npm
4,292 tracked vulnerabilities.
CVE-2018-3734
HIGH
stattic < 0.3.0 - Path Traversal
May 29, 2018
CVSS 7.5
EPSS 0.02
CVE-2018-3733
HIGH
crud-file-server < 0.9.0 - Path Traversal via URL Validation Bypass
May 29, 2018
CVSS 7.5
EPSS 0.02
CVE-2018-7160
HIGH
Node.js 6.0.0-6.8.0 and 6.9.0-6.13.1 - Remote Code Execution via DNS Rebinding Attack
May 17, 2018
CVSS 8.8
EPSS 0.10
CVE-2018-9861
MEDIUM
CKEditor Enhanced Image 4.5.10-4.9.1 - Cross-Site Scripting via Crafted IMG Element
Apr 19, 2018
CVSS 6.1
EPSS 0.02
CVE-2018-6874
HIGH
auth0.js < 8.12.1 and npm/auth0-js < 9.0.0 - Cross-Site Request Forgery via Legacy Lock API
Apr 04, 2018
CVSS 8.8
EPSS 0.01
CVE-2018-3728
HIGH
hoek < 4.2.0 and 5.0.x < 5.0.3 - Prototype Pollution via merge and applyToDefaults Functions
Mar 30, 2018
CVSS 8.8
EPSS 0.04
CVE-2018-1000136
HIGH
Electron 1.7.0-1.7.12, 1.8.0-1.8.3, 2.0.0-beta.0-2.0.0-beta.3 - RCE via Webview Node Integration Bypass
Mar 23, 2018
CVSS 8.1
EPSS 0.05
CVE-2018-1000086
HIGH
NPR Visuals Team Pym.js <1.3.2 - CSRF
Mar 13, 2018
CVSS 8.8
EPSS 0.01
CVE-2018-1000096
HIGH
tiny-json-http 1.0.0-6.9.9 - Improper Certificate Validation
Mar 13, 2018
CVSS 8.1
EPSS 0.01
CVE-2018-1000118
HIGH
Github Electron <1.8.2.4 - Command Injection
Mar 07, 2018
CVSS 8.8
EPSS 0.02
CVE-2018-7307
HIGH
auth0.js < 9.3 - Cross-Site Request Forgery via Missing State Parameter
Mar 06, 2018
CVSS 8.8
EPSS 0.01
CVE-2018-7560
HIGH
aws-lambda-multipart-parser < 0.1.2 - Regular Expression Denial of Service via Crafted Multipart Boundary
Mar 04, 2018
CVSS 7.5
EPSS 0.01
CVE-2018-7651
MEDIUM
ssri < 5.2.2 - Denial of Service via Long Base64 Hash String
Mar 04, 2018
CVSS 5.9
EPSS 0.02
CVE-2018-7408
HIGH
npm 5.7.0 - Incorrect Permission Assignment for Critical Resource via correctMkdir
Feb 22, 2018
CVSS 7.8
EPSS 0.00
CVE-2018-6591
MEDIUM
Converse.js < 3.3 - Unintended Exposure of Sensitive Information
Feb 19, 2018
CVSS 5.3
EPSS 0.01
CVE-2018-1000023
MEDIUM
Bitpay/insight-api <5.0.0 - Info Disclosure
Feb 09, 2018
CVSS 5.3
EPSS 0.01
CVE-2018-6835
CRITICAL
Etherpad Lite < 1.6.3 - Unauthenticated Access Restriction Bypass via JSONP Mishandling
Feb 08, 2018
CVSS 9.8
EPSS 0.02
CVE-2018-6561
MEDIUM
Dojo Toolkit 1.13 - Cross-Site Scripting via SVG onload Attribute in dijit.Editor
Feb 02, 2018
CVSS 6.1
EPSS 0.01
CVE-2018-6464
MEDIUM
Simditor 2.3.11 - Cross-Site Scripting via SVG onload Attribute in TEXTAREA Element
Jan 31, 2018
CVSS 6.1
EPSS 0.01
CVE-2018-1000006
HIGH
Electron < 1.7.11 - Remote Code Execution via Protocol Handler
Jan 24, 2018
CVSS 8.8
EPSS 0.84
CVE-2018-6184
HIGH
NUCLEI
ZEIT Next.js <4.2.3 - Path Traversal
Jan 24, 2018
CVSS 7.5
EPSS 0.09
CVE-2018-0114
HIGH
Cisco node-jose < 0.11.0 - Unauthenticated Token Re-signing via Embedded Public Key
Jan 04, 2018
CVSS 7.5
EPSS 0.43
CVE-2017-20165
LOW
debug < 3.1.0 - Inefficient Regular Expression Complexity in useColors Function
Jan 09, 2023
CVSS 3.5
EPSS 0.02
CVE-2017-20162
MEDIUM
Vercel MS <2.0.0 - Regular Expression Complexity
Jan 05, 2023
CVSS 4.3
EPSS 0.01
CVE-2017-20160
MEDIUM
flitto express-param <1.0.0 - Improper Parameter Handling
Dec 31, 2022
CVSS 6.3
EPSS 0.01
Products
openclaw 433
parse-server 98
n8n 87
flowise 67
directus 55
nocodb 54
electron 49
next 47
vm2 41
hono 38
axios 33
undici 30
pnpm 25
ghost 22
vite 21
astro 19
tar 19
tinymce 18
protobufjs 16
ckeditor4 15
fuxa-server 15
jspdf 15
joplin 14
liquidjs 14
nodebb 14
sequelize 14
angular 13
flowise-components 13
react-router 13
signalk-server 13
Quick Filters