Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • C
Malicious Package
sd-pay-ts*npm12 Dec 2025
  • C
Malicious Package
sdbao-content-report*npm12 Dec 2025
  • C
Malicious Package
pp-js-lib*npm12 Dec 2025
  • C
Malicious Package
cfruitmaliciousxmlparser*npm12 Dec 2025
  • C
Malicious Package
bfruitmaliciousxmlparser*npm12 Dec 2025
  • C
Malicious Package
gfruitmaliciousxmlparser*npm12 Dec 2025
  • C
Malicious Package
dfruitmaliciousxmlparser*npm12 Dec 2025
  • C
Malicious Package
browser-client-neptune*npm12 Dec 2025
  • C
Malicious Package
efruitmaliciousxmlparser*npm12 Dec 2025
  • C
Malicious Package
afruitmaliciousxmlparser*npm12 Dec 2025
  • C
Malicious Package
fruit-malicious-xml-parser*npm12 Dec 2025
  • C
Malicious Package
hfruitmaliciousxmlparser*npm12 Dec 2025
  • C
Malicious Package
ffruitmaliciousxmlparser*npm12 Dec 2025
  • C
Malicious Package
@cheqplease/structured-logger*npm12 Dec 2025
  • M
Use of Non-Canonical URL Paths for Authorization Decisions
astro<5.16.3npm12 Dec 2025
  • M
Incorrect Authorization
@auth0/nextjs-auth0>=4.11.0 <4.11.2>=4.12.0 <4.12.1npm11 Dec 2025
  • L
Incomplete List of Disallowed Inputs
@auth0/nextjs-auth0>=4.9.0 <4.13.0npm11 Dec 2025
  • H
Improper Handling of Case Sensitivity
formio<3.5.7-rc.1>=4.0.0-rc.1 <4.4.3-rc.1npm11 Dec 2025
  • H
Inadequate Encryption Strength
altcha>=0.8.0npm10 Dec 2025
  • C
Server-side Request Forgery (SSRF)
mcp-fetch-server*npm10 Dec 2025
  • M
Cross-site Scripting (XSS)
qwc2-lts*npm10 Dec 2025
  • M
Cross-site Scripting (XSS)
qwc2<2025.8.14npm10 Dec 2025
  • M
Improper Protection for Out of Bounds Signal Level Alerts
@nocobase/auth<1.9.0-beta.18>=1.9.0 <1.9.22>=2.0.0-alpha.2 <2.0.0-alpha.52npm10 Dec 2025
  • H
Arbitrary Code Injection
elysia<1.4.17npm10 Dec 2025
  • C
Prototype Pollution
elysia>=1.4.0 <1.4.17npm10 Dec 2025
  • C
Malicious Package
non-modular-buildable*npm10 Dec 2025
  • C
Malicious Package
near-fast-auth-signer*npm10 Dec 2025
  • C
Malicious Package
express-my-error-handler*npm10 Dec 2025
  • C
Malicious Package
native-component-list*npm10 Dec 2025
  • C
Malicious Package
real-time-tweet-streamer*npm10 Dec 2025