VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

CVE-2026-83614High· 7.5
3w ago

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom versions 0.3.0 through 0.6.0, two independent quadratic paths can…

▾ Twilightxmldom · @xmldom/xmldomEPSS 0.59%via NVD
CVE-2026-83612High
3w ago

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.1 until 0.9.12, HTML-mode parsing through DOMParser.parseFromString() mishandles a mixed-case closing tag for the s…

▾ Twilightxmldom · @xmldom/xmldomEPSS 0.52%via NVD
CVE-2026-83619High· 7.5
3w ago

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.7.0 until 0.8.15, the release-0.8.x parser in lib/sax.js trims captured end-tag names with the unanchored global expression …

▾ Twilightxmldom · @xmldom/xmldomEPSS 0.52%via NVD
CVE-2026-83618High
3w ago

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.10 until 0.9.12, the requireWellFormed: true serializer validates DocumentType.publicId and DocumentType.systemId with Pub…

▾ Twilightxmldom · @xmldom/xmldomEPSS 0.57%via NVD
CVE-2026-83617High· 7.5
3w ago

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.11 until 0.9.12, the requireWellFormed: true element and attribute name checks use the anchored QName_exact expression pro…

▾ Twilightxmldom · @xmldom/xmldomEPSS 0.57%via NVD
CVE-2026-83616High· 7.5
3w ago

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, Document.createProcessingInstruction(t…

▾ Twilightxmldom · @xmldom/xmldomEPSS 0.61%via NVD
CVE-2026-83613High· 7.5
3w ago

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, DOMHandler.startElement in lib/dom-par…

▾ Twilightxmldom · @xmldom/xmldomEPSS 0.60%via NVD
CVE-2026-83611Medium
3w ago

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, DOMParser.parseFromString() can silent…

▾ Sunlitxmldom · @xmldom/xmldomEPSS 0.62%via NVD
CVE-2026-83609High· 7.5
3w ago

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0 until 0.9.12, the shared reg() builder in lib/grammar.js compiles the anchored QName_exact validator with the multiline …

▾ Twilightxmldom · @xmldom/xmldomEPSS 0.54%via NVD
CVE-2026-83608High· 3.1
3w ago

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, the DOCUMENT_TYPE_NODE branch in lib/d…

▾ Twilightxmldom · @xmldom/xmldomEPSS 0.61%via NVD
CVE-2026-83610Medium· 5.3
3w ago

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, Document.createEntityReference(name) a…

▾ Sunlitxmldom · @xmldom/xmldomEPSS 0.59%via NVD
CVE-2026-84371Medium· 5.4
3w ago

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value…

▾ SunlitRed Hat · Red Hat Satellite 6EPSS 0.30%via NVD
CVE-2026-58191Medium· 6.5PoC
3w ago

Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes

Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes

▾ Twilightappium · @appium/base-driverEPSS 0.56%via GHSA
GHSA-2rx9-3g3h-c2jvHigh· 7.1
3w ago

pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project

pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project

▾ Twilightpnpm · pnpmvia GHSA
GHSA-vx52-2968-3vc6High· 7.4
3w ago

pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml

pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml

▾ Twilightpnpm · pnpmvia GHSA
GHSA-3f6p-5ww8-9rcrHigh
3w ago

MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials

MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials

▾ Twilightmysql2 · mysql2via GHSA
CVE-2026-82393High· 7.5
3w ago

pnpm is a package manager

pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for…

▾ Twilightpnpm · pnpmEPSS 0.63%via NVD
CVE-2026-82392High· 7.1
3w ago

pnpm is a package manager

pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name and uses it without validation in deps/graph-builde…

▾ Twilightpnpm · pnpmEPSS 0.61%via NVD
CVE-2026-81888Medium· 5.4
3w ago

@hono/oauth-providers is Authentication middleware for Hono

@hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in social login providers accept an OAuth callback even when the `state` value is absent on both sides, so the anti-CSRF check passes for a ca…

▾ Sunlithono · @hono/oauth-providersEPSS 0.19%via NVD
CVE-2026-55855Medium· 6.5
1mo ago

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js permits SQL injection when attacker-controlled Buffer param…

▾ Sunlitmariadb · mariadbEPSS 0.47%via NVD
CVE-2026-55854Medium· 5.9
1mo ago

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js can disclose an account password when PAM dialog authentica…

▾ Sunlitmariadb · mariadbEPSS 0.42%via NVD
CVE-2026-55638High· 8.6
1mo ago

9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass

9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass

▾ Twilight9router · 9routerEPSS 0.61%via GHSA
CVE-2026-55215High· 7.5
1mo ago

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to versions 3.3.3, 3.4.6, and 3.5.3, when ssl is enabled without a pinned CA or server certificate, MariaDB Connector/No…

▾ Twilightmariadb · mariadbEPSS 0.57%via NVD
CVE-2026-54687Critical· 9.8
1mo ago

n8n-nodes-sqlite3 is a node for operating a local SQLite database from n8n

n8n-nodes-sqlite3 is a node for operating a local SQLite database from n8n. Prior to 1.0.0, nodes/SqliteNode/v1/SqliteV1.node.ts exposes the db_path database file path as a node parameter that permits data expressions from upstream workf…

▾ Midnightdangerblack · n8n-node-sqlite3EPSS 0.58%via NVD
CVE-2026-54732Medium· 6.5
1mo ago

libreoffice-convert is a Node.js module for converting office documents to different formats

libreoffice-convert is a Node.js module for converting office documents to different formats. Prior to 1.8.2, index.js uses the caller-controlled options.fileName value in path.join(tempDir.name, fileName) without reducing it to a base n…

▾ Sunlitlibreoffice-convert · libreoffice-convertEPSS 0.42%via NVD
CVE-2026-54606High
1mo ago

SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies

SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 3.1.4, the SunEditor Embed plugin in src/plugins/modal/embed.js parses attacker-controlled raw embed HTML with DOMParser and proc…

▾ Twilightsuneditor · suneditorEPSS 0.58%via NVD
CVE-2026-54511High· 8.6
1mo ago

LogTape is an unobtrusive logging library

LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, the @logtape/syslog package's escapeStructuredDataValue() function in packages/syslog/src/syslog.ts does not neutralize C0 control characters from U+0000 thro…

▾ Twilightlogtape · @logtape/syslogEPSS 0.48%via NVD
CVE-2026-55629High
1mo ago

Whistle vulnerable to path traversal

Whistle vulnerable to path traversal

▾ Twilightwhistle · whistleEPSS 0.67%via GHSA
CVE-2026-55609High· 7.1
1mo ago

sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear time

sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear time. Prior to consciousness-explorer 1.1.2 and sublinear-time-solver 1.6.0, the export_state and import_state tools …

▾ Twilightconsciousness-explorer · consciousness-explorerEPSS 0.17%via NVD
CVE-2026-55604High· 8.6
1mo ago

@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key

@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key

▾ Twilightarikusi · @arikusi/deepseek-mcp-serverEPSS 0.37%via GHSA
CVEs tagged “npm” — page 6 · VulnSea