Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • C
Embedded Malicious Code
@pkgr/core>0.2.7 <0.2.9npm22 Jul 2025
  • C
Embedded Malicious Code
synckit>0.11.8 <0.11.10npm22 Jul 2025
  • C
Embedded Malicious Code
eslint-plugin-prettier>4.2.1 <4.2.4npm22 Jul 2025
  • C
Embedded Malicious Code
eslint-config-prettier>8.10.0 <8.10.2>9.1.0 <9.1.2>10.1.5 <10.1.8npm22 Jul 2025
  • M
Cross-site Scripting (XSS)
@pdfme/common>=5.2.0 <5.4.1npm21 Jul 2025
  • C
Malicious Package
evmlogger*npm21 Jul 2025
  • C
Malicious Package
vite-lightsparse*npm21 Jul 2025
  • C
Malicious Package
websyncer*npm21 Jul 2025
  • C
Malicious Package
okta-core-component*npm21 Jul 2025
  • C
Malicious Package
config-log*npm21 Jul 2025
  • C
Malicious Package
rc-logger*npm21 Jul 2025
  • C
Malicious Package
vite-postcss-helper*npm21 Jul 2025
  • C
Malicious Package
grayavatar*npm21 Jul 2025
  • C
Malicious Package
mooduliop*npm21 Jul 2025
  • H
Denial of Service (DoS)
string-math>=0.0.0npm21 Jul 2025
  • M
Cross-site Scripting (XSS)
@nuxtjs/mdc<0.17.2npm21 Jul 2025
  • C
Command Injection
@sunwood-ai-labs/github-kanban-mcp-server>=0.0.0npm20 Jul 2025
  • L
Regular Expression Denial of Service (ReDoS)
@eslint/plugin-kit<0.3.4npm20 Jul 2025
  • C
Predictable Value Range from Previous Values
form-data<2.5.4>=3.0.0 <3.0.4>=4.0.0 <4.0.4npm20 Jul 2025
  • C
Improper Verification of Cryptographic Signature
tiny-secp256k1<1.1.7npm18 Jul 2025
  • C
Insufficiently Protected Credentials
tiny-secp256k1<1.1.7npm18 Jul 2025
  • C
Malicious Package
public-tools-and-demos*npm18 Jul 2025
  • C
Malicious Package
@jssrv/template*npm18 Jul 2025
  • C
Malicious Package
@lensapp/eslint-config*npm18 Jul 2025
  • C
Malicious Package
jenkins-for-jira-ui*npm18 Jul 2025
  • C
Malicious Package
eth-multisig-v4*npm18 Jul 2025
  • C
Malicious Package
eth-validator*npm18 Jul 2025
  • C
Malicious Package
glean-mcp-server*npm18 Jul 2025
  • C
Malicious Package
dex-sample-app*npm18 Jul 2025
  • C
Malicious Package
rtp-rapyd*npm18 Jul 2025