npm
4,292 tracked vulnerabilities.
CVE-2019-10061
CRITICAL
node-opencv <6.1.0 - Command Injection
Mar 26, 2019
CVSS 9.8
EPSS 0.04
CVE-2019-5417
HIGH
serve 7.0.1 - Path Traversal
Mar 21, 2019
CVSS 7.5
EPSS 0.02
CVE-2019-5416
HIGH
localhost-now <1.0.2 - Path Traversal
Mar 21, 2019
CVSS 7.5
EPSS 0.02
CVE-2019-5415
HIGH
serve 6.5.3 - Unauthenticated Directory Listing and File Read via Ignore Feature
Mar 21, 2019
CVSS 7.5
EPSS 0.02
CVE-2019-5414
HIGH
kill-port < 1.3.2 - Command Injection
Mar 21, 2019
CVSS 8.1
EPSS 0.02
CVE-2019-5413
CRITICAL
morgan < 1.9.1 - Remote Code Execution via Format Parameter Injection
Mar 21, 2019
CVSS 9.8
EPSS 0.03
CVE-2019-9737
MEDIUM
Editor.md 1.5.0 - DOM-based Cross-Site Scripting via EMBED SRC Attribute
Mar 13, 2019
CVSS 6.1
EPSS 0.01
CVE-2019-9115
CRITICAL
irisnet-crypto < 1.1.7 - Remote Code Execution via Unsafe Eval in util/utils.js
Feb 25, 2019
CVSS 9.8
EPSS 0.02
CVE-2019-8331
MEDIUM
Bootstrap < 3.4.1 and 4.3.x < 4.3.1 - Cross-Site Scripting via Tooltip or Popover Data-Template Attribute
Feb 20, 2019
CVSS 6.1
EPSS 0.17
CVE-2019-8903
HIGH
NUCLEI
Total.js prior to 3.2.4 Directory Traversal
Feb 18, 2019
CVSS 7.5
EPSS 0.72
CVE-2019-0542
HIGH
xterm.js < 5.0.0 - Remote Code Execution via Special Character Mishandling
Jan 09, 2019
CVSS 8.8
EPSS 0.03
CVE-2018-25110
HIGH
marked < 0.3.17 - Denial of Service via Regular Expression Backtracking
May 23, 2025
CVSS 7.5
EPSS 0.00
CVE-2018-25083
CRITICAL
pullit < 1.4.0 - OS Command Injection via Git Branch Name
Mar 27, 2023
CVSS 9.8
EPSS 0.03
CVE-2018-25079
MEDIUM
Segmentio is-url < 1.2.2 - Inefficient Regular Expression Complexity in index.js
Feb 04, 2023
CVSS 4.3
EPSS 0.01
CVE-2018-25077
LOW
melnaron mel-spintax - Info Disclosure
Jan 18, 2023
CVSS 3.5
EPSS 0.01
CVE-2018-25074
LOW
skeemas < 1.2.5 - Inefficient Regular Expression Complexity in URI Validation
Jan 11, 2023
CVSS 3.5
EPSS 0.01
CVE-2018-25066
MEDIUM
PeterMu nodebatis <2.2.0 - SQL Injection
Jan 06, 2023
CVSS 5.5
EPSS 0.01
CVE-2018-25061
MEDIUM
rgb2hex <0.1.5 - Regular Expression Complexity
Dec 31, 2022
CVSS 4.3
EPSS 0.01
CVE-2018-25058
MEDIUM
twitter-post-fetcher < 18.0.0 - Use of Web Link to Untrusted Target with window.opener Access in Link Target Handler
Dec 29, 2022
CVSS 4.2
EPSS 0.01
CVE-2018-25053
MEDIUM
json2html < 1.2.0 - Cross-Site Scripting
Dec 28, 2022
CVSS 4.3
EPSS 0.01
CVE-2018-25049
LOW
email-existence - Inefficient Regular Expression Complexity in index.js
Dec 27, 2022
CVSS 3.0
EPSS 0.01
CVE-2018-25031
MEDIUM
NUCLEI
Swagger UI < 4.1.3 - Server-Side Request Forgery via OpenAPI Definition URL
Mar 11, 2022
CVSS 4.3
EPSS 0.42
CVE-2018-1109
MEDIUM
braces 2.2.0-2.3.0 - Regular Expression Denial of Service
Mar 30, 2021
CVSS 5.3
EPSS 0.01
CVE-2018-1107
MEDIUM
is-my-json-valid <1.4.1 and >=2.0.0 <2.17.2 - Uncontrolled Resource Consumption via Email Format Validation
Mar 30, 2021
CVSS 5.3
EPSS 0.01
CVE-2018-21270
MEDIUM
Node.js stringstream < 0.0.6 - Out-of-bounds Read via Uninitialized Buffer Allocation
Dec 03, 2020
CVSS 6.5
EPSS 0.04
Products
openclaw 433
parse-server 98
n8n 87
flowise 67
directus 55
nocodb 54
electron 49
next 47
vm2 41
hono 38
axios 33
undici 30
pnpm 25
ghost 22
vite 21
astro 19
tar 19
tinymce 18
protobufjs 16
ckeditor4 15
fuxa-server 15
jspdf 15
joplin 14
liquidjs 14
nodebb 14
sequelize 14
angular 13
flowise-components 13
react-router 13
signalk-server 13
Quick Filters