npm Package Vulnerabilities
All 2,874 JavaScript / Node.js packages with known CVEs, ranked by live CVE volume — 6,722 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.
- 201.aws-iot-device-sdk-v24 CVEs
- 202.@backstage/plugin-auth-backend4 CVEs
- 203.@backstage/plugin-techdocs-node4 CVEs
- 204.@better-auth/oauth-provider4 CVEs
- 205.@builder.io/qwik4 CVEs
- 206.@clerk/nextjs4 CVEs
- 207.code-server4 CVEs
- 208.convert-svg-core4 CVEs
- 209.@earendil-works/pi-coding-agent4 CVEs
- 210.erxes4 CVEs
- 211.exifreader4 CVEs
- 212.express-cart4 CVEs
- 213.@fastify/middie4 CVEs
- 214.@fastify/static4 CVEs
- 215.@feathersjs/authentication-oauth4 CVEs
- 216.@finos/git-proxy4 CVEs
- 217.hummus4 CVEs
- 218.i18next-http-middleware4 CVEs
- 219.@intlify/vue-i18n-core4 CVEs
- 220.jquery-validation4 CVEs
- 221.jsonwebtoken4 CVEs
- 222.kysely4 CVEs
- 223.langsmith4 CVEs
- 224.libxmljs4 CVEs
- 225.markdown-it4 CVEs
- 226.materialize-css4 CVEs
- 227.mcp-searxng4 CVEs
- 228.mercurius4 CVEs
- 229.meshcentral4 CVEs
- 230.mongo-express4 CVEs
- 231.mongosh4 CVEs
- 232.morgan4 CVEs
- 233.mppx4 CVEs
- 234.muhammara4 CVEs
- 235.@nestjs/platform-fastify4 CVEs
- 236.@node-saml/node-saml4 CVEs
- 237.nuxt-og-image4 CVEs
- 238.nx4 CVEs
- 239.parse-dashboard4 CVEs
- 240.passport-wsfed-saml24 CVEs
- 241.petite-vue-i18n4 CVEs
- 242.protobufjs-cli4 CVEs
- 243.re24 CVEs
- 244.remarkable4 CVEs
- 245.@saltcorn/server4 CVEs
- 246.@samanhappy/mcphub4 CVEs
- 247.@sap/approuter4 CVEs
- 248.shell-quote4 CVEs
- 249.sm-crypto4 CVEs
- 250.snyk4 CVEs
Which npm packages run in YOUR stack?
EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.
Book a Demo →