npm Package Vulnerabilities
All 2,666 JavaScript / Node.js packages with known CVEs, ranked by live CVE volume — 5,511 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.
- 351.@backstage/plugin-techdocs-node2 CVEs
- 352.@backstage/techdocs-common2 CVEs
- 353.@better-auth/sso2 CVEs
- 354.billboard.js2 CVEs
- 355.bmoor2 CVEs
- 356.bodymen2 CVEs
- 357.bootstrap-table2 CVEs
- 358.@boxlite-ai/boxlite2 CVEs
- 359.braces2 CVEs
- 360.@braintree/sanitize-url2 CVEs
- 361.browserstack-runner2 CVEs
- 362.@budibase/worker2 CVEs
- 363.buttle2 CVEs
- 364.cached-path-relative2 CVEs
- 365.chromedriver2 CVEs
- 366.ckeditor52 CVEs
- 367.@ckeditor/ckeditor5-clipboard2 CVEs
- 368.@clerk/hono2 CVEs
- 369.@clerk/react-router2 CVEs
- 370.@clerk/shared2 CVEs
- 371.@clerk/tanstack-react-start2 CVEs
- 372.@cloudflare/workers-oauth-provider2 CVEs
- 373.color-string2 CVEs
- 374.compressing2 CVEs
- 375.converse.js2 CVEs
- 376.cordova-plugin-inappbrowser2 CVEs
- 377.crud-file-server2 CVEs
- 378.crypto-js2 CVEs
- 379.css-what2 CVEs
- 380.@cubejs-backend/api-gateway2 CVEs
- 381.@cubejs-backend/server-core2 CVEs
- 382.cyberchef2 CVEs
- 383.datatables.net2 CVEs
- 384.dbgate-api2 CVEs
- 385.dbgate-web2 CVEs
- 386.decal2 CVEs
- 387.decompress2 CVEs
- 388.deep-get-set2 CVEs
- 389.deephas2 CVEs
- 390.deepseek-tui2 CVEs
- 391.defaults-deep2 CVEs
- 392.@dependencytrack/frontend2 CVEs
- 393.detect-character-encoding2 CVEs
- 394.devcert2 CVEs
- 395.dijit2 CVEs
- 396.@directus/app2 CVEs
- 397.@directus/storage-driver-s32 CVEs
- 398.@discordjs/opus2 CVEs
- 399.dotty2 CVEs
- 400.droppy2 CVEs
Which npm packages run in YOUR stack?
EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.
Start Free Scan →