npm Package Vulnerabilities

All 2,666 JavaScript / Node.js packages with known CVEs, ranked by live CVE volume — 5,511 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.

  1. 401.electron-markdownify2 CVEs
  2. 402.element-plus2 CVEs
  3. 403.elysia2 CVEs
  4. 404.enclave-vm2 CVEs
  5. 405.@enderfga/claw-orchestrator2 CVEs
  6. 406.eta2 CVEs
  7. 407.@excalidraw/excalidraw2 CVEs
  8. 408.exifreader2 CVEs
  9. 409.expo2 CVEs
  10. 410.express-fileupload2 CVEs
  11. 411.express-gateway2 CVEs
  12. 412.express-openid-connect2 CVEs
  13. 413.express-xss-sanitizer2 CVEs
  14. 414.expr-eval2 CVEs
  15. 415.expr-eval-fork2 CVEs
  16. 416.fast-filesystem-mcp2 CVEs
  17. 417.fastify-csrf2 CVEs
  18. 418.@fastify/multipart2 CVEs
  19. 419.fastify-multipart2 CVEs
  20. 420.@fastify/passport2 CVEs
  21. 421.@fastify/static2 CVEs
  22. 422.fastify-static2 CVEs
  23. 423.@fastly/js-compute2 CVEs
  24. 424.fast-string-search2 CVEs
  25. 425.fast-xml-builder2 CVEs
  26. 426.@fedify/vocab-runtime2 CVEs
  27. 427.financejs2 CVEs
  28. 428.@finastra/nestjs-proxy2 CVEs
  29. 429.@finastra/ssr-pages2 CVEs
  30. 430.find-my-way2 CVEs
  31. 431.fiora2 CVEs
  32. 432.flatted2 CVEs
  33. 433.flowise-ui2 CVEs
  34. 434.form-data2 CVEs
  35. 435.formio2 CVEs
  36. 436.forms2 CVEs
  37. 437.ftp-srv2 CVEs
  38. 438.fullpage.js2 CVEs
  39. 439.generator-jhipster2 CVEs
  40. 440.generator-jhipster-kotlin2 CVEs
  41. 441.genieacs2 CVEs
  42. 442.ggit2 CVEs
  43. 443.gitbook2 CVEs
  44. 444.@github/copilot2 CVEs
  45. 445.@gitlawb/openclaude2 CVEs
  46. 446.glob-parent2 CVEs
  47. 447.@hapi/content2 CVEs
  48. 448.@hapi/wreck2 CVEs
  49. 449.Haraka2 CVEs
  50. 450.harp2 CVEs

Which npm packages run in YOUR stack?

EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.

Start Free Scan →