npm
4,292 tracked vulnerabilities.
CVE-2019-15782
MEDIUM
WebTorrent < 0.107.6 - Cross-Site Scripting via HTTP Server Title or File Name
Aug 29, 2019
CVSS 6.1
EPSS 0.01
CVE-2019-15658
HIGH
connect-pg-simple < 6.0.1 - SQL Injection via Untrusted tableName or schemaName
Aug 26, 2019
CVSS 7.3
EPSS 0.01
CVE-2019-15657
CRITICAL
eslint-utils < 1.4.1 - Remote Code Execution via getStaticValue Function
Aug 26, 2019
CVSS 9.8
EPSS 0.02
CVE-2019-15479
MEDIUM
status-board 1.1.81 - Reflected Cross-Site Scripting via dashboard.ts
Aug 26, 2019
CVSS 6.1
EPSS 0.01
CVE-2019-15532
MEDIUM
CyberChef < 8.31.2 - Cross-Site Scripting in TextEncodingBruteForce
Aug 26, 2019
CVSS 6.1
EPSS 0.01
CVE-2019-15478
MEDIUM
Status Board 1.1.81 - Reflected Cross-Site Scripting via logic.ts
Aug 26, 2019
CVSS 6.1
EPSS 0.01
CVE-2019-10750
CRITICAL
deeply < 3.1.0 - Prototype Pollution via _proto_ Payload
Aug 23, 2019
CVSS 9.8
EPSS 0.02
CVE-2019-10747
CRITICAL
set-value < 2.0.1 - Prototype Pollution via mixin-deep Function
Aug 23, 2019
CVSS 9.8
EPSS 0.02
CVE-2019-10746
CRITICAL
mixin-deep < 1.3.2 - Prototype Pollution via Constructor Payload
Aug 23, 2019
CVSS 9.8
EPSS 0.04
CVE-2019-15482
MEDIUM
selectize-plugin-a11y < 1.1.0 - Cross-Site Scripting via msg Field
Aug 23, 2019
CVSS 6.1
EPSS 0.01
CVE-2019-9155
MEDIUM
Openpgpjs < 4.2.0 - Broken Cryptographic Algorithm
Aug 22, 2019
CVSS 5.9
EPSS 0.01
CVE-2019-9154
HIGH
Openpgpjs < 4.1.2 - Signature Verification Bypass
Aug 22, 2019
CVSS 7.5
EPSS 0.02
CVE-2019-9153
HIGH
Openpgpjs < 4.1.2 - Signature Verification Bypass
Aug 22, 2019
CVSS 7.5
EPSS 0.02
CVE-2019-10745
HIGH
assign-deep < 0.4.8 - Prototype Pollution via Constructor or __proto__ Payload
Aug 20, 2019
CVSS 7.5
EPSS 0.01
CVE-2019-14939
MEDIUM
mysqljs 2.17.1 - Unauthenticated Arbitrary File Read via LOAD DATA LOCAL INFILE
Aug 12, 2019
CVSS 5.5
EPSS 0.00
CVE-2019-14772
MEDIUM
verdaccio < 3.12.0 - Cross-Site Scripting
Aug 08, 2019
CVSS 6.1
EPSS 0.01
CVE-2019-14653
MEDIUM
pandao Editor.md 1.5.0 - Cross-Site Scripting via ABBR or SUP Element Attribute
Aug 03, 2019
CVSS 6.1
EPSS 0.01
CVE-2019-14517
MEDIUM
Editor.md 1.5.0 - Cross-Site Scripting via JavaScript String
Aug 01, 2019
CVSS 6.1
EPSS 0.01
CVE-2019-5458
MEDIUM
http-file-server - Stored Cross-Site Scripting
Jul 30, 2019
CVSS 5.4
EPSS 0.01
CVE-2019-5457
MEDIUM
min-http-server - Stored Cross-Site Scripting
Jul 30, 2019
CVSS 5.4
EPSS 0.01
CVE-2019-5448
HIGH
Yarn < 1.17.3 - Cleartext Transmission of Sensitive Information via HTTP URLs in Lockfile
Jul 30, 2019
CVSS 8.1
EPSS 0.01
CVE-2019-1020013
MEDIUM
parse-server <3.6.0 - Info Disclosure
Jul 29, 2019
CVSS 5.3
EPSS 0.01
CVE-2019-1020012
HIGH
parse-server < 3.4.1 - Denial of Service via POST to Volatile Class
Jul 29, 2019
CVSS 7.5
EPSS 0.01
CVE-2019-10744
CRITICAL
lodash < 4.17.12 - Prototype Pollution via defaultsDeep Function
Jul 26, 2019
CVSS 9.1
EPSS 0.05
CVE-2019-13483
HIGH
passport-sharepoint < 0.4.0 - Unauthenticated JWT Signature Forgery
Jul 25, 2019
CVSS 7.3
EPSS 0.01
Products
openclaw 433
parse-server 98
n8n 87
flowise 67
directus 55
nocodb 54
electron 49
next 47
vm2 41
hono 38
axios 33
undici 30
pnpm 25
ghost 22
vite 21
astro 19
tar 19
tinymce 18
protobufjs 16
ckeditor4 15
fuxa-server 15
jspdf 15
joplin 14
liquidjs 14
nodebb 14
sequelize 14
angular 13
flowise-components 13
react-router 13
signalk-server 13
Quick Filters