npm Package Vulnerabilities

All 2,694 JavaScript / Node.js packages with known CVEs, ranked by live CVE volume — 5,663 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.

  1. 401.decal2 CVEs
  2. 402.decompress2 CVEs
  3. 403.deep-get-set2 CVEs
  4. 404.deephas2 CVEs
  5. 405.deepseek-tui2 CVEs
  6. 406.defaults-deep2 CVEs
  7. 407.@dependencytrack/frontend2 CVEs
  8. 408.detect-character-encoding2 CVEs
  9. 409.devcert2 CVEs
  10. 410.dijit2 CVEs
  11. 411.@directus/app2 CVEs
  12. 412.@directus/storage-driver-s32 CVEs
  13. 413.@discordjs/opus2 CVEs
  14. 414.dotty2 CVEs
  15. 415.droppy2 CVEs
  16. 416.electron-markdownify2 CVEs
  17. 417.element-plus2 CVEs
  18. 418.elysia2 CVEs
  19. 419.enclave-vm2 CVEs
  20. 420.@enclave-vm/core2 CVEs
  21. 421.@enderfga/claw-orchestrator2 CVEs
  22. 422.eta2 CVEs
  23. 423.@excalidraw/excalidraw2 CVEs
  24. 424.expo2 CVEs
  25. 425.express-fileupload2 CVEs
  26. 426.express-gateway2 CVEs
  27. 427.express-openid-connect2 CVEs
  28. 428.express-xss-sanitizer2 CVEs
  29. 429.expr-eval2 CVEs
  30. 430.expr-eval-fork2 CVEs
  31. 431.fast-filesystem-mcp2 CVEs
  32. 432.fastify-csrf2 CVEs
  33. 433.@fastify/multipart2 CVEs
  34. 434.fastify-multipart2 CVEs
  35. 435.@fastify/passport2 CVEs
  36. 436.fastify-static2 CVEs
  37. 437.@fastly/js-compute2 CVEs
  38. 438.fast-string-search2 CVEs
  39. 439.fast-xml-builder2 CVEs
  40. 440.@fedify/vocab-runtime2 CVEs
  41. 441.financejs2 CVEs
  42. 442.@finastra/nestjs-proxy2 CVEs
  43. 443.@finastra/ssr-pages2 CVEs
  44. 444.find-my-way2 CVEs
  45. 445.fiora2 CVEs
  46. 446.flatted2 CVEs
  47. 447.flowise-ui2 CVEs
  48. 448.form-data2 CVEs
  49. 449.formio2 CVEs
  50. 450.forms2 CVEs

Which npm packages run in YOUR stack?

EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.

Start Free Scan →