npm
4,315 tracked vulnerabilities.
CVE-2014-10068
HIGH
hapi/inert < 1.1.1 - Path Traversal via Hidden Directory Handling
May 29, 2018
CVSS 7.5
EPSS 0.02
CVE-2014-10067
MEDIUM
paypal-ipn < 3.0.0 - Improper Authentication via test_ipn Parameter
May 29, 2018
CVSS 5.9
EPSS 0.01
CVE-2014-3744
HIGH
NUCLEI
st module for Node.js < 0.2.5 - Path Traversal via Encoded Dot-Dot Sequences
Oct 23, 2017
CVSS 7.5
EPSS 0.34
CVE-2014-3741
CRITICAL
node-printer < 0.0.1 - OS Command Injection via lpr Command
Oct 23, 2017
CVSS 9.8
EPSS 0.04
CVE-2014-6393
MEDIUM
Express < 3.11 and 4.x < 4.5 - Cross-Site Scripting via Missing Charset in Content-Type Header
Aug 09, 2017
CVSS 6.1
EPSS 0.01
CVE-2014-9772
MEDIUM
Validator <2.0.0 - XSS
Jan 23, 2017
CVSS 6.1
EPSS 0.03
CVE-2014-9682
dns-sync <0.1.1 - Command Injection
Feb 28, 2015
EPSS 0.03
CVE-2014-7193
Crumb plugin <3.0.0 - Info Disclosure
Dec 25, 2014
EPSS 0.01
CVE-2014-7192
syntax-error <1.1.1 - Code Injection
Dec 11, 2014
EPSS 0.13
CVE-2014-7191
Node.js qs module < 1.0.0 - Denial of Service via Sparse Array Index
Oct 19, 2014
EPSS 0.08
CVE-2014-7205
hapi Server Framework - Code Injection
Oct 08, 2014
EPSS 0.79
CVE-2014-6394
visionmedia send <0.8.4 - Info Disclosure
Oct 08, 2014
EPSS 0.04
CVE-2014-4671
Adobe Flash Player <14.0.0.145 - CSRF
Jul 09, 2014
EPSS 0.23
CVE-2014-3742
hapi server framework 2.0.x-2.1.x - Denial of Service via File Descriptor Consumption
May 16, 2014
EPSS 0.02
CVE-2013-7381
CRITICAL
libnotify < 1.0.4 - Remote Code Execution via libnotify.notify
Feb 12, 2020
CVSS 9.8
EPSS 0.03
CVE-2013-7378
CRITICAL
hubot_scripts < 2.4.4 - Remote Code Execution via Email Script
Feb 12, 2020
CVSS 9.8
EPSS 0.03
CVE-2013-7371
MEDIUM
Sencha Connect < 2.8.2 - Cross-Site Scripting in Middleware
Dec 11, 2019
CVSS 6.1
EPSS 0.01
CVE-2013-7370
MEDIUM
node-connect <2.8.1 - XSS
Dec 11, 2019
CVSS 6.1
EPSS 0.01
CVE-2013-7377
HIGH
codem-transcode < 0.5.0 - Remote Code Execution via /probe POST Request
Oct 23, 2017
CVSS 8.1
EPSS 0.02
CVE-2013-7454
MEDIUM
Node.js <1.1.0 - XSS
Jan 23, 2017
CVSS 6.1
EPSS 0.02
CVE-2013-7453
MEDIUM
Validator <1.1.0 - XSS
Jan 23, 2017
CVSS 6.1
EPSS 0.02
CVE-2013-7452
MEDIUM
Validator <1.1.0 - XSS
Jan 23, 2017
CVSS 6.1
EPSS 0.02
CVE-2013-7451
MEDIUM
Validator <1.1.0 - XSS
Jan 23, 2017
CVSS 6.1
EPSS 0.02
CVE-2013-7379
ucdok/tomato < 0.0.5 and npm/tomato < 0.0.6 - Improper Authentication via Partial Access Key Match
May 16, 2014
EPSS 0.02
CVE-2013-4116
Node Packaged Modules < 1.3.3 - Arbitrary File Overwrite via Symlink Attack on Temporary Files
Apr 22, 2014
EPSS 0.00
Products
openclaw 433
n8n 110
parse-server 98
flowise 67
directus 55
nocodb 54
electron 49
next 47
vm2 41
hono 38
axios 33
undici 30
pnpm 25
ghost 22
vite 21
astro 19
tar 19
tinymce 18
protobufjs 16
ckeditor4 15
fuxa-server 15
jspdf 15
joplin 14
liquidjs 14
nodebb 14
sequelize 14
angular 13
flowise-components 13
react-router 13
signalk-server 13
Quick Filters