npm Package Vulnerabilities
All 2,694 JavaScript / Node.js packages with known CVEs, ranked by live CVE volume — 5,663 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.
- 401.decal2 CVEs
- 402.decompress2 CVEs
- 403.deep-get-set2 CVEs
- 404.deephas2 CVEs
- 405.deepseek-tui2 CVEs
- 406.defaults-deep2 CVEs
- 407.@dependencytrack/frontend2 CVEs
- 408.detect-character-encoding2 CVEs
- 409.devcert2 CVEs
- 410.dijit2 CVEs
- 411.@directus/app2 CVEs
- 412.@directus/storage-driver-s32 CVEs
- 413.@discordjs/opus2 CVEs
- 414.dotty2 CVEs
- 415.droppy2 CVEs
- 416.electron-markdownify2 CVEs
- 417.element-plus2 CVEs
- 418.elysia2 CVEs
- 419.enclave-vm2 CVEs
- 420.@enclave-vm/core2 CVEs
- 421.@enderfga/claw-orchestrator2 CVEs
- 422.eta2 CVEs
- 423.@excalidraw/excalidraw2 CVEs
- 424.expo2 CVEs
- 425.express-fileupload2 CVEs
- 426.express-gateway2 CVEs
- 427.express-openid-connect2 CVEs
- 428.express-xss-sanitizer2 CVEs
- 429.expr-eval2 CVEs
- 430.expr-eval-fork2 CVEs
- 431.fast-filesystem-mcp2 CVEs
- 432.fastify-csrf2 CVEs
- 433.@fastify/multipart2 CVEs
- 434.fastify-multipart2 CVEs
- 435.@fastify/passport2 CVEs
- 436.fastify-static2 CVEs
- 437.@fastly/js-compute2 CVEs
- 438.fast-string-search2 CVEs
- 439.fast-xml-builder2 CVEs
- 440.@fedify/vocab-runtime2 CVEs
- 441.financejs2 CVEs
- 442.@finastra/nestjs-proxy2 CVEs
- 443.@finastra/ssr-pages2 CVEs
- 444.find-my-way2 CVEs
- 445.fiora2 CVEs
- 446.flatted2 CVEs
- 447.flowise-ui2 CVEs
- 448.form-data2 CVEs
- 449.formio2 CVEs
- 450.forms2 CVEs
Which npm packages run in YOUR stack?
EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.
Start Free Scan →