npm Package Vulnerabilities
All 2,691 JavaScript / Node.js packages with known CVEs, ranked by live CVE volume — 5,641 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.
- 301.safer-eval3 CVEs
- 302.sails3 CVEs
- 303.@samanhappy/mcphub3 CVEs
- 304.samlify3 CVEs
- 305.send3 CVEs
- 306.@sequelize/core3 CVEs
- 307.set-in3 CVEs
- 308.simplehttpserver3 CVEs
- 309.simple-markdown3 CVEs
- 310.slpjs3 CVEs
- 311.slp-validate3 CVEs
- 312.sm-crypto3 CVEs
- 313.snowflake-sdk3 CVEs
- 314.socket.io3 CVEs
- 315.stimulsoft-dashboards-js3 CVEs
- 316.@strapi/core3 CVEs
- 317.@strapi/plugin-content-manager3 CVEs
- 318.@strapi/utils3 CVEs
- 319.@theia/ai-chat3 CVEs
- 320.@theia/ai-chat-ui3 CVEs
- 321.@theia/ai-claude-code3 CVEs
- 322.@theia/ai-code-completion3 CVEs
- 323.@theia/ai-core3 CVEs
- 324.@theia/ai-editor3 CVEs
- 325.tinacms3 CVEs
- 326.tmp3 CVEs
- 327.tough-cookie3 CVEs
- 328.@typebot.io/js3 CVEs
- 329.typeorm3 CVEs
- 330.uap-core3 CVEs
- 331.@vitest/browser3 CVEs
- 332.@vrite/sdk3 CVEs
- 333.vuetify3 CVEs
- 334.@workos-inc/authkit-nextjs3 CVEs
- 335.xml-crypto3 CVEs
- 336.yapi-vendor3 CVEs
- 337.@aborruso/ckan-mcp-server2 CVEs
- 338.@actions/core2 CVEs
- 339.adm-zip2 CVEs
- 340.@adobe/css-tools2 CVEs
- 341.aedes2 CVEs
- 342.aegir2 CVEs
- 343.@agenticmail/api2 CVEs
- 344.@agenticmail/core2 CVEs
- 345.agents2 CVEs
- 346.ag-grid-community2 CVEs
- 347.ag-grid-enterprise2 CVEs
- 348.ajv2 CVEs
- 349.algoliasearch-helper2 CVEs
- 350.@anthropic-ai/sdk2 CVEs
Which npm packages run in YOUR stack?
EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.
Start Free Scan →