npm Package Vulnerabilities
All 2,694 JavaScript / Node.js packages with known CVEs, ranked by live CVE volume — 5,666 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.
- 451.ftp-srv2 CVEs
- 452.fullpage.js2 CVEs
- 453.generator-jhipster-kotlin2 CVEs
- 454.genieacs2 CVEs
- 455.ggit2 CVEs
- 456.gitbook2 CVEs
- 457.@github/copilot2 CVEs
- 458.@gitlawb/openclaude2 CVEs
- 459.glob-parent2 CVEs
- 460.h32 CVEs
- 461.@hapi/content2 CVEs
- 462.@hapi/wreck2 CVEs
- 463.Haraka2 CVEs
- 464.harp2 CVEs
- 465.hashbrown-cms2 CVEs
- 466.hawk2 CVEs
- 467.@haxtheweb/open-apis2 CVEs
- 468.@haxtheweb/video-player2 CVEs
- 469.hekto2 CVEs
- 470.hellojs2 CVEs
- 471.hexo2 CVEs
- 472.highcharts2 CVEs
- 473.hoek2 CVEs
- 474.html-janitor2 CVEs
- 475.html-pages2 CVEs
- 476.http-file-server2 CVEs
- 477.http-live-simulator2 CVEs
- 478.@hulumi/baseline2 CVEs
- 479.i18next2 CVEs
- 480.i18next-fs-backend2 CVEs
- 481.ip2 CVEs
- 482.is-my-json-valid2 CVEs
- 483.isolated-vm2 CVEs
- 484.is-svg2 CVEs
- 485.jellyfin-web2 CVEs
- 486.jose-browser-runtime2 CVEs
- 487.jpeg-js2 CVEs
- 488.jpv2 CVEs
- 489.jquery-file-upload2 CVEs
- 490.js-data2 CVEs
- 491.jsonata2 CVEs
- 492.jsoneditor2 CVEs
- 493.jsonpath2 CVEs
- 494.jsonpath-plus2 CVEs
- 495.json-ptr2 CVEs
- 496.jsreport2 CVEs
- 497.jsuites2 CVEs
- 498.jsx-slack2 CVEs
- 499.jszip2 CVEs
- 500.karma2 CVEs
Which npm packages run in YOUR stack?
EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.
Start Free Scan →