npm Package Vulnerabilities
All 2,689 JavaScript / Node.js packages with known CVEs, ranked by live CVE volume — 5,609 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.
- 451.genieacs2 CVEs
- 452.ggit2 CVEs
- 453.gitbook2 CVEs
- 454.@github/copilot2 CVEs
- 455.@gitlawb/openclaude2 CVEs
- 456.glob-parent2 CVEs
- 457.@hapi/content2 CVEs
- 458.@hapi/wreck2 CVEs
- 459.Haraka2 CVEs
- 460.harp2 CVEs
- 461.hashbrown-cms2 CVEs
- 462.hawk2 CVEs
- 463.@haxtheweb/open-apis2 CVEs
- 464.@haxtheweb/video-player2 CVEs
- 465.hekto2 CVEs
- 466.hellojs2 CVEs
- 467.hexo2 CVEs
- 468.highcharts2 CVEs
- 469.hoek2 CVEs
- 470.html-janitor2 CVEs
- 471.html-pages2 CVEs
- 472.http-file-server2 CVEs
- 473.http-live-simulator2 CVEs
- 474.@hulumi/baseline2 CVEs
- 475.i18next2 CVEs
- 476.i18next-fs-backend2 CVEs
- 477.ip2 CVEs
- 478.is-my-json-valid2 CVEs
- 479.isolated-vm2 CVEs
- 480.is-svg2 CVEs
- 481.jellyfin-web2 CVEs
- 482.jose-browser-runtime2 CVEs
- 483.jpeg-js2 CVEs
- 484.jpv2 CVEs
- 485.jquery-file-upload2 CVEs
- 486.js-data2 CVEs
- 487.jsonata2 CVEs
- 488.jsoneditor2 CVEs
- 489.jsonpath2 CVEs
- 490.jsonpath-plus2 CVEs
- 491.json-ptr2 CVEs
- 492.jsreport2 CVEs
- 493.jsuites2 CVEs
- 494.jsx-slack2 CVEs
- 495.jszip2 CVEs
- 496.karma2 CVEs
- 497.keyget2 CVEs
- 498.@keystone-6/auth2 CVEs
- 499.kindeditor2 CVEs
- 500.@kindspells/astro-shield2 CVEs
Which npm packages run in YOUR stack?
EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.
Start Free Scan →