npm

3,969 tracked vulnerabilities.

CVE-2025-55173 MEDIUM
Next.js <14.2.31, 15.0.0-15.4.4 - Code Injection
Aug 29, 2025
CVSS 4.3
EPSS 0.01
CVE-2025-4644 MEDIUM
Payload CMS < 3.44.0 - Session Fixation via SQLite Adapter Identifier Reuse
Aug 29, 2025
EPSS 0.00
CVE-2025-4643 MEDIUM
Payload CMS < 3.44.0 - Insufficient Session Expiration via JWT Reuse
Aug 29, 2025
EPSS 0.00
CVE-2025-50979 HIGH
NodeBB v4.3.0 - Unauthenticated SQL Injection via Search-Categories API Endpoint
Aug 27, 2025
CVSS 8.6
EPSS 0.00
CVE-2025-57820 HIGH
devalue < 5.3.2 - Prototype Pollution via __proto__ Property Parsing
Aug 26, 2025
EPSS 0.00
CVE-2025-57810 HIGH
jspdf < 3.0.2 - Denial of Service via addImage Method
Aug 26, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-57814 MEDIUM
request-filtering-agent < 2.0.0 - Server-Side Request Forgery via HTTPS 127.0.0.1 Bypass
Aug 25, 2025
EPSS 0.00
CVE-2025-43761 MEDIUM
Liferay Portal 7.4.0-7.4.3.131 & DXP 2024.Q1.1-2024.Q1.12 - Reflected XSS via CKEditor
Aug 22, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-57753 MEDIUM
vite-plugin-static-copy 0.4.3-2.3.1 and 3.0.0-3.1.1 - Path Traversal
Aug 21, 2025
EPSS 0.00
CVE-2025-9288 CRITICAL
sha.js < 2.4.11 - Input Data Manipulation via Improper Input Validation
Aug 20, 2025
CVSS 9.1
EPSS 0.00
CVE-2025-9287 CRITICAL
cipher-base <1.0.4 - Info Disclosure
Aug 20, 2025
CVSS 9.1
EPSS 0.00
CVE-2025-57749 MEDIUM
n8n < 1.106.0 - Symlink Traversal in Read/Write File Node
Aug 20, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-55746 CRITICAL
Directus 10.8.0-11.9.2 - Unauthenticated Arbitrary File Upload via File Update Mechanism
Aug 20, 2025
CVSS 9.3
EPSS 0.00
CVE-2025-55303 MEDIUM NUCLEI
Astro < 4.16.18 and 5.0.0-alpha.0-5.13.2 - Unauthorized Image Serving via Protocol-Relative URL Bypass
Aug 19, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-55294 CRITICAL
screenshot-desktop <1.15.2 - Command Injection
Aug 19, 2025
CVSS 9.8
EPSS 0.01
CVE-2025-54881 MEDIUM
mermaid 10.9.0-rc.1-11.9.0 - Cross-Site Scripting via Sequence Diagram Label Input
Aug 19, 2025
EPSS 0.00
CVE-2025-54880 MEDIUM
mermaid 11.1.0-11.9.0 - Cross-Site Scripting via Architecture Diagram Icon Input
Aug 19, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-52478 HIGH
n8n 1.77.0-1.98.2 - Authenticated Stored Cross-Site Scripting via Form Trigger Node HTML Injection
Aug 19, 2025
CVSS 8.7
EPSS 0.00
CVE-2025-9096 LOW
ExpressGateway express-gateway <= 1.16.10 - Cross-Site Scripting in REST Endpoint
Aug 18, 2025
CVSS 3.5
EPSS 0.00
CVE-2025-9095 LOW
ExpressGateway express-gateway <= 1.16.10 - Cross-Site Scripting in REST Endpoint
Aug 17, 2025
CVSS 3.5
EPSS 0.00
CVE-2025-8943 CRITICAL NUCLEI
Flowise < 3.0.1 - Unauthenticated Remote Code Execution via Custom MCPs Feature
Aug 14, 2025
CVSS 9.8
EPSS 0.88
CVE-2025-55346 CRITICAL
flowise - Remote Code Execution via Dynamic Function Constructor
Aug 14, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-55164 HIGH
content-security-policy-parser <0.6.0 - Prototype Pollution
Aug 12, 2025
EPSS 0.00
CVE-2025-54793 MEDIUM NUCLEI
Astro 5.2.0-5.12.7 - Open Redirect via Trailing Slash Logic
Aug 08, 2025
CVSS 6.1
EPSS 0.01
CVE-2025-54885 MEDIUM
Thinbus Javascript Secure Remote Password <2.0.0 - Info Disclosure
Aug 07, 2025
EPSS 0.00