npm
4,315 tracked vulnerabilities.
CVE-2016-6799
HIGH
Apache Cordova Android < 5.2.2 - Sensitive Information Exposure via Log File Insertion
May 09, 2017
CVSS 7.5
EPSS 0.03
CVE-2016-5682
MEDIUM
Swagger-UI < 2.2.1 - Stored Cross-Site Scripting via Default Field in Definitions Section
Apr 10, 2017
CVSS 6.1
EPSS 0.01
CVE-2016-7103
MEDIUM
jQuery UI < 1.12.0 - Cross-Site Scripting via Dialog closeText Parameter
Mar 15, 2017
CVSS 6.1
EPSS 0.23
CVE-2016-4947
MEDIUM
Cloudera HUE < 3.9.0 - User Account Enumeration via Autocomplete API
Mar 07, 2017
CVSS 5.3
EPSS 0.01
CVE-2016-4055
MEDIUM
moment < 2.11.2 - Denial of Service via Regular Expression in Duration Function
Jan 23, 2017
CVSS 6.5
EPSS 0.10
CVE-2016-7191
HIGH
Microsoft Azure Active Directory Passport 1.x < 1.4.6 and 2.x < 2.0.1 - Authentication Bypass via Token Validation Issue
Sep 28, 2016
CVSS 8.1
EPSS 0.29
CVE-2016-3956
HIGH
npm <2.15.1,3.x <3.8.3 - Info Disclosure
Jul 02, 2016
CVSS 7.5
EPSS 0.07
CVE-2016-4567
MEDIUM
MediaElement.js < 2.21.0 - Cross-Site Scripting via FlashMediaElement.as jsinitfunction Parameter
May 22, 2016
CVSS 6.1
EPSS 0.06
CVE-2016-1202
HIGH
Atom Electron <0.33.5 - Privilege Escalation
Apr 25, 2016
CVSS 7.8
EPSS 0.00
CVE-2016-2515
HIGH
hawk < 3.1.3 and 4.x < 4.1.1 - Denial of Service via Long Header or URI
Apr 13, 2016
CVSS 7.5
EPSS 0.03
CVE-2016-2537
HIGH
is-my-json-valid < 2.12.4 - Denial of Service via Crafted String
Feb 23, 2016
CVSS 7.5
EPSS 0.02
CVE-2015-20110
HIGH
JHipster < 2.23.0 - Timing Attack via Token Validation
Oct 31, 2023
CVSS 7.5
EPSS 0.01
CVE-2015-10005
LOW
markdown-it <3.0.0 - Info Disclosure
Dec 27, 2022
CVSS 3.5
EPSS 0.01
CVE-2015-9545
HIGH
xdLocalStorage < 2.0.5 - Unauthenticated Data Manipulation via Missing Origin Validation
Apr 07, 2020
CVSS 7.1
EPSS 0.01
CVE-2015-9544
HIGH
xdLocalStorage < 2.0.5 - Unauthenticated Data Manipulation via Missing Origin Validation
Apr 07, 2020
CVSS 7.1
EPSS 0.01
CVE-2015-8851
HIGH
node-uuid < 1.4.4 - Insufficient Entropy in GUID Generation
Jan 30, 2020
CVSS 7.5
EPSS 0.02
CVE-2015-9286
MEDIUM
NodeBB < 0.7.3 - Cross-Site Scripting in Controllers.outgoing
Apr 30, 2019
CVSS 6.1
EPSS 0.01
CVE-2015-9239
HIGH
ansi2html - Regular Expression Denial of Service via User Input
May 31, 2018
CVSS 7.5
EPSS 0.01
CVE-2015-9238
MEDIUM
secure-compare < 3.0.1 - Incorrect String Comparison
May 31, 2018
CVSS 5.3
EPSS 0.01
CVE-2015-9236
MEDIUM
hapi < 11.0.0 - Improper Access Control via CORS Header Inconsistency
May 31, 2018
CVSS 5.3
EPSS 0.02
CVE-2015-9244
CRITICAL
mysqljs/mysql < 2.0.0-alpha8 - SQL Injection via Unescaped Object Keys
May 29, 2018
CVSS 9.8
EPSS 0.02
CVE-2015-9243
MEDIUM
hapi < 11.1.4 - Improper Access Control via CORS Configuration Override
May 29, 2018
CVSS 5.9
EPSS 0.01
CVE-2015-9242
HIGH
ecstatic < 1.4.0 - Denial of Service via If-Modified-Since Header
May 29, 2018
CVSS 7.5
EPSS 0.02
CVE-2015-9241
HIGH
hapi < 11.1.3 - Denial of Service via If-Modified-Since or Last-Modified Header
May 29, 2018
CVSS 7.5
EPSS 0.02
CVE-2015-9240
HIGH
keystonejs keystone < 0.3.16 - Incomplete Email Address Matching in Sign-In
May 29, 2018
CVSS 7.5
EPSS 0.01
Products
openclaw 433
n8n 110
parse-server 98
flowise 67
directus 55
nocodb 54
electron 49
next 47
vm2 41
hono 38
axios 33
undici 30
pnpm 25
ghost 22
vite 21
astro 19
tar 19
tinymce 18
protobufjs 16
ckeditor4 15
fuxa-server 15
jspdf 15
joplin 14
liquidjs 14
nodebb 14
sequelize 14
angular 13
flowise-components 13
react-router 13
signalk-server 13
Quick Filters