The product does not properly protect an assumed-immutable element from being modified by an attacker.
Volume of CVEs assigned to CWE-471 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-21824HIGH Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing | Feb 24, 2022 | 8.2 | 39 | NO | NO |
CVE-2020-15256CRITICAL A prototype pollution vulnerability has been found in `object-path` <= 0.11.4 affecting the `set()` method. The vulnerability is limited to the `includeInheritedProps` mode (if ver | Oct 19, 2020 | 9.8 | 32 | NO | NO |
CVE-2020-26245CRITICAL npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. The issue was fixed with a rewrite of shell sanitations to av | Nov 27, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-8147CRITICAL Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of | Apr 3, 2020 | 9.8 | 31 | NO | NO |
CVE-2022-25893CRITICAL The package vm2 before 3.9.10 are vulnerable to Arbitrary Code Execution due to the usage of prototype lookup for the WeakMap.prototype.set method. Exploiting this vulnerability le | Dec 21, 2022 | 9.8 | 30 | NO | NO |
CVE-2026-44798HIGH Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, a user with access to add/change a GitRepository record could use the REST API to | May 28, 2026 | 7.1 | 29 | NO | NO |
CVE-2018-3728HIGH hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge' and 'applyToDefaults' functions, which a | Mar 30, 2018 | 8.8 | 29 | NO | NO |
CVE-2026-54267MEDIUM Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, to optimi | Jun 22, 2026 | 6.1 | 28 | NO | NO |
CVE-2020-26237HIGH Highlight.js is a syntax highlighter written in JavaScript. Highlight.js versions before 9.18.2 and 10.1.2 are vulnerable to Prototype Pollution. A malicious HTML code block can be | Nov 24, 2020 | 8.7 | 27 | NO | NO |
CVE-2018-3719HIGH mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" vi | Jun 7, 2018 | 8.8 | 27 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.