Products: 4
    Vulnerabilities: 6
    Known Exploited: 0
    2
    Critical Level Threats
    1
    High Level Threats
    2
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-39315

    Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe()

    Last Modified: Apr 15, 2026
    Published: Apr 09, 2026

    CVE-2026-35209

    defu: Prototype pollution via `__proto__` key in defaults argument

    Last Modified: Apr 27, 2026
    Published: Apr 06, 2026

    CVE-2026-31873

    Unhead has a Bypass of URI Scheme Sanitization in makeTagSafe via Case-Sensitivity

    Last Modified: Mar 20, 2026
    Published: Mar 12, 2026

    CVE-2026-31860

    Unhead has a XSS bypass in `useHeadSafe` via attribute name injection and case-sensitive protocol check

    Last Modified: Mar 20, 2026
    Published: Mar 12, 2026

    CVE-2025-69874

    nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outside the intended extraction directory via a crafted tar archive containing path traversal sequence.

    Last Modified: Apr 03, 2026
    Published: Feb 11, 2026
    Items Per Page
    Unjs Vulnerabilities & Security CVEs | CVE-DB