Package Vulnerabilities by Ecosystem
11,333 CVE-affected open-source packages across 11 ecosystems, ranked by live CVE volume — 41,288 package-to-CVE mappings sourced from GHSA, NVD, and vendor advisories, with affected ranges and fixed versions. Each package links to its live CVE list, updated continuously as new vulnerabilities publish.
Java / JVM artifacts
Top 8 by CVE volume
- 1.org.jenkins-ci.main:jenkins-core259 CVEs
- 2.org.apache.tomcat:tomcat161 CVEs
- 3.com.liferay.portal:release.portal.bom159 CVEs
- 4.com.liferay.portal:release.dxp.bom125 CVEs
- 5.org.keycloak:keycloak-services96 CVEs
- 6.com.fasterxml.jackson.core:jackson-databind79 CVEs
- 7.org.apache.tomcat.embed:tomcat-embed-core75 CVEs
- 8.org.apache.struts:struts2-core60 CVEs
JavaScript / Node.js packages
Top 8 by CVE volume
- 1.openclaw530 CVEs
- 2.n8n140 CVEs
- 3.parse-server117 CVEs
- 4.flowise110 CVEs
- 5.electron65 CVEs
- 6.next56 CVEs
- 7.directus55 CVEs
- 8.nocodb54 CVEs
Python packages
Top 8 by CVE volume
- 1.tensorflow427 CVEs
- 2.tensorflow-cpu424 CVEs
- 3.tensorflow-gpu421 CVEs
- 4.django160 CVEs
- 5.apache-airflow150 CVEs
- 6.open-webui131 CVEs
- 7.plone101 CVEs
- 8.mlflow79 CVEs
Go modules
Top 8 by CVE volume
- 1.github.com/mattermost/mattermost-server283 CVEs
- 2.github.com/mattermost/mattermost-server/v6214 CVEs
- 3.github.com/mattermost/mattermost/server/v8199 CVEs
- 4.github.com/mattermost/mattermost-server/v5191 CVEs
- 5.stdlib162 CVEs
- 6.code.gitea.io/gitea106 CVEs
- 7.github.com/usememos/memos74 CVEs
- 8.gogs.io/gogs71 CVEs
PHP / Composer packages
Top 8 by CVE volume
- 1.moodle/moodle437 CVEs
- 2.magento/community-edition353 CVEs
- 3.magento/project-community-edition161 CVEs
- 4.wwbn/avideo142 CVEs
- 5.craftcms/cms125 CVEs
- 6.dolibarr/dolibarr125 CVEs
- 7.pimcore/pimcore125 CVEs
- 8.concrete5/concrete5119 CVEs
Rust crates
Top 8 by CVE volume
- 1.coreutils44 CVEs
- 2.wasmtime39 CVEs
- 3.deno36 CVEs
- 4.openssl-src26 CVEs
- 5.surrealdb26 CVEs
- 6.zebrad22 CVEs
- 7.rusqlite15 CVEs
- 8.russh15 CVEs
.NET packages
Top 8 by CVE volume
- 1.Microsoft.ChakraCore247 CVEs
- 2.Magick.NET-Q16-AnyCPU160 CVEs
- 3.Magick.NET-Q16-HDRI-AnyCPU160 CVEs
- 4.Magick.NET-Q8-AnyCPU160 CVEs
- 5.Magick.NET-Q16-HDRI-x86159 CVEs
- 6.Magick.NET-Q16-x86158 CVEs
- 7.Magick.NET-Q8-x86158 CVEs
- 8.Magick.NET-Q16-arm64156 CVEs
Ruby gems
Top 8 by CVE volume
- 1.actionpack62 CVEs
- 2.rack50 CVEs
- 3.nokogiri40 CVEs
- 4.rubygems-update25 CVEs
- 5.activerecord23 CVEs
- 6.puppet23 CVEs
- 7.activesupport17 CVEs
- 8.publify_core15 CVEs
Elixir / Erlang packages
Top 8 by CVE volume
- 1.hackney13 CVEs
- 2.ash8 CVEs
- 3.bandit8 CVEs
- 4.mint8 CVEs
- 5.cowlib7 CVEs
- 6.mpp7 CVEs
- 7.plug7 CVEs
- 8.html_sanitize_ex6 CVEs
Dart / Flutter packages
Top 8 by CVE volume
- 1.archive2 CVEs
- 2.agent_dart1 CVEs
- 3.dio1 CVEs
- 4.http1 CVEs
- 5.jose1 CVEs
- 6.personnummer1 CVEs
- 7.pubnub1 CVEs
- 8.serverpod_auth_server1 CVEs
Swift packages
Top 6 by CVE volume
- 1.github.com/pytorch/executorch6 CVEs
- 2.github.com/apple/swift-nio-http21 CVEs
- 3.github.com/facebook/zstd1 CVEs
- 4.github.com/mongodb/mongo-swift-driver1 CVEs
- 5.github.com/pubnub/swift1 CVEs
- 6.github.com/shareup/wasm-interpreter-apple1 CVEs
Which of these packages run in YOUR stack?
EchelonGraph inventories your dependencies across clouds and clusters, then correlates every package against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.
Start Free Scan →