Products: 9
    Vulnerabilities: 19
    Known Exploited: 0
    1
    Critical Level Threats
    15
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-9496

    Denial of Service via addGitSha in pacote due to malicious spec.rawSpec input

    Last Modified: Jun 27, 2026
    Published: May 26, 2026

    CVE-2024-21523

    All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different functions. This makes it possible to reach an assert macro, leading to a process crash. **Note:** By providing some specific integer values (like 0) to the size function, it is possible to obtain a Segmentation fault error, leading to the process crash.

    Last Modified: Jun 26, 2026
    Published: Jul 10, 2024

    CVE-2024-25354

    RegEx Denial of Service in domain-suffix 1.0.8 allows attackers to crash the application via crafted input to the parse function.

    Last Modified: Apr 15, 2026
    Published: Mar 27, 2024

    CVE-2022-25883

    nodejs-semver: Regular expression denial of service

    Last Modified: Sep 23, 2025
    Published: Jun 21, 2023

    CVE-2022-29244

    npm packing does not respect root-level ignore files in workspaces

    Last Modified: Apr 23, 2025
    Published: Jun 13, 2022
    Items Per Page