VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

CVE-2026-56762Medium· 5.3
5mo ago

Hono missing validation of cookie name on write path in setCookie()

Hono missing validation of cookie name on write path in setCookie()

▾ Sunlithono · honoEPSS 0.42%via GHSA
CVE-2026-32594Medium
6mo ago

Parse Server's GraphQL WebSocket endpoint bypasses security middleware

Parse Server's GraphQL WebSocket endpoint bypasses security middleware

▾ Sunlitparse-server · parse-serverEPSS 0.47%via GHSA
CVE-2026-26318High· 8.8
7mo ago

Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation

Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation

▾ Twilightsysteminformation · systeminformationEPSS 1.3%via GHSA
CVE-2026-21884High· 8.2
8mo ago

React Router is a router for React

React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React Router's <ScrollRestoration> API in Framework Mode when using the getKey/stora…

▾ Twilightshopify · react-routerEPSS 0.54%via NVD
CVE-2025-59057High· 7.6PoC
8mo ago

React Router is a router for React

React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating s…

▾ Midnightshopify · react-routerEPSS 0.51%via NVD
CVE-2025-61686Critical· 9.1PoC
8mo ago

React Router is a router for React

React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node prior to version 2.17.2, if createFileSessionStorage() is being used from @react-router/…

▾ Abyssalshopify · react-router/nodeEPSS 18%via NVD
CVE-2025-68113Medium· 6.5
9mo ago

ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay

ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay

▾ Sunlitaltcha-lib · altcha-libEPSS 0.46%via OSV
CVE-2025-64495High· 8.7PoC
10mo ago

Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE

Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE

▾ Midnightopen-webui · open-webuiEPSS 0.46%via OSV
CVE-2025-64496High· 7.3
10mo ago

Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events

Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events

▾ Twilightopen-webui · open-webuiEPSS 7.8%via OSV
CVE-2025-11849Critical· 9.3
11mo ago

Mammoth is vulnerable to Directory Traversal

Mammoth is vulnerable to Directory Traversal

▾ Midnightmammoth · mammothEPSS 1.0%via OSV
CVE-2024-58351High
1y ago

Flowise OverrideConfig security vulnerability

Flowise OverrideConfig security vulnerability

▾ Twilightflowise · flowiseEPSS 0.93%via GHSA
CVE-2024-39896High· 7.5
2y ago

Directus Allows Single Sign-On User Enumeration

Directus Allows Single Sign-On User Enumeration

▾ Twilightdirectus · directusEPSS 0.51%via GHSA
CVE-2024-38355Medium· 7.3PoC
2y ago

socket.io has an unhandled 'error' event

socket.io has an unhandled 'error' event

▾ Twilightsocket.io · socket.ioEPSS 0.81%via GHSA
CVE-2024-38357Medium· 6.1
2y ago

TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements

TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements

▾ Sunlittinymce · tinymceEPSS 0.53%via OSV
CVE-2024-38356Medium· 6.1
2y ago

TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option

TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option

▾ Sunlittinymce · tinymceEPSS 0.53%via OSV
CVE-2024-21485Medium· 6.5PoC
2y ago

Dash apps vulnerable to Cross-site Scripting

Dash apps vulnerable to Cross-site Scripting

▾ Twilightdash-core-components · dash-core-componentsEPSS 1.5%via OSV
CVE-2023-26154Medium· 5.9
2y ago

pubnub Insufficient Entropy vulnerability

pubnub Insufficient Entropy vulnerability

▾ Sunlitpubnub · pubnubEPSS 0.96%via OSV
CVE-2024-21910Medium· 6.1
4y ago

Cross-site scripting vulnerability in TinyMCE plugins

Cross-site scripting vulnerability in TinyMCE plugins

▾ Sunlittinymce · tinymceEPSS 0.96%via OSV
CVE-2021-21423Medium· 6.8PoC
5y ago

Rebuild-bot workflow may allow unauthorised repository modifications

Rebuild-bot workflow may allow unauthorised repository modifications

▾ Twilightprojen · projenEPSS 1.4%via OSV
CVE-2019-11358Medium· 6.1⚠ ExploitedPoC
7y ago

XSS in jQuery as used in Drupal, Backdrop CMS, and other products

XSS in jQuery as used in Drupal, Backdrop CMS, and other products

▾ Twilightjquery · jqueryEPSS 87%via OSV
CVEs tagged “npm” — page 34 · VulnSea