
npm
5,162,107 packages · npmjs.org
Security Advisories in npm
Critical
8 months ago
Better Auth URL parameter HTML Injection (Reflected Cross-Site scripting)
npm
better-auth
Critical
8 months ago
Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening
npm
vitest
Moderate
8 months ago
snowflake-sdk may incorrectly validate temporary credential cache file permissions
npm
snowflake-sdk
Low
8 months ago
Potential DoS when using ContextLines integration
npm
@sentry/remix, @sentry/nuxt, @sentry/nextjs, @sentry/nestjs, @sentry/google-cloud-serverless, @sentry/bun, @sentry/aws-serverless, @sentry/astro, @sentry/node
Moderate
8 months ago
Opening a malicious website while running a Nuxt dev server could allow read-only access to code
npm
@nuxt/rspack-builder, @nuxt/webpack-builder
Moderate
8 months ago
Opening a malicious website while running a Nuxt dev server could allow read-only access to code
npm
@nuxt/vite-builder
Low
8 months ago
Directus has a DOM-Based cross-site scripting (XSS) via layout_options
npm
directus
Moderate
8 months ago
XSS/HTML Injection Vulnerability in Umbraco Backoffice Components
npm, nuget
@umbraco-cms/backoffice, Umbraco.Cms.StaticAssets
Moderate
8 months ago
Infinite loop and Blind SSRF found inside the Webfinger mechanism in @fedify/fedify
npm
@fedify/fedify
Moderate
8 months ago
Websites were able to send any requests to the development server and read the response in vite
npm
vite
Low
9 months ago
AWS Cloud Development Kit (AWS CDK) IAM OIDC custom resource allows connection to unauthorized OIDC provider
npm
aws-cdk-lib
Moderate
9 months ago
parse-uri Regular expression Denial of Service (ReDoS)
npm
parseuri, parse-uri
Critical
9 months ago
path-sanitizer allows bypassing the existing filters to achieve path-traversal vulnerability
npm
path-sanitizer
High
9 months ago
Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint
npm
better-auth
Moderate
9 months ago
Marp Core allows XSS by improper neutralization of HTML sanitization
npm
@marp-team/marp-core
High
10 months ago
Systeminformation has command injection vulnerability in getWindowsIEEE8021x (SSID)
npm
systeminformation
Moderate
10 months ago
uptime-kuma vulnerable to Local File Inclusion (LFI) via Improper URL Handling in `Real-Browser` monitor
npm
uptime-kuma
High
10 months ago
Astro's server source code is exposed to the public if sourcemaps are enabled
npm
astro
Moderate
10 months ago
Bun has an Application-level Prototype Pollution vulnerability in the runtime native API for Glo
npm
bun
Moderate
10 months ago
pnpm no-script global cache poisoning via overrides / `ignore-scripts` evasion
npm
pnpm
Critical
10 months ago
Angular Expressions - Remote Code Execution when using locals
npm
angular-expressions
High
10 months ago
Directus allows unauthenticated access to WebSocket events and operations
npm
@directus/api, directus
Moderate
10 months ago
Predictable results in nanoid generation when given non-integer values
npm
nanoid
High
10 months ago
Modified package published to npm, containing malware that exfiltrates private key material
npm
@solana/web3.js
Moderate
10 months ago
Backstage Scaffolder plugin vulnerable to Server-Side Request Forgery
npm
@backstage/plugin-scaffolder-node
Moderate
10 months ago
@intlify/shared Prototype Pollution vulnerability
npm
vue-i18n, @intlify/vue-i18n-core, @intlify/shared, petite-vue-i18n
Moderate
10 months ago
vue-i18n has cross-site scripting vulnerability with prototype pollution
npm
@intlify/vue-i18n-core, @intlify/core, vue-i18n, @intlify/core-base, petite-vue-i18n
Moderate
10 months ago
@dapperduckling/keycloak-connector-server has Reflected XSS Vulnerability in Authentication Flow URL Handling
npm
@dapperduckling/keycloak-connector-server
Low
10 months ago
@sveltejs/kit has unescaped error message included on error page
npm
@sveltejs/kit
Moderate
10 months ago
smol-toml has a Denial of Service via malicious TOML document using deeply nested inline tables
npm
smol-toml
Moderate
11 months ago
Firebase JavaScript SDK allows attackers to manipulate the "_authTokenSyncURL" to point to their own server
npm
firebase
Low
11 months ago
Regular Expression Denial of Service (ReDoS) in @eslint/plugin-kit
npm
@eslint/plugin-kit
Moderate
11 months ago
matrix-js-sdk has insufficient MXC URI validation which allows client-side path traversal
npm
matrix-js-sdk
Moderate
11 months ago
Froala WYSIWYG editor allows cross-site scripting (XSS)
packagist, npm
froala/wysiwyg-editor, froala-editor
Critical
11 months ago
happy-dom allows for server side code to be executed by a <script> tag
npm
happy-dom
Low
11 months ago
@workos-inc/authkit-remix refresh tokens are logged when the debug flag is enabled
npm
@workos-inc/authkit-remix
Low
11 months ago
@workos-inc/authkit-nextjs refresh tokens are logged when the debug flag is enabled
npm
@workos-inc/authkit-nextjs
High
11 months ago
Path traversal in oak allows transfer of hidden files within the served root directory
npm
@oakserver/oak
Moderate
11 months ago
CycloneDX cdxgen may execute code contained within build-related files
npm
@cyclonedx/cdxgen
Moderate
11 months ago
Foundation Regular Expression Denial of Service vulnerability
npm
foundation-sites
Moderate
11 months ago
nope-validator Regular Expression Denial of Service vulnerability
npm
nope-validator
Moderate
11 months ago
CommonRegexJS Regular Expression Denial of Service vulnerability
npm
commonregex
Moderate
11 months ago
validate.js Regular Expression Denial of Service vulnerability
npm
validate.js
High
11 months ago
Prototype pollution vulnerability found in Mermaid's bundled version of DOMPurify
npm
mermaid
High
12 months ago
Malicious homeservers can steal message keys when the matrix-react-sdk user invites another user to a room
npm
matrix-react-sdk
High
12 months ago
Matrix JavaScript SDK's key history sharing could share keys to malicious devices
npm
matrix-js-sdk
Critical
12 months ago
Vendure asset server plugin has local file read vulnerability with AssetServerPlugin & LocalAssetStorageStrategy
npm
@vendure/asset-server-plugin
Moderate
12 months ago
Hono allows bypass of CSRF Middleware by a request without Content-Type header.
npm
hono
Filter by Severity
Filter by Package
directus
39
parse-server
33
next
29
electron
28
flowise
24
@openzeppelin/contracts-upgradeable
21
@openzeppelin/contracts
21
ghost
16
sequelize
16
tinymce
16
undici
15
vite
15
ckeditor4
15
joplin
14
swagger-ui
14
angular
14
nodebb
14
strapi
13
matrix-js-sdk
12
marked
12
vm2
12
nocodb
11
handlebars
11
TinyMCE
11
tinymce/tinymce
11
n8n
10
matrix-appservice-irc
9
@strapi/strapi
9
uptime-kuma
9
@evershop/evershop
9
matrix-react-sdk
9
systeminformation
9
serve
9
next-auth
9
sanitize-html
8
@directus/api
8
@anthropic-ai/claude-code
8
urijs
8
@haxtheweb/haxcms-nodejs
8
url-parse
8
dompurify
8
npm
8
jsrsasign
8
elliptic
8
steal
8
editor.md
8
shescape
8
express-cart
8
node-forge
8
validator
8
axios
7
snyk-broker
7
hermes-engine
7
tar
7
hapi
7
vega
7
@lobehub/chat
7
mermaid
7
total.js
7
mongoose
7
@strapi/plugin-users-permissions
6
hono
6
jquery-ui
6
rsshub
6
prismjs
6
@sveltejs/kit
6
tarteaucitronjs
6
safe-eval
6
org.webjars.npm:jquery-ui
6
bootstrap
6
jQuery.UI.Combined
6
parse-url
6
mattermost-desktop
6
aaptjs
6
openpgp
6
yarn
5
aws-cdk-lib
5
jquery
5
keystone
5
total4
5
@backstage/plugin-scaffolder-backend
5
@saltcorn/server
5
public
5
jspdf
5
ws
5
vditor
5
ua-parser-js
5
better-auth
5
sweetalert2
5
nuxt
5
rendertron
5
astro
5
xlsx
5
froala-editor
5
trix
5
express
5
katex
5
passport-wsfed-saml2
5
fastify
5
@keystone-6/core
5
dojo
5
mysql2
5
ejs
5
moment
4
generator-jhipster
4
@auth0/nextjs-auth0
4
payload
4
fast-xml-parser
4
ecstatic
4
jsonwebtoken
4
auth0-js
4
follow-redirects
4
materialize-css
4
software.amazon.awssdk.iotdevicesdk:aws-iot-device-sdk
4
glance
4
@finos/git-proxy
4
valine
4
@node-saml/node-saml
4
engine.io
4
@intlify/vue-i18n-core
4
pnpm
4
safer-eval
4
apollo-server-core
4
twbs/bootstrap
4
bootstrap
4
convert-svg-core
4
petite-vue-i18n
4
@apollo/gateway
4
erxes
4
snyk
4
xml-crypto
4
bootstrap
4
simple-markdown
4
muhammara
4
remarkable
4
auth0-lock
4
mongo-express
4
org.webjars:bootstrap
4
tar-fs
4
yui
4
qs
4
ses
4
hummus
4
multer
4
mongosh
4
meshcentral
4
apostrophe
4
aws-iot-device-sdk-v2
4
jquery-validation
4
realms-shim
4
bootstrap-sass
4
vega-functions
4
code-server
4
jQuery
4
vue-i18n
4
simple-git
4
m-server
3
highcharts
3
@backstage/techdocs-common
3
@intlify/core
3
xdLocalStorage
3
llhttp
3
localhost-now
3
socket.io
3
@strapi/admin
3
@soketi/soketi
3
@strapi/utils
3
node-red-dashboard
3
ftp-srv
3
socket.io-file
3
json-pointer
3
serialize-javascript
3
dojox
3
uap-core
3
parsel
3
libxmljs
3
locutus
3
mcp-markdownify-server
3
@cubejs-backend/api-gateway
3
@janhq/core
3
jointjs
3
slp-validate
3
immer
3
nodemailer
3
webpack-dev-server
3
mysql
3
@apollo/server
3
simplehttpserver
3
http-live-simulator
3
@commercial/subtext
3
@frangoteam/fuxa
3
ids-enterprise
3
loader-utils
3
renovate
3
open-webui
3
nadesiko3
3
tough-cookie
3
awsiotsdk
3
buttle
3
mixme
3
Filter by Repository
https://github.com/directus/directus
41
https://github.com/parse-community/parse-server
33
https://github.com/electron/electron
28
https://github.com/vercel/next.js
25
https://github.com/strapi/strapi
25
https://github.com/OpenZeppelin/openzeppelin-contracts
21
https://github.com/FlowiseAI/Flowise
20
https://github.com/backstage/backstage
19
https://github.com/sequelize/sequelize
16
https://github.com/tinymce/tinymce
16
https://github.com/nodejs/undici
15
https://github.com/vitejs/vite
15
https://github.com/TryGhost/Ghost
14
https://github.com/ckeditor/ckeditor4
14
https://github.com/swagger-api/swagger-ui
13
https://github.com/laurent22/joplin
13
https://github.com/NodeBB/NodeBB
12
https://github.com/matrix-org/matrix-js-sdk
12
https://github.com/VulnSageAgent/PoCs
12
https://github.com/patriksimek/vm2
12
https://github.com/nocodb/nocodb
11
https://github.com/keystonejs/keystone
11
https://github.com/nextauthjs/next-auth
10
https://github.com/n8n-io/n8n
10
https://github.com/matrix-org/matrix-appservice-irc
9
https://github.com/louislam/uptime-kuma
9
https://github.com/sebhildebrandt/systeminformation
9
https://github.com/evershopcommerce/evershop
9
https://github.com/haxtheweb/issues
9
https://github.com/matrix-org/matrix-react-sdk
9
https://github.com/stealjs/steal
8
https://github.com/ericcornelissen/shescape
8
https://github.com/nuxt/nuxt
8
https://github.com/pandao/editor.md
8
https://github.com/cure53/DOMPurify
8
https://github.com/anthropics/claude-code
8
https://github.com/digitalbazaar/forge
8
https://github.com/vega/vega
8
https://github.com/kjur/jsrsasign
8
https://github.com/indutny/elliptic
8
https://github.com/apollographql/apollo-server
8
https://github.com/withastro/astro
7
https://github.com/jquery/jquery
7
https://github.com/axios/axios
7
https://github.com/unshiftio/url-parse
7
https://github.com/lobehub/lobe-chat
7
https://github.com/aws/aws-cdk
7
https://github.com/saltcorn/saltcorn
7
https://github.com/ionicabizau/parse-url
6
https://github.com/eclipse-theia/theia
6
https://github.com/facebook/hermes
6
https://github.com/sveltejs/kit
6
https://github.com/ckeditor/ckeditor5
6
https://github.com/totaljs/framework
6
https://github.com/shenzhim/aaptjs
6
https://github.com/panva/jose
6
https://github.com/apostrophecms/sanitize-html
6
https://github.com/openpgpjs/openpgpjs
6
https://github.com/markedjs/marked
6
https://github.com/honojs/hono
6
https://github.com/DIYgod/RSSHub
6
https://github.com/npm/node-tar
6
https://github.com/gatsbyjs/gatsby
5
https://github.com/sidorares/node-mysql2
5
https://github.com/npm/cli
5
https://github.com/hacksparrow/safe-eval
5
https://github.com/mermaid-js/mermaid
5
https://github.com/basecamp/trix
5
https://github.com/AmauriC/tarteaucitron.js
5
https://github.com/jquery/jquery-ui
5
https://github.com/fastify/fastify
5
https://github.com/better-auth/better-auth
5
https://github.com/auth0/passport-wsfed-saml2
5
https://github.com/GoogleChrome/rendertron
5
https://github.com/cloudflare/workers-sdk
5
https://github.com/Automattic/mongoose
5
https://github.com/handlebars-lang/handlebars.js
5
https://github.com/PrismJS/prism
5
https://github.com/KaTeX/KaTeX
5
https://github.com/sweetalert2/sweetalert2
5
https://github.com/faisalman/ua-parser-js
5
https://github.com/BlackFan/client-side-prototype-pollution
5
https://github.com/Ylianst/MeshCentral
4
https://github.com/auth0/node-jsonwebtoken
4
https://github.com/payloadcms/payload
4
https://github.com/hapijs/hapi
4
https://github.com/jonschlinkert/remarkable
4
https://github.com/jhipster/generator-jhipster
4
https://github.com/auth0/lock
4
https://github.com/erxes/erxes
4
https://github.com/node-opcua/node-opcua
4
https://github.com/mde/ejs
4
https://github.com/npm/npm
4
https://github.com/finos/git-proxy
4
https://github.com/node-saml/node-saml
4
https://github.com/intlify/vue-i18n
4
https://github.com/expressjs/express
4
https://github.com/balderdashy/sails
4
https://github.com/follow-redirects/follow-redirects
4
https://github.com/yarnpkg/yarn
4
https://github.com/mafintosh/tar-fs
4
https://github.com/auth0/nextjs-auth0
4
https://github.com/medialize/uri.js
4
https://github.com/NaturalIntelligence/fast-xml-parser
4
https://github.com/ofirdagan/cross-domain-local-storage
4
https://github.com/websockets/ws
4
https://github.com/jquery-validation/jquery-validation
4
https://github.com/socketio/engine.io
4
https://github.com/aws/aws-iot-device-sdk-java-v2
4
https://github.com/vendure-ecommerce/vendure
4
https://github.com/mrvautin/expressCart
4
https://github.com/pnpm/pnpm
4
https://github.com/medialize/URI.js
4
https://github.com/expressjs/multer
4
https://github.com/getsentry/sentry-javascript
4
https://github.com/steveukx/git-js
4
https://github.com/xCss/Valine
4
https://github.com/Dogfalo/materialize
4
https://github.com/angular/angular.js
4
https://github.com/jfhbrook/node-ecstatic
3
https://github.com/soketi/soketi
3
https://github.com/manuelstofer/json-pointer
3
https://github.com/mozilla/node-convict
3
https://github.com/micromatch/braces
3
https://github.com/ua-parser/uap-core
3
https://github.com/endojs/endo
3
https://github.com/moment/moment
3
https://github.com/docsifyjs/docsify
3
https://github.com/josdejong/mathjs
3
https://github.com/simpleledger/slpjs
3
https://github.com/snyk/cli
3
https://github.com/nodejs/llhttp
3
https://github.com/socketio/socket.io
3
https://github.com/lukeed/dset
3
https://github.com/Escape-Technologies/graphql-armor
3
https://github.com/transloadit/uppy
3
https://github.com/ChainSafe/lodestar
3
https://github.com/OpenZeppelin/openzeppelin-contracts-upgradeable
3
https://github.com/facebook/react
3
https://github.com/chjj/marked
3
https://github.com/salesforce/tough-cookie
3
https://github.com/postcss/postcss
3
https://github.com/Marak/colors.js
3
https://github.com/adaltas/node-mixme
3
https://github.com/libxmljs/libxmljs
3
https://github.com/cloudhead/node-static
3
https://github.com/plone/volto
3
https://github.com/twbs/bootstrap
3
https://github.com/dwisiswant0/advisory
3
https://github.com/nestjs/nest
3
https://github.com/vriteio/vrite
3
https://github.com/dojo/dojox
3
https://github.com/renovatebot/renovate
3
https://github.com/peerigon/angular-expressions
3
https://github.com/koajs/koa
3
https://github.com/jarofghosts/glance
3
https://github.com/gruntjs/grunt
3
https://github.com/socketio/socket.io-parser
3
https://github.com/chimurai/http-proxy-middleware
3
https://github.com/snowflakedb/snowflake-connector-nodejs
3
https://github.com/mozilla/pdf.js
3
https://github.com/beerpwn/CVE
3
https://github.com/actions/toolkit
3
https://github.com/cisco/node-jose
3
https://github.com/nodemailer/nodemailer
3
https://github.com/mongo-express/mongo-express
3
https://github.com/froala/wysiwyg-editor
3
https://github.com/skoranga/node-dns-sync
3
https://github.com/typeorm/typeorm
3
https://github.com/hapijs/subtext
3
https://github.com/MrRio/jsPDF
3
https://github.com/vanessa219/vditor
3
https://github.com/zeit/next.js
3
https://github.com/fastify/fastify-multipart
3
https://github.com/webpack/webpack-dev-server
3
https://github.com/node-saml/xml-crypto
3
https://github.com/webpack/loader-utils
3
https://github.com/RIAEvangelist/node-ipc
3
https://github.com/neocotic/convert-svg
3
https://github.com/zestedesavoir/zmarkdown
3
https://github.com/immerjs/immer
3
https://github.com/apostrophecms/apostrophe
3
https://github.com/remix-run/react-router
3
https://github.com/HackAllSec/CVEs
3
https://github.com/jasonraimondi/url-to-png
3
https://github.com/thlorenz/browserify-shim
3
https://github.com/ag-grid/ag-grid
3
https://github.com/YMFE/yapi
3
https://github.com/mongodb/js-bson
3
https://github.com/udecode/plate
3
https://github.com/koush/scrypted
3
https://github.com/highcharts/highcharts
3
https://github.com/zcaceres/markdownify-mcp
3
https://github.com/agnaistic/agnai
3
https://github.com/infor-design/enterprise-ng
3
https://github.com/yahoo/serialize-javascript
3
https://github.com/clientIO/joint
3
https://github.com/mariocasciaro/object-path
3
https://github.com/xmldom/xmldom
3