npm Package Vulnerabilities
All 2,701 JavaScript / Node.js packages with known CVEs, ranked by live CVE volume — 5,719 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.
- 751.@apollo/server1 CVE
- 752.apollo-server1 CVE
- 753.@apollosproject/data-connector-rock1 CVE
- 754.@apostrophecms/cli1 CVE
- 755.@apphp/object-resolver1 CVE
- 756.appium-chromedriver1 CVE
- 757.appium-desktop1 CVE
- 758.appium-mcp1 CVE
- 759.@appium/support1 CVE
- 760.appwrite-cli1 CVE
- 761.arcanist1 CVE
- 762.argencoders-notevil1 CVE
- 763.arrayfire-js1 CVE
- 764.arr-flatten-unflatten1 CVE
- 765.asciitable.js1 CVE
- 766.@astrojs/netlify1 CVE
- 767.@astrojs/rss1 CVE
- 768.async1 CVE
- 769.@asyncapi/java-spring-cloud-stream-template1 CVE
- 770.@asyncapi/modelina1 CVE
- 771.atlasboard1 CVE
- 772.@atlaskit/editor-core1 CVE
- 773.atlassian-connect-express1 CVE
- 774.atob1 CVE
- 775.atom-node-module-installer1 CVE
- 776.audify1 CVE
- 777.augustine1 CVE
- 778.aurelia-framework1 CVE
- 779.aurelia-path1 CVE
- 780.auth01 CVE
- 781.auth-fetch-mcp1 CVE
- 782.automagik-genie1 CVE
- 783.@aws-amplify/cli1 CVE
- 784.@aws-cdk/aws-eks1 CVE
- 785.aws-lambda1 CVE
- 786.aws-lambda-multipart-parser1 CVE
- 787.aws-sdk1 CVE
- 788.@aws-sdk/shared-ini-file-loader1 CVE
- 789.@awsui/components-react1 CVE
- 790.axios-cache-interceptor1 CVE
- 791.azle1 CVE
- 792.@azure/identity1 CVE
- 793.@azure/mcp1 CVE
- 794.@azure/msal-node1 CVE
- 795.@azure/ms-rest-nodeauth1 CVE
- 796.babelcli1 CVE
- 797.@babel/core1 CVE
- 798.@babel/helpers1 CVE
- 799.@babel/plugin-transform-modules-systemjs1 CVE
- 800.@babel/runtime1 CVE
Which npm packages run in YOUR stack?
EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.
Start Free Scan →