npm Package Vulnerabilities

All 2,874 JavaScript / Node.js packages with known CVEs, ranked by live CVE volume — 6,722 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.

  1. 201.aws-iot-device-sdk-v24 CVEs
  2. 202.@backstage/plugin-auth-backend4 CVEs
  3. 203.@backstage/plugin-techdocs-node4 CVEs
  4. 204.@better-auth/oauth-provider4 CVEs
  5. 205.@builder.io/qwik4 CVEs
  6. 206.@clerk/nextjs4 CVEs
  7. 207.code-server4 CVEs
  8. 208.convert-svg-core4 CVEs
  9. 209.@earendil-works/pi-coding-agent4 CVEs
  10. 210.erxes4 CVEs
  11. 211.exifreader4 CVEs
  12. 212.express-cart4 CVEs
  13. 213.@fastify/middie4 CVEs
  14. 214.@fastify/static4 CVEs
  15. 215.@feathersjs/authentication-oauth4 CVEs
  16. 216.@finos/git-proxy4 CVEs
  17. 217.hummus4 CVEs
  18. 218.i18next-http-middleware4 CVEs
  19. 219.@intlify/vue-i18n-core4 CVEs
  20. 220.jquery-validation4 CVEs
  21. 221.jsonwebtoken4 CVEs
  22. 222.kysely4 CVEs
  23. 223.langsmith4 CVEs
  24. 224.libxmljs4 CVEs
  25. 225.markdown-it4 CVEs
  26. 226.materialize-css4 CVEs
  27. 227.mcp-searxng4 CVEs
  28. 228.mercurius4 CVEs
  29. 229.meshcentral4 CVEs
  30. 230.mongo-express4 CVEs
  31. 231.mongosh4 CVEs
  32. 232.morgan4 CVEs
  33. 233.mppx4 CVEs
  34. 234.muhammara4 CVEs
  35. 235.@nestjs/platform-fastify4 CVEs
  36. 236.@node-saml/node-saml4 CVEs
  37. 237.nuxt-og-image4 CVEs
  38. 238.nx4 CVEs
  39. 239.parse-dashboard4 CVEs
  40. 240.passport-wsfed-saml24 CVEs
  41. 241.petite-vue-i18n4 CVEs
  42. 242.protobufjs-cli4 CVEs
  43. 243.re24 CVEs
  44. 244.remarkable4 CVEs
  45. 245.@saltcorn/server4 CVEs
  46. 246.@samanhappy/mcphub4 CVEs
  47. 247.@sap/approuter4 CVEs
  48. 248.shell-quote4 CVEs
  49. 249.sm-crypto4 CVEs
  50. 250.snyk4 CVEs

Which npm packages run in YOUR stack?

EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.

Book a Demo →