VulnSea

CWE-915

CVEs classified under CWE-915, newest first.

70 CVEsRSS

CVE-2026-42041Medium· 4.8PoC⚖ disputed
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to silently suppress all HT…

▾ Twilightaxios · axiosEPSS 0.81%via NVD
CVE-2026-42033High· 7.4PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) sil…

▾ Midnightaxios · axiosEPSS 0.92%via NVD
CVE-2026-40175Medium· 4.8PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inje…

▾ Twilightaxios · axiosEPSS 1.3%via NVD
CVE-2026-5708High· 8.8
5mo ago

Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authenticated remote user to escalate privileges, assume the virtual…

Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authenticated remote user to escalate privileges, assume the virtual…

▾ Twilightamazon · research_and_engineering_studioEPSS 0.74%via NVD
CVE-2026-34445High· 8.6
5mo ago

ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.

ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.

▾ Twilightonnx · onnxEPSS 0.51%via OSV
CVE-2026-34406High· 8.8
6mo ago

APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed for penetration testers and security organizations

APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed for penetration testers and security organizations. Prior to version 2.0.1, the edit_user endpoint (POST /api/auth/edit…

▾ Twilightaptrs · aptrsEPSS 0.80%via NVD
CVE-2026-33228Critical· 9.8
6mo ago

flatted is a circular JSON parser

flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the int…

▾ MidnightEPSS 0.99%via NVD
CVE-2026-32640Critical· 9.8
6mo ago

SimpleEval is a library for adding evaluatable expressions into python projects

SimpleEval is a library for adding evaluatable expressions into python projects. Prior to 1.0.5, objects (including modules) can leak dangerous modules through to direct access inside the sandbox. If the objects you've passed in as names…

▾ Midnightdanthedeckie · simpleevalEPSS 0.78%via NVD
CVE-2026-29063Critical· 9.8
6mo ago

Immutable.js provides many Persistent Immutable data structures

Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. …

▾ Midnightimmutable-js · immutableEPSS 1.2%via NVD
CVE-2026-25521High· 8.8
7mo ago

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to before 2.0.39, a prototype pollution vulnerability exists in locutus. Despite a previous fix that attempted to mitig…

▾ Twilightlocutus · locutusEPSS 0.44%via NVD
CWE-915 vulnerabilities (CVEs) — page 3 · VulnSea