npm

3,969 tracked vulnerabilities.

CVE-2024-51091 MEDIUM
seajs 2.2.3 - Cross-Site Scripting via seajs Package
Mar 03, 2025
CVSS 5.4
EPSS 0.00
CVE-2024-53388 HIGH
mavo v0.3.2 - DOM Clobbering
Mar 03, 2025
CVSS 8.8
EPSS 0.00
CVE-2024-53386 MEDIUM
stage.js < 0.8.10 - DOM Clobbering and Cross-Site Scripting via document.currentScript Shadowing
Mar 03, 2025
CVSS 4.9
EPSS 0.00
CVE-2024-53382 MEDIUM
PrismJS < 1.29.0 - DOM Clobbering and Cross-Site Scripting via document.currentScript Shadowing
Mar 03, 2025
CVSS 4.9
EPSS 0.00
CVE-2024-11831 MEDIUM
serialize-javascript >=6.0.0 <6.0.2 - Cross-Site Scripting via Unsanitized JavaScript Object Input
Feb 10, 2025
CVSS 5.4
EPSS 0.01
CVE-2024-57086 HIGH
node-opcua-alarm-condition <2.134.0 - DoS
Feb 05, 2025
CVSS 7.5
EPSS 0.00
CVE-2024-57080 HIGH
vxe-table 4.8.10 - Denial of Service via Prototype Pollution in lib.install
Feb 05, 2025
CVSS 7.5
EPSS 0.00
CVE-2024-57077 CRITICAL
utils-extend 1.0.8 - Prototype Pollution
Feb 05, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-57075 HIGH
eazy-logger < 4.1.0 - Denial of Service via Prototype Pollution
Feb 05, 2025
CVSS 7.5
EPSS 0.00
CVE-2024-57072 HIGH
module-from-string 3.3.1 - Denial of Service via Prototype Pollution
Feb 05, 2025
CVSS 7.5
EPSS 0.00
CVE-2024-53615 MEDIUM
files.photo.gallery 0.3.0-0.11.0 - Remote Code Execution via Video Thumbnail Rendering
Jan 30, 2025
CVSS 6.5
EPSS 0.21
CVE-2024-57041 MEDIUM
NodeBB < 3.11.1 - Stored Cross-Site Scripting in Profile About Me Section
Jan 24, 2025
CVSS 4.6
EPSS 0.07
CVE-2024-57556 MEDIUM
nbubna/store < 2.14.2 - Cross-Site Scripting via store.deep.js Component
Jan 23, 2025
CVSS 6.1
EPSS 0.01
CVE-2024-48460 MEDIUM
tabby-ssh < 1.0.214 - Improper Certificate Validation
Jan 16, 2025
CVSS 4.3
EPSS 0.00
CVE-2024-36751 MEDIUM
parse-uri - Regular Expression Denial of Service via Crafted URL
Jan 15, 2025
CVSS 6.5
EPSS 0.00
CVE-2024-56332 MEDIUM
Next.js 13.0.0-13.5.7 - Denial of Service via Server Actions
Jan 03, 2025
CVSS 5.3
EPSS 0.00
CVE-2024-56198 CRITICAL
path-sanitizer < 3.1.0 - Path Traversal via .=%5c Bypass
Dec 31, 2024
EPSS 0.01
CVE-2024-56734 MEDIUM
better-auth < 1.1.6 - Open Redirect via Email Verification Callback URL Parameter
Dec 30, 2024
CVSS 6.1
EPSS 0.00
CVE-2024-56334 HIGH
systeminformation < 5.23.7 - OS Command Injection via SSID Parameter in getWindowsIEEE8021x
Dec 20, 2024
CVSS 7.8
EPSS 0.05
CVE-2024-56331 MEDIUM NUCLEI
Uptime Kuma 1.23.0-1.23.15 and 2.0.0-beta.0 - Authenticated Path Traversal via Real-Browser URL Input
Dec 20, 2024
CVSS 6.8
EPSS 0.59
CVE-2024-56159 MEDIUM NUCLEI
Astro < 4.16.18 and 5.0.0-alpha.0-5.0.7 - Unauthenticated Sensitive Source Code Exposure via Sourcemap Files
Dec 19, 2024
CVSS 5.3
EPSS 0.11
CVE-2024-56140 MEDIUM
Astro < 4.16.17 - Cross-Site Request Forgery Bypass via Semicolon-Delimited Content-Type
Dec 18, 2024
CVSS 5.9
EPSS 0.00
CVE-2024-51479 HIGH
Next.js 9.5.5-14.2.14 - Improper Authorization via Pathname-Based Middleware Bypass
Dec 17, 2024
CVSS 7.5
EPSS 0.79
CVE-2024-55500 HIGH
Avenwu Whistle <= 2.9.90 - Cross-Site Request Forgery
Dec 10, 2024
CVSS 8.8
EPSS 0.01
CVE-2024-53866 CRITICAL
pnpm < 9.15.0 - Untrusted Search Path via Global Cache Override Leak
Dec 10, 2024
CVSS 9.8
EPSS 0.01