CVE-2021-23450High· 7.5▾ TwilightAll versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 6.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
30%
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
dojo < 1.17.0communications_policy_management = 12.6.0.0.0primavera_unifier >= 17.7, <= 17.12primavera_unifier = 18.8primavera_unifier = 19.12primavera_unifier = 20.12primavera_unifier = 21.12weblogic_server = 12.2.1.4.0weblogic_server = 14.1.1.0.0debian_linux = 10.0Upgrade past the affected range:
dojo 1.17.0Connected by shared product, vendor, weakness, or advisory.
CVE-2020-5258High· 7.7In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution
CVE-2025-52881High· 7.5runc is a CLI tool for spawning and running containers according to the OCI specification
CVE-2025-31133High· 7.8runc is a CLI tool for spawning and running containers according to the OCI specification
CVE-2025-67508High· 8.4gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools
CVE-2025-66623High· 7.4Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations
CVE-2026-49114High· 7.1In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a non-atomic 'os.path.isfile()' check