Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-1321 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 85 | 81 | 0 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▆█▅
2025-09 1 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 0 · 2026-03 2 · 2026-04 3 · 2026-05 8 · 2026-06 20 · 2026-07 30 · 2026-08 16
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-13465 | 6.9 | 72.8 | — | Prototype Pollution Vulnerability in Lodash _.unset and _.omit functions |
| CVE-2026-44494 | 8.7 | 61.3 | — | Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` |
| CVE-2026-29063 | 8.7 | 59.4 | — | Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Proto… |
| CVE-2026-44789 | 9.4 | 56.2 | — | n8n: HTTP Request Node Pagination Prototype Pollution to RCE |
| CVE-2026-44005 | 10.0 | 54.8 | — | vm2: Sandbox escape |
| CVE-2026-33228 | 8.9 | 54.0 | — | flatted: Prototype Pollution via parse() |
| CVE-2026-42033 | 7.4 | 54.0 | — | Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request… |
| CVE-2026-44495 | 7.7 | 53.0 | — | Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config… |
| CVE-2024-21529 | 8.8 | 52.0 | — | — |
| CVE-2026-42264 | 7.4 | 50.9 | — | Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection… |
| CVE-2024-21548 | 7.7 | 48.2 | — | — |
| CVE-2024-21489 | 7.8 | 48.1 | — | — |
| CVE-2026-44791 | 9.4 | 47.7 | — | n8n: XML Node Prototype Pollution Patch Bypass |
| CVE-2026-42041 | 6.5 | 46.6 | — | Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge S… |
| CVE-2026-53676 | 8.6 | 46.2 | — | — |
| CVE-2026-42044 | 6.5 | 45.5 | — | Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver` |
| CVE-2026-46625 | 7.5 | 41.5 | — | JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute i… |
| CVE-2026-44966 | 9.8 | 41.1 | — | Velocity.js: Prototype Pollution in #set path assignment |
| CVE-2025-3193 | 7.5 | 39.7 | — | — |
| CVE-2026-49252 | 9.9 | 38.9 | — | deepstream is vulnerable to prototype pollution |
| Vendor | CVEs |
|---|---|
| axios | 11 |
| n8n-io | 7 |
| apostrophecms | 2 |
| cure53 | 2 |
| i18next | 2 |
| mermaid-js | 2 |
| xdan | 2 |
| @rvf | 1 |
| adonisjs | 1 |
| airjp73 | 1 |
| antv | 1 |
| apidevtools | 1 |
| automattic | 1 |
| browserslist | 1 |
| cartodb | 1 |