npm
4,315 tracked vulnerabilities.
CVE-2017-16021
MEDIUM
uri-js < 2.1.1 - Inefficient Regular Expression Complexity in URL Validation
Jun 04, 2018
CVSS 6.5
EPSS 0.01
CVE-2017-16020
CRITICAL
Summit 0.1.0-0.1.20 - OS Command Injection via PouchDB Collection Name
Jun 04, 2018
CVSS 9.8
EPSS 0.02
CVE-2017-16019
MEDIUM
GitBook < 3.2.2 - Stored Cross-Site Scripting via Ebook Code Injection
Jun 04, 2018
CVSS 6.1
EPSS 0.01
CVE-2017-16018
MEDIUM
restify 2.0.0-4.0.4 - Cross-Site Scripting via URL Encoded Script Tags
Jun 04, 2018
CVSS 6.1
EPSS 0.01
CVE-2017-16017
MEDIUM
sanitize-html < 1.2.2 - Cross-Site Scripting
Jun 04, 2018
CVSS 6.1
EPSS 0.01
CVE-2017-16016
MEDIUM
sanitize-html < 1.11.1 - Cross-Site Scripting via Non-Text Tag Handling
Jun 04, 2018
CVSS 6.1
EPSS 0.01
CVE-2017-16015
MEDIUM
forms < 1.3.0 - Cross-Site Scripting via Improper HTML Escaping
Jun 04, 2018
CVSS 6.1
EPSS 0.01
CVE-2017-16014
HIGH
http-proxy < 0.7.0 - Denial of Service via Error Handling
Jun 04, 2018
CVSS 7.5
EPSS 0.02
CVE-2017-16013
HIGH
hapi 15.0.0-16.1.0 - Denial of Service via Malformed Accept-Encoding Header
Jun 04, 2018
CVSS 7.5
EPSS 0.02
CVE-2017-16009
MEDIUM
ag-grid < 27.0.0 - Cross-Site Scripting via Angular Expressions
Jun 04, 2018
CVSS 6.1
EPSS 0.01
CVE-2017-16008
MEDIUM
i18next <=1.10.2 - Cross-Site Scripting via Interpolation Injection
Jun 04, 2018
CVSS 6.1
EPSS 0.01
CVE-2017-16007
MEDIUM
node-jose < 0.9.3 - Exposure of Sensitive Information via Invalid Curve Attack
Jun 04, 2018
CVSS 5.9
EPSS 0.01
CVE-2017-16006
MEDIUM
remarkable < 1.6.2 - Cross-Site Scripting via Data URI Handling
Jun 04, 2018
CVSS 6.1
EPSS 0.01
CVE-2017-16005
HIGH
joyent/http-signature <=0.9.11 - Header Forgery via Unsigned Header Names
Jun 04, 2018
CVSS 7.5
EPSS 0.01
CVE-2017-0931
MEDIUM
html-janitor < 2.0.3 - Cross-Site Scripting via clean() Function
Jun 04, 2018
CVSS 6.1
EPSS 0.01
CVE-2017-0930
MEDIUM
augustine - Path Traversal via URL Parameter
Jun 04, 2018
CVSS 6.5
EPSS 0.01
CVE-2017-0928
MEDIUM
html-janitor - Sanitization Bypass via _sanitized Variable
Jun 04, 2018
CVSS 6.1
EPSS 0.01
CVE-2017-16153
HIGH
gaoxuyan - Path Traversal via URL Parameter
May 29, 2018
CVSS 7.5
EPSS 0.02
CVE-2017-16062
HIGH
node-tkinter - Exposure of Sensitive Information via Environment Variable Hijacking
May 29, 2018
CVSS 7.5
EPSS 0.01
CVE-2017-16061
HIGH
tkinter - Exposure of Sensitive Information via Malicious Environment Variable Hijacking
May 29, 2018
CVSS 7.5
EPSS 0.01
CVE-2017-16047
HIGH
mysqljs - Exposure of Sensitive Information via Malicious Environment Variable Hijacking
May 29, 2018
CVSS 7.5
EPSS 0.01
CVE-2017-16010
MEDIUM
i18next 2.0.0-3.4.3 - Cross-Site Scripting via Interpolation Options
May 29, 2018
CVSS 6.1
EPSS 0.01
CVE-2017-16003
HIGH
windows-build-tools < 1.0.0 - Missing Encryption of Sensitive Data via HTTP Resource Download
May 29, 2018
CVSS 8.1
EPSS 0.02
CVE-2017-18214
HIGH
moment < 2.19.3 - Regular Expression Denial of Service via Crafted Date String
Mar 04, 2018
CVSS 7.5
EPSS 0.04
CVE-2017-18197
CRITICAL
mxGraph < 3.7.6 - XML External Entity Injection via SAXParserFactory
Feb 24, 2018
CVSS 9.8
EPSS 0.03
Products
openclaw 433
n8n 110
parse-server 98
flowise 67
directus 55
nocodb 54
electron 49
next 47
vm2 41
hono 38
axios 33
undici 30
pnpm 25
ghost 22
vite 21
astro 19
tar 19
tinymce 18
protobufjs 16
ckeditor4 15
fuxa-server 15
jspdf 15
joplin 14
liquidjs 14
nodebb 14
sequelize 14
angular 13
flowise-components 13
react-router 13
signalk-server 13
Quick Filters