flatted: Prototype Pollution via parse() |
| CVE-2026-46625 | 7.5 | 61.1 | — | JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute i… |
| CVE-2026-42264 | 9.1 | 60.4 | — | Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection… |
| CVE-2026-44494 | 8.7 | 59.3 | — | Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` |
| CVE-2026-42033 | 7.4 | 59.1 | — | Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request… |
| CVE-2026-42044 | 9.1 | 57.1 | — | Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver` |
| CVE-2026-61534 | 9.1 | 56.4 | — | Yayson: Prototype pollution in the Store/LegacyStore deserialization |
| CVE-2026-44005 | 10.0 | 56.0 | — | vm2: Sandbox escape |
| CVE-2026-42041 | 6.5 | 55.4 | — | Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge S… |
| CVE-2026-53676 | 8.6 | 55.1 | — | — |
| CVE-2024-21529 | 8.8 | 53.4 | — | — |
| CVE-2026-85625 | 9.2 | 52.8 | — | sift 17.1.3 Prototype Pollution Remote Code Execution via $where |
| CVE-2026-78654 | 5.5 | 52.1 | — | cleverbrush framework/deep deepExtend.ts deepExtend prototype pollution |
| CVE-2024-21489 | 7.8 | 51.7 | — | — |
| CVE-2026-63376 | 8.2 | 50.9 | — | toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__proto__` K… |
| CVE-2026-81887 | 5.1 | 50.8 | — | Livewire DOM-based cross-site scripting during client-side state handling |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| axios | 17 |
| n8n-io | 9 |
| adobe | 4 |
| apache | 3 |
| hapijs | 3 |
| apostrophecms | 2 |
| builderio | 2 |
| cure53 | 2 |
| i18next | 2 |
| mermaid-js | 2 |
| middleapi | 2 |
| piscinajs | 2 |
| thomaspoignant | 2 |
| tinylibs | 2 |
| xdan | 2 |