VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

CVE-2026-71439Medium
1mo ago

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.6.0 until 11.16.1, Mermaid Radar Diagrams allow arbitrary large values for the ticks parameter, which can cause high …

▾ Sunlitmermaid · mermaidEPSS 0.53%via NVD
CVE-2026-48054High· 8.8
1mo ago

OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts

OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test file (`test/test.ts`) by interpolating user-supplied `op…

▾ TwilightOpenZeppelin · contracts-wizardEPSS 0.64%via NVD
CVE-2026-71314High· 7.5
1mo ago

Nuxt is an open-source web development framework for Vue.js

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island v-for prop, including vforToArray and , to trigger unbounded SSR memory allocation until…

▾ Twilightnuxt · nuxtEPSS 0.66%via NVD
CVE-2026-71315High· 8.2
1mo ago

Nuxt is an open-source web development framework for Vue.js

Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to match case-folded lookups when router.options.sensitive is false and drop appMiddleware authorizatio…

▾ Twilightnuxt · nuxtEPSS 0.47%via NVD
CVE-2026-71316High· 7.5
1mo ago

Nuxt is an open-source web development framework for Vue.js

Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for /<page>/_payload.json can be returned before route middleware and page guards because import.meta.prerender is no…

▾ Twilightnuxt · nuxtEPSS 0.51%via NVD
CVE-2026-71318Medium· 4.8
1mo ago

Nuxt is an open-source web development framework for Vue.js

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply a top-level `as` prop to the /__nuxt_island/ endpoint and drive dynamic component resolution through <component :is>,…

▾ Sunlitnuxt · nuxtEPSS 0.32%via NVD
CVE-2026-71319Critical· 9.6
1mo ago

Nuxt is an open-source web development framework for Vue.js

Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the…

▾ Midnightnuxt · @nuxt/devtoolsEPSS 0.63%via NVD
CVE-2026-71320High· 8.1
1mo ago

Nuxt is an open-source web development framework for Vue.js

Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nuxt_island/ props into a dynamic component when `vue.runtimeCompiler: true` is enabled, ca…

▾ Twilightnuxt · nuxtEPSS 0.71%via NVD
CVE-2026-71321High· 7.5
1mo ago

Nuxt is an open-source web development framework for Vue.js

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer endpoint `/__nuxt_island/...` decodes and hashes attacker-controlled JSON body input with destr and ohash befor…

▾ Twilightnuxt · nuxtEPSS 0.74%via NVD
CVE-2026-70612Medium· 5.4
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, requests to open external protocol URLs from web content did not take iframe sand…

▾ Sunlitelectron · electronEPSS 0.44%via NVD
CVE-2026-70608High· 7.2
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sandboxed iframe without the allow-popups keyword could still open a new window or trigger s…

▾ Twilightelectron · electronEPSS 0.45%via NVD
CVE-2026-70609Medium· 5.7
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, the mode option of webContents.openDevTools() was not sanitized before use by the…

▾ Sunlitelectron · electronEPSS 0.55%via NVD
CVE-2026-70610Medium· 5.4
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4, objects copied across the contextBridge boundary from untrusted content could car…

▾ Sunlitelectron · electronEPSS 0.58%via NVD
CVE-2026-70611Medium· 6.9
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-beta.3, the DevTools reveal in file manager action could launch the target file rather th…

▾ Sunlitelectron · electronEPSS 0.18%via NVD
CVE-2026-70603Medium· 6.0
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1, shell.openPath() did not reject paths containing embedded null bytes. Apps that p…

▾ Sunlitelectron · electronEPSS 0.14%via NVD
CVE-2026-70602Medium· 6.6
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, extension tab and scripting APIs were not scoped to the extension's own session. …

▾ Sunlitelectron · electronEPSS 0.26%via NVD
CVE-2026-70604High· 7.4
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0, a custom scheme registered with supportFetchAPI: true but without corsEnabled: true was…

▾ Twilightelectron · electronEPSS 0.35%via NVD
CVE-2026-70605Medium· 5.9
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, when following HTTP redirects, net.fetch() and net.request() did not restrict whi…

▾ Sunlitelectron · electronEPSS 0.32%via NVD
CVE-2026-70606Medium· 5.9
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 40.10.6, 41.9.1, 42.5.1, and 43.0.0, when a custom protocol handler returned a ProtocolResponse with a url and no session, E…

▾ Sunlitelectron · electronEPSS 0.26%via NVD
CVE-2026-70607Medium· 5.3
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, some window options supplied by web content in the window.open() features string …

▾ Sunlitelectron · electronEPSS 0.58%via NVD
CVE-2026-70597Medium· 6.3
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the check Electron uses on macOS to confirm it was launched by a same-signed pare…

▾ Sunlitelectron · electronEPSS 0.11%via NVD
CVE-2026-70598Low· 3.9
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rendering frame data received from the GPU process was not fully valid…

▾ Sunlitelectron · electronEPSS 0.14%via NVD
CVE-2026-70599Medium· 5.9
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, serial-port and media permission checks made from an iframe passed the top-level …

▾ Sunlitelectron · electronEPSS 0.19%via NVD
CVE-2026-70600Low· 3.1
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the native autofill popup could be positioned by a cross-origin iframe outside th…

▾ Sunlitelectron · electronEPSS 0.22%via NVD
CVE-2026-70601High· 7.5
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5, apps that expose Promise-returning functions to web content via contextBridge may…

▾ Twilightelectron · electronEPSS 0.30%via NVD
CVE-2026-70595Medium· 4.0
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost serve…

▾ Sunlitghost · ghostEPSS 0.28%via NVD
CVE-2026-70596Medium· 4.3
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to create a post with content in feature_image_caption that could be used to hijack another staff user's Ghost Admin …

▾ Sunlitghost · ghostEPSS 0.32%via NVD
CVE-2026-53949Medium· 5.3
1mo ago

Ghost Content API filter bypass reveals private fields

Ghost Content API filter bypass reveals private fields

▾ Sunlitghost · ghostEPSS 0.36%via GHSA
CVE-2026-70593Medium· 6.6
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside of the uploads directory. This could be used to alter the behavior of the installation t…

▾ Sunlitghost · ghostEPSS 0.41%via NVD
CVE-2026-70594Medium· 6.7
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another v…

▾ Sunlitghost · ghostEPSS 0.24%via NVD
CVEs tagged “npm” — page 11 · VulnSea