npm
Security Advisories in npm
High
about 8 hours ago
@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
npm
@apostrophecms/seo
Low
about 8 hours ago
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
npm
apostrophe
Critical
about 8 hours ago
Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
npm
apostrophe
Moderate
about 8 hours ago
sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes
npm
sanitize-html
Critical
about 10 hours ago
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
npm
@nocobase/plugin-notification-in-app-message
Moderate
about 11 hours ago
Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization
npm
jodit
High
about 11 hours ago
Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
npm
jodit
Moderate
about 11 hours ago
Jodit has prototype pollution via Jodit.configure() / ConfigMerge
npm
jodit
Moderate
about 11 hours ago
Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS
npm
jodit
High
about 12 hours ago
@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging
npm
@phun-ky/defaults-deep
High
about 13 hours ago
hashi-vault-js has a path traversal and query parameter injection
npm
hashi-vault-js
Moderate
about 13 hours ago
re2: Global `String.prototype.match` with an empty-matchable pattern never advances โ infinite loop with unbounded native memory growth (DoS)
npm
re2
High
about 14 hours ago
`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation
npm
@dynatrace-oss/dynatrace-mcp-server
Moderate
about 14 hours ago
@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification
npm
@dynatrace-oss/dynatrace-mcp-server
Moderate
about 14 hours ago
@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL
npm
@dynatrace-oss/dynatrace-mcp-server
Critical
1 day ago
AWS Amplify Studio UI Component Properties Has an Input Validation Issue
npm
@aws-amplify/codegen-ui-react
High
3 days ago
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
npm
@aws/agentcore
Low
3 days ago
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
npm
@dynatrace-oss/dynatrace-mcp-server
High
3 days ago
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
npm
swagger-typescript-api
High
3 days ago
swagger-typescript-api vulnerable to code injection via unescaped enum string values
npm
swagger-typescript-api
High
3 days ago
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
npm
swagger-typescript-api
Moderate
3 days ago
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
npm
swagger-typescript-api
High
3 days ago
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
npm
swagger-typescript-api
High
3 days ago
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
npm
swagger-typescript-api
High
3 days ago
Style Dictionary - Prototype Pollution in convertTokenData utility function
npm
style-dictionary
Critical
3 days ago
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
npm
@hypequery/clickhouse
Moderate
3 days ago
NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
npm
@nocobase/plugin-collection-sql
High
4 days ago
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
npm, pypi, maven
qti-neon, com.quietterminal:qti-neon
Moderate
4 days ago
@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations โ affects Workflow HTTP request step + Webhook filter condition
npm
@novu/application-generic
Moderate
7 days ago
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
npm
@frontmcp/adapters
Moderate
7 days ago
Shescape: Home-directory disclosure in assignment context on Unix with Dash
npm
shescape
Critical
7 days ago
Shescape: Shell injection via unescaped parentheses on Windows with CMD
npm
shescape
High
7 days ago
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
npm
brace-expansion
Critical
7 days ago
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
npm
sm-crypto
High
7 days ago
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
npm
@anephenix/hub
Moderate
7 days ago
Budibase: SSRF via bare fetch() in uploadUrl during AI table generation
npm
@budibase/server
High
7 days ago
Budibase: SSRF via DNS rebinding in the REST datasource integration
npm
@budibase/server
High
7 days ago
Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete
npm
@budibase/server
Moderate
7 days ago
Budibase: Account Enumeration via Login Lockout Response Differential
npm
@budibase/server
High
7 days ago
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
npm
@budibase/server
High
7 days ago
Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
npm
@budibase/server
High
7 days ago
Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
npm
@budibase/server
Moderate
7 days ago
Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders
npm
@budibase/server
High
7 days ago
Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
npm
@budibase/server
Critical
7 days ago
Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
npm
@budibase/server
Critical
7 days ago
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
npm
@budibase/server
High
7 days ago
Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
npm
@budibase/server
High
7 days ago
Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs
npm
@budibase/server
High
7 days ago
Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile
npm
@budibase/server
High
7 days ago
Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
npm
@budibase/server
Moderate
7 days ago
Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
npm
@budibase/server
Moderate
7 days ago
Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
npm
@budibase/server
High
7 days ago
Budibase: Privilege escalation via public role assignment API missing app-level authorization
npm
@budibase/server
High
7 days ago
react-server-dom: Denial of Service in Server Functions
npm
react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack
High
8 days ago
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
npm
@anthropic-ai/claude-code
High
8 days ago
js-yaml: Exponential parsing time in flow collections leads to denial of service
npm
js-yaml
High
8 days ago
React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
npm
react-router
Low
8 days ago
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
pypi, go, maven, nuget, npm
aws-cdk.aws-codebuild, aws-cdk-lib, github.com/aws/aws-cdk-go/awscdk, software.amazon.awscdk:codebuild, Amazon.CDK.AWS.CodeBuild, @aws-cdk/aws-codebuild, github.com/aws/aws-cdk-go/awscdk/v2, software.amazon.awscdk:aws-cdk-lib, Amazon.CDK.Lib
Moderate
8 days ago
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
npm
@fastify/static
High
8 days ago
@fastify/static vulnerable to route guard bypass via path traversal
npm
@fastify/static
Critical
8 days ago
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
npm
@prompty/core
Moderate
8 days ago
Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
npm
mongoose
Critical
8 days ago
Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
npm
velocityjs
Moderate
8 days ago
@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass
npm
@backstage/plugin-auth-backend
Moderate
8 days ago
Trix: Stored XSS via HTMLParser attribute injection on paste
rubygems, npm
action_text-trix, trix
Moderate
8 days ago
Valibot: record() issue paths can make flatten() throw for inherited Object property names
npm
valibot
Critical
8 days ago
seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
npm
seroval
Moderate
8 days ago
SvelteKit: Prototype pollution in file input deletion path in remote-function forms
npm
@sveltejs/kit
Moderate
8 days ago
SvelteKit: Big remote form function payloads can cause Node process to crash
npm
@sveltejs/kit
High
8 days ago
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
npm
better-auth
High
8 days ago
@better-auth/stripe: cross-organization billing tampering in organization subscription actions
npm
@better-auth/stripe
Critical
8 days ago
@better-auth/scim: account takeover and stale access via SCIM provider-id collision
npm
@better-auth/scim
High
8 days ago
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
npm
react-router
High
8 days ago
LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
npm
liquidjs
High
8 days ago
electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`
npm
builder-util-runtime
High
8 days ago
electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`
npm
app-builder-lib
Moderate
8 days ago
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
npm
react-router
Moderate
8 days ago
React Router: RSCErrorHandler Missing Protocol Validation (XSS)
npm
react-router
Moderate
8 days ago
React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
npm
react-router
High
9 days ago
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
npm
postcss
Critical
9 days ago
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
npm
next-auth
High
9 days ago
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
npm
next-auth, @auth/core
Critical
9 days ago
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
npm
next-auth, @auth/core
Moderate
9 days ago
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
npm
next-auth, @auth/core
Moderate
9 days ago
n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
npm
n8n
Filter by Severity
Filter by Package
openclaw
591
n8n
139
parse-server
116
flowise
86
next
64
directus
58
nocodb
54
electron
47
vm2
43
axios
43
hono
43
@budibase/server
40
undici
30
pnpm
28
@anthropic-ai/claude-code
28
dompurify
27
astro
25
ghost
25
vite
22
better-auth
22
fuxa-server
21
@openzeppelin/contracts
21
tinymce
20
react-router
20
tar
20
@openzeppelin/contracts-upgradeable
19
handlebars
18
sequelize
17
flowise-components
17
protobufjs
17
@haxtheweb/haxcms-nodejs
16
liquidjs
16
@sveltejs/kit
16
angular
15
apostrophe
15
ckeditor4
15
node-forge
15
jspdf
15
nodebb
14
nuxt
14
swagger-ui
14
@nyariv/sandboxjs
14
signalk-server
14
next-auth
14
systeminformation
14
svelte
14
joplin
14
jsrsasign
14
TinyMCE
13
marked
13
electerm
13
tinymce/tinymce
13
shescape
13
strapi
12
@evershop/evershop
12
@directus/api
12
matrix-js-sdk
12
fast-xml-parser
12
n8n-mcp
11
mermaid
11
@lobehub/chat
11
@strapi/strapi
11
sanitize-html
11
uptime-kuma
11
nodemailer
11
renovate
11
@oneuptime/common
11
sillytavern
11
lodash
10
bootstrap
10
payload
10
h3
10
open-webui
10
fastify
10
clawdbot
10
validator
10
elliptic
9
matrix-react-sdk
9
network-ai
9
multer
9
mongoose
9
js-yaml
9
trix
9
serve
9
@saltcorn/server
9
praisonai
9
matrix-appservice-irc
9
react-server-dom-parcel
8
9router
8
@astrojs/node
8
@backstage/plugin-scaffolder-backend
8
tarteaucitronjs
8
@paperclipai/server
8
fast-jwt
8
@strapi/plugin-users-permissions
8
editor.md
8
react-server-dom-turbopack
8
aws-cdk-lib
8
locutus
8
@builder.io/qwik-city
8
react-server-dom-webpack
8
xmldom
8
npm
8
vega
8
devalue
8
urijs
8
url-parse
8
steal
8
mattermost-desktop
7
@xmldom/xmldom
7
@fedify/fedify
7
@vitejs/plugin-rsc
7
@angular/core
7
budibase
7
webpack-dev-server
7
qs
7
@keystone-6/core
7
ws
7
snyk-broker
7
studiocms
7
express-cart
7
lodash-es
7
org.webjars.npm:jquery-ui
7
@hulumi/policies
7
@actual-app/sync-server
7
hermes-engine
7
jodit
7
simple-git
7
hapi
7
@asymmetric-effort/specifyjs
7
total.js
7
jquery-ui
7
@auth0/nextjs-auth0
7
@tinacms/cli
7
jQuery.UI.Combined
7
@angular/platform-server
6
swagger-typescript-api
6
@evomap/evolver
6
postcss
6
open-webui
6
ua-parser-js
6
openpgp
6
safe-eval
6
brace-expansion
6
@hono/node-server
6
rsshub
6
seroval
6
parse-url
6
@frangoteam/fuxa
6
@angular/ssr
6
prismjs
6
@budibase/backend-core
6
aaptjs
6
typeorm
6
basic-ftp
5
@perfood/couch-auth
5
muhammara
5
mathjs
5
@angular/common
5
engine.io
5
ejs
5
jquery
5
vega-functions
5
auth0-js
5
oneuptime
5
follow-redirects
5
mcp-server-kubernetes
5
koa
5
bootstrap
5
total4
5
@tinacms/graphql
5
convict
5
@grackle-ai/server
5
passport-wsfed-saml2
5
jQuery
5
xlsx
5
lodash-amd
5
minimatch
5
yarn
5
serialize-javascript
5
sweetalert2
5
express
5
apollo-server-core
5
rendertron
5
public
5
@steipete/summarize
5
@apollo/gateway
5
keystone
5
@apollo/server
5
katex
5
happy-dom
5
path-to-regexp
5
dojo
5
vditor
5
mysql2
5
http-proxy-middleware
5
@samanhappy/mcphub
5
tar-fs
4
snyk
4
code-server
4
Filter by Repository
https://github.com/directus/directus
41
https://github.com/parse-community/parse-server
34
https://github.com/strapi/strapi
28
https://github.com/electron/electron
28
https://github.com/FlowiseAI/Flowise
28
https://github.com/vercel/next.js
25
https://github.com/OpenZeppelin/openzeppelin-contracts
21
https://github.com/backstage/backstage
19
https://github.com/sequelize/sequelize
16
https://github.com/tinymce/tinymce
16
https://github.com/vitejs/vite
16
https://github.com/nodejs/undici
15
https://github.com/ckeditor/ckeditor4
14
https://github.com/TryGhost/Ghost
14
https://github.com/swagger-api/swagger-ui
13
https://github.com/laurent22/joplin
13
https://github.com/n8n-io/n8n
12
https://github.com/matrix-org/matrix-js-sdk
12
https://github.com/patriksimek/vm2
12
https://github.com/NodeBB/NodeBB
12
https://github.com/nocodb/nocodb
11
https://github.com/nextauthjs/next-auth
11
https://github.com/keystonejs/keystone
11
https://github.com/louislam/uptime-kuma
10
https://github.com/anthropics/claude-code
10
https://github.com/VulnSageAgent/PoCs
10
https://github.com/evershopcommerce/evershop
9
https://github.com/haxtheweb/issues
9
https://github.com/sebhildebrandt/systeminformation
9
https://github.com/matrix-org/matrix-appservice-irc
9
https://github.com/withastro/astro
9
https://github.com/matrix-org/matrix-react-sdk
9
https://github.com/indutny/elliptic
8
https://github.com/kjur/jsrsasign
8
https://github.com/lobehub/lobe-chat
8
https://github.com/pandao/editor.md
8
https://github.com/cure53/DOMPurify
8
https://github.com/ericcornelissen/shescape
8
https://github.com/digitalbazaar/forge
8
https://github.com/nuxt/nuxt
8
https://github.com/honojs/hono
8
https://github.com/apollographql/apollo-server
8
https://github.com/stealjs/steal
8
https://github.com/vega/vega
8
https://github.com/axios/axios
7
https://github.com/twbs/bootstrap
7
https://github.com/aws/aws-cdk
7
https://github.com/jquery/jquery
7
https://github.com/lodash/lodash
7
https://github.com/unshiftio/url-parse
7
https://github.com/saltcorn/saltcorn
7
https://github.com/sveltejs/kit
6
https://github.com/ckeditor/ckeditor5
6
https://github.com/ionicabizau/parse-url
6
https://github.com/apostrophecms/sanitize-html
6
https://github.com/DIYgod/RSSHub
6
https://github.com/facebook/hermes
6
https://github.com/totaljs/framework
6
https://github.com/markedjs/marked
6
https://github.com/npm/node-tar
6
https://github.com/jquery/jquery-ui
6
https://github.com/better-auth/better-auth
6
https://github.com/openpgpjs/openpgpjs
6
https://github.com/eclipse-theia/theia
6
https://github.com/shenzhim/aaptjs
6
https://github.com/panva/jose
6
https://github.com/faisalman/ua-parser-js
5
https://github.com/PrismJS/prism
5
https://github.com/gatsbyjs/gatsby
5
https://github.com/AmauriC/tarteaucitron.js
5
https://github.com/hacksparrow/safe-eval
5
https://github.com/sidorares/node-mysql2
5
https://github.com/fastify/fastify
5
https://github.com/BlackFan/client-side-prototype-pollution
5
https://github.com/Automattic/mongoose
5
https://github.com/handlebars-lang/handlebars.js
5
https://github.com/basecamp/trix
5
https://github.com/auth0/passport-wsfed-saml2
5
https://github.com/sweetalert2/sweetalert2
5
https://github.com/npm/cli
5
https://github.com/cloudflare/workers-sdk
5
https://github.com/mermaid-js/mermaid
5
https://github.com/GoogleChrome/rendertron
5
https://github.com/KaTeX/KaTeX
5
https://github.com/auth0/node-jsonwebtoken
4
https://github.com/typeorm/typeorm
4
https://github.com/koajs/koa
4
https://github.com/node-opcua/node-opcua
4
https://github.com/intlify/vue-i18n
4
https://github.com/erxes/erxes
4
https://github.com/open-webui/open-webui
4
https://github.com/medialize/URI.js
4
https://github.com/Dogfalo/materialize
4
https://github.com/yarnpkg/yarn
4
https://github.com/pnpm/pnpm
4
https://github.com/angular/angular.js
4
https://github.com/xCss/Valine
4
https://github.com/follow-redirects/follow-redirects
4
https://github.com/aws/aws-iot-device-sdk-java-v2
4
https://github.com/auth0/lock
4
https://github.com/ofirdagan/cross-domain-local-storage
4
https://github.com/auth0/nextjs-auth0
4
https://github.com/nodemailer/nodemailer
4
https://github.com/finos/git-proxy
4
https://github.com/expressjs/multer
4
https://github.com/node-saml/node-saml
4
https://github.com/expressjs/express
4
https://github.com/getsentry/sentry-javascript
4
https://github.com/npm/npm
4
https://github.com/medialize/uri.js
4
https://github.com/vendure-ecommerce/vendure
4
https://github.com/mde/ejs
4
https://github.com/Ylianst/MeshCentral
4
https://github.com/balderdashy/sails
4
https://github.com/hapijs/hapi
4
https://github.com/socketio/engine.io
4
https://github.com/NaturalIntelligence/fast-xml-parser
4
https://github.com/payloadcms/payload
4
https://github.com/mafintosh/tar-fs
4
https://github.com/jhipster/generator-jhipster
4
https://github.com/websockets/ws
4
https://github.com/jquery-validation/jquery-validation
4
https://github.com/jonschlinkert/remarkable
4
https://github.com/steveukx/git-js
4
https://github.com/transloadit/uppy
3
https://github.com/zestedesavoir/zmarkdown
3
https://github.com/jasonraimondi/url-to-png
3
https://github.com/apollographql/federation
3
https://github.com/peerigon/angular-expressions
3
https://github.com/libxmljs/libxmljs
3
https://github.com/mongodb/js-bson
3
https://github.com/cloudhead/node-static
3
https://github.com/kujirahand/nadesiko3
3
https://github.com/adaltas/node-mixme
3
https://github.com/cisco/node-jose
3
https://github.com/agnaistic/agnai
3
https://github.com/node-fetch/node-fetch
3
https://github.com/josdejong/mathjs
3
https://github.com/neocotic/convert-svg
3
https://github.com/ua-parser/uap-core
3
https://github.com/zeit/next.js
3
https://github.com/dwisiswant0/advisory
3
https://github.com/nasa/openmct
3
https://github.com/Marak/colors.js
3
https://github.com/gruntjs/grunt
3
https://github.com/udecode/plate
3
https://github.com/highcharts/highcharts
3
https://github.com/ChainSafe/lodestar
3
https://github.com/koush/scrypted
3
https://github.com/eladnava/mailgen
3
https://github.com/vriteio/vrite
3
https://github.com/plone/volto
3
https://github.com/capricorn86/happy-dom
3
https://github.com/jfhbrook/node-ecstatic
3
https://github.com/feathersjs-ecosystem/feathers-sequelize
3
https://github.com/immerjs/immer
3
https://github.com/node-saml/xml-crypto
3
https://github.com/webpack/webpack-dev-server
3
https://github.com/zcaceres/markdownify-mcp
3
https://github.com/RIAEvangelist/node-ipc
3
https://github.com/OpenZeppelin/openzeppelin-contracts-upgradeable
3
https://github.com/nestjs/nest
3
https://github.com/snowflakedb/snowflake-connector-nodejs
3
https://github.com/mozilla/node-convict
3
https://github.com/socketio/socket.io
3
https://github.com/socketio/socket.io-parser
3
https://github.com/hapijs/subtext
3
https://github.com/vanessa219/vditor
3
https://github.com/apostrophecms/apostrophe
3
https://github.com/jarofghosts/glance
3
https://github.com/YMFE/yapi
3
https://github.com/moment/moment
3
https://github.com/manuelstofer/json-pointer
3
https://github.com/postcss/postcss
3
https://github.com/salesforce/tough-cookie
3
https://github.com/dojo/dojox
3
https://github.com/mozilla/pdf.js
3
https://github.com/chjj/marked
3
https://github.com/mariocasciaro/object-path
3
https://github.com/webpack/loader-utils
3
https://github.com/nodejs/llhttp
3
https://github.com/MrRio/jsPDF
3
https://github.com/thlorenz/browserify-shim
3
https://github.com/renovatebot/renovate
3
https://github.com/facebook/react
3
https://github.com/xmldom/xmldom
3
https://github.com/beerpwn/CVE
3
https://github.com/docsifyjs/docsify
3
https://github.com/validatorjs/validator.js
3
https://github.com/remix-run/react-router
3
https://github.com/actions/toolkit
3
https://github.com/Escape-Technologies/graphql-armor
3
https://github.com/mongo-express/mongo-express
3
https://github.com/dojo/dojo
3
https://github.com/soketi/soketi
3
https://github.com/ag-grid/ag-grid
3
https://github.com/HackAllSec/CVEs
3
https://github.com/clientIO/joint
3
https://github.com/chimurai/http-proxy-middleware
3