npm

4,315 tracked vulnerabilities.

CVE-2016-6799 HIGH
Apache Cordova Android < 5.2.2 - Sensitive Information Exposure via Log File Insertion
May 09, 2017
CVSS 7.5
EPSS 0.03
CVE-2016-5682 MEDIUM
Swagger-UI < 2.2.1 - Stored Cross-Site Scripting via Default Field in Definitions Section
Apr 10, 2017
CVSS 6.1
EPSS 0.01
CVE-2016-7103 MEDIUM
jQuery UI < 1.12.0 - Cross-Site Scripting via Dialog closeText Parameter
Mar 15, 2017
CVSS 6.1
EPSS 0.23
CVE-2016-4947 MEDIUM
Cloudera HUE < 3.9.0 - User Account Enumeration via Autocomplete API
Mar 07, 2017
CVSS 5.3
EPSS 0.01
CVE-2016-4055 MEDIUM
moment < 2.11.2 - Denial of Service via Regular Expression in Duration Function
Jan 23, 2017
CVSS 6.5
EPSS 0.10
CVE-2016-7191 HIGH
Microsoft Azure Active Directory Passport 1.x < 1.4.6 and 2.x < 2.0.1 - Authentication Bypass via Token Validation Issue
Sep 28, 2016
CVSS 8.1
EPSS 0.29
CVE-2016-3956 HIGH
npm <2.15.1,3.x <3.8.3 - Info Disclosure
Jul 02, 2016
CVSS 7.5
EPSS 0.07
CVE-2016-4567 MEDIUM
MediaElement.js < 2.21.0 - Cross-Site Scripting via FlashMediaElement.as jsinitfunction Parameter
May 22, 2016
CVSS 6.1
EPSS 0.06
CVE-2016-1202 HIGH
Atom Electron <0.33.5 - Privilege Escalation
Apr 25, 2016
CVSS 7.8
EPSS 0.00
CVE-2016-2515 HIGH
hawk < 3.1.3 and 4.x < 4.1.1 - Denial of Service via Long Header or URI
Apr 13, 2016
CVSS 7.5
EPSS 0.03
CVE-2016-2537 HIGH
is-my-json-valid < 2.12.4 - Denial of Service via Crafted String
Feb 23, 2016
CVSS 7.5
EPSS 0.02
CVE-2015-20110 HIGH
JHipster < 2.23.0 - Timing Attack via Token Validation
Oct 31, 2023
CVSS 7.5
EPSS 0.01
CVE-2015-10005 LOW
markdown-it <3.0.0 - Info Disclosure
Dec 27, 2022
CVSS 3.5
EPSS 0.01
CVE-2015-9545 HIGH
xdLocalStorage < 2.0.5 - Unauthenticated Data Manipulation via Missing Origin Validation
Apr 07, 2020
CVSS 7.1
EPSS 0.01
CVE-2015-9544 HIGH
xdLocalStorage < 2.0.5 - Unauthenticated Data Manipulation via Missing Origin Validation
Apr 07, 2020
CVSS 7.1
EPSS 0.01
CVE-2015-8851 HIGH
node-uuid < 1.4.4 - Insufficient Entropy in GUID Generation
Jan 30, 2020
CVSS 7.5
EPSS 0.02
CVE-2015-9286 MEDIUM
NodeBB < 0.7.3 - Cross-Site Scripting in Controllers.outgoing
Apr 30, 2019
CVSS 6.1
EPSS 0.01
CVE-2015-9239 HIGH
ansi2html - Regular Expression Denial of Service via User Input
May 31, 2018
CVSS 7.5
EPSS 0.01
CVE-2015-9238 MEDIUM
secure-compare < 3.0.1 - Incorrect String Comparison
May 31, 2018
CVSS 5.3
EPSS 0.01
CVE-2015-9236 MEDIUM
hapi < 11.0.0 - Improper Access Control via CORS Header Inconsistency
May 31, 2018
CVSS 5.3
EPSS 0.02
CVE-2015-9244 CRITICAL
mysqljs/mysql < 2.0.0-alpha8 - SQL Injection via Unescaped Object Keys
May 29, 2018
CVSS 9.8
EPSS 0.02
CVE-2015-9243 MEDIUM
hapi < 11.1.4 - Improper Access Control via CORS Configuration Override
May 29, 2018
CVSS 5.9
EPSS 0.01
CVE-2015-9242 HIGH
ecstatic < 1.4.0 - Denial of Service via If-Modified-Since Header
May 29, 2018
CVSS 7.5
EPSS 0.02
CVE-2015-9241 HIGH
hapi < 11.1.3 - Denial of Service via If-Modified-Since or Last-Modified Header
May 29, 2018
CVSS 7.5
EPSS 0.02
CVE-2015-9240 HIGH
keystonejs keystone < 0.3.16 - Incomplete Email Address Matching in Sign-In
May 29, 2018
CVSS 7.5
EPSS 0.01