Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • H
Prototype Pollution
content-security-policy-parser<0.5.0npm13 Aug 2025
  • C
Arbitrary Command Injection
@cdklabs/cdk-proserve-lib<0.5.1npm13 Aug 2025
  • H
Improper Authentication
@fedify/fedify<1.3.20>=1.4.0-dev.585 <1.4.13>=1.5.0-dev.636 <1.5.5>=1.6.0-dev.754 <1.6.8>=1.7.0-pr.251.885 <1.7.9>=1.8.0-dev.909 <1.8.5npm10 Aug 2025
  • H
Information Exposure
@workos-inc/authkit-remix<0.15.0npm10 Aug 2025
  • H
Information Exposure
@workos-inc/authkit-react-router<0.7.0npm10 Aug 2025
  • M
Regular Expression Denial of Service (ReDoS)
@oakserver/oak*npm10 Aug 2025
  • H
Arbitrary Command Injection
mcp-package-docs<0.1.28npm8 Aug 2025
  • C
Insufficient Entropy
thinbus-srp<2.0.1npm8 Aug 2025
  • M
Open Redirect
@astrojs/internal-helpers>=0.6.1 <0.7.1npm8 Aug 2025
  • H
Use After Free
electron<37.2.6npm7 Aug 2025
  • H
Directory Traversal
@anthropic-ai/claude-code<0.2.113npm7 Aug 2025
  • H
Prototype Pollution
linkify-react<4.3.2npm7 Aug 2025
  • H
Prototype Pollution
linkifyjs<4.3.2npm7 Aug 2025
  • M
Insertion of Sensitive Information into Log File
kuzu<0.8.2npm7 Aug 2025
  • M
Allocation of Resources Without Limits or Throttling
bento4*npm7 Aug 2025
  • H
Command Injection
@anthropic-ai/claude-code<1.0.20npm7 Aug 2025
  • M
Symlink Attack
tmp<0.2.4npm7 Aug 2025
  • M
Regular Expression Denial of Service (ReDoS)
@actions/glob*npm6 Aug 2025
  • L
Directory Traversal
vvvebjs*npm6 Aug 2025
  • M
Directory Traversal
ipx<1.3.2>=2.0.0-0 <2.1.1>=3.0.0 <3.1.1npm6 Aug 2025
  • H
Prototype Pollution
js-toml<1.0.2npm6 Aug 2025
  • C
Malicious Package
epic-games-nav-share*npm4 Aug 2025
  • C
Malicious Package
epic-fortnite-shared-values*npm4 Aug 2025
  • H
Prototype Pollution
@nyariv/sandboxjs<0.8.24npm4 Aug 2025
  • C
Arbitrary Command Injection
@nestjs/devtools-integration<0.2.1npm3 Aug 2025
  • C
Improper Neutralization of Input Used for LLM Prompting
@modelcontextprotocol/server-slack*npm1 Aug 2025
  • C
Malicious Package
dhei-0731-pkg2*npm1 Aug 2025
  • M
Server-side Request Forgery (SSRF)
webfinger.js<2.8.1npm1 Aug 2025
  • H
Improper Authorization
@finos/git-proxy<1.19.2npm31 Jul 2025
  • H
Information Exposure
@finos/git-proxy<1.19.2npm31 Jul 2025