npm

4,292 tracked vulnerabilities.

CVE-2019-15782 MEDIUM
WebTorrent < 0.107.6 - Cross-Site Scripting via HTTP Server Title or File Name
Aug 29, 2019
CVSS 6.1
EPSS 0.01
CVE-2019-15658 HIGH
connect-pg-simple < 6.0.1 - SQL Injection via Untrusted tableName or schemaName
Aug 26, 2019
CVSS 7.3
EPSS 0.01
CVE-2019-15657 CRITICAL
eslint-utils < 1.4.1 - Remote Code Execution via getStaticValue Function
Aug 26, 2019
CVSS 9.8
EPSS 0.02
CVE-2019-15479 MEDIUM
status-board 1.1.81 - Reflected Cross-Site Scripting via dashboard.ts
Aug 26, 2019
CVSS 6.1
EPSS 0.01
CVE-2019-15532 MEDIUM
CyberChef < 8.31.2 - Cross-Site Scripting in TextEncodingBruteForce
Aug 26, 2019
CVSS 6.1
EPSS 0.01
CVE-2019-15478 MEDIUM
Status Board 1.1.81 - Reflected Cross-Site Scripting via logic.ts
Aug 26, 2019
CVSS 6.1
EPSS 0.01
CVE-2019-10750 CRITICAL
deeply < 3.1.0 - Prototype Pollution via _proto_ Payload
Aug 23, 2019
CVSS 9.8
EPSS 0.02
CVE-2019-10747 CRITICAL
set-value < 2.0.1 - Prototype Pollution via mixin-deep Function
Aug 23, 2019
CVSS 9.8
EPSS 0.02
CVE-2019-10746 CRITICAL
mixin-deep < 1.3.2 - Prototype Pollution via Constructor Payload
Aug 23, 2019
CVSS 9.8
EPSS 0.04
CVE-2019-15482 MEDIUM
selectize-plugin-a11y < 1.1.0 - Cross-Site Scripting via msg Field
Aug 23, 2019
CVSS 6.1
EPSS 0.01
CVE-2019-9155 MEDIUM
Openpgpjs < 4.2.0 - Broken Cryptographic Algorithm
Aug 22, 2019
CVSS 5.9
EPSS 0.01
CVE-2019-9154 HIGH
Openpgpjs < 4.1.2 - Signature Verification Bypass
Aug 22, 2019
CVSS 7.5
EPSS 0.02
CVE-2019-9153 HIGH
Openpgpjs < 4.1.2 - Signature Verification Bypass
Aug 22, 2019
CVSS 7.5
EPSS 0.02
CVE-2019-10745 HIGH
assign-deep < 0.4.8 - Prototype Pollution via Constructor or __proto__ Payload
Aug 20, 2019
CVSS 7.5
EPSS 0.01
CVE-2019-14939 MEDIUM
mysqljs 2.17.1 - Unauthenticated Arbitrary File Read via LOAD DATA LOCAL INFILE
Aug 12, 2019
CVSS 5.5
EPSS 0.00
CVE-2019-14772 MEDIUM
verdaccio < 3.12.0 - Cross-Site Scripting
Aug 08, 2019
CVSS 6.1
EPSS 0.01
CVE-2019-14653 MEDIUM
pandao Editor.md 1.5.0 - Cross-Site Scripting via ABBR or SUP Element Attribute
Aug 03, 2019
CVSS 6.1
EPSS 0.01
CVE-2019-14517 MEDIUM
Editor.md 1.5.0 - Cross-Site Scripting via JavaScript String
Aug 01, 2019
CVSS 6.1
EPSS 0.01
CVE-2019-5458 MEDIUM
http-file-server - Stored Cross-Site Scripting
Jul 30, 2019
CVSS 5.4
EPSS 0.01
CVE-2019-5457 MEDIUM
min-http-server - Stored Cross-Site Scripting
Jul 30, 2019
CVSS 5.4
EPSS 0.01
CVE-2019-5448 HIGH
Yarn < 1.17.3 - Cleartext Transmission of Sensitive Information via HTTP URLs in Lockfile
Jul 30, 2019
CVSS 8.1
EPSS 0.01
CVE-2019-1020013 MEDIUM
parse-server <3.6.0 - Info Disclosure
Jul 29, 2019
CVSS 5.3
EPSS 0.01
CVE-2019-1020012 HIGH
parse-server < 3.4.1 - Denial of Service via POST to Volatile Class
Jul 29, 2019
CVSS 7.5
EPSS 0.01
CVE-2019-10744 CRITICAL
lodash < 4.17.12 - Prototype Pollution via defaultsDeep Function
Jul 26, 2019
CVSS 9.1
EPSS 0.05
CVE-2019-13483 HIGH
passport-sharepoint < 0.4.0 - Unauthenticated JWT Signature Forgery
Jul 25, 2019
CVSS 7.3
EPSS 0.01