Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
310454
AlmaLinux
3782
Alpine
3747
Android
2824
Bitnami
5696
Chainguard
24827
CRAN
10
crates.io
1733
Debian
46993
GHC
3
GIT
29868
GitHub Actions
28
Go
4350
Hackage
24
Hex
37
Linux
13574
Mageia
5644
Maven
5682
MinimOS
1880
npm
27428
NuGet
1446
openSUSE
10118
OSS-Fuzz
3084
Packagist
4741
Pub
10
PyPI
16000
Red Hat
16469
Rocky Linux
1747
RubyGems
1688
SUSE
16484
SwiftURL
35
Ubuntu
47103
Wolfi
13399
ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2025-6005
npm/noya-vaults
Malicious code in noya-vaults (npm)
6 hours ago
No fix available
MAL-2025-5998
npm/eth-validator
Malicious code in eth-validator (npm)
11 hours ago
No fix available
MAL-2025-6003
npm/sol-validator
Malicious code in sol-validator (npm)
11 hours ago
No fix available
MAL-2025-5999
npm/nodemailer-helper
Malicious code in nodemailer-helper (npm)
11 hours ago
No fix available
MAL-2025-6001
npm/react-hook-form-ui
Malicious code in react-hook-form-ui (npm)
11 hours ago
No fix available
MAL-2025-6004
npm/winston-compose
Malicious code in winston-compose (npm)
11 hours ago
No fix available
MAL-2025-6002
npm/rtp-rapyd
Malicious code in rtp-rapyd (npm)
11 hours ago
No fix available
MAL-2025-5997
npm/dex-sample-app
Malicious code in dex-sample-app (npm)
11 hours ago
No fix available
MAL-2025-6000
npm/public-tools-and-demos
Malicious code in public-tools-and-demos (npm)
11 hours ago
No fix available
GHSA-9rcw-c2f9-2j55
npm/@openzeppelin/contracts
npm/@openzeppelin/contracts-upgradeable
OpenZeppelin Contracts Bytes's lastIndexOf function with position argument performs out-of-bound memory access on empty buffers
13 hours ago
Fix available
Severity - 6.9 (Medium)
GHSA-76c9-3jph-rj3q
npm/on-headers
on-headers is vulnerable to http response header manipulation
13 hours ago
Fix available
Severity - 3.4 (Low)
GHSA-fjgf-rc76-4x9p
npm/multer
Multer vulnerable to Denial of Service via unhandled exception from malformed request
13 hours ago
Fix available
Severity - 7.5 (High)
MAL-2025-5996
npm/@jssrv/template
Malicious code in @jssrv/template (npm)
14 hours ago
No fix available
GHSA-hfj7-542q-8fvv
npm/@dirac-grid/diracx-web-components
DiracX-Web is vulnerable to attack through an Open Redirect on its login page
15 hours ago
Fix available
Severity - 4.7 (Medium)
MAL-2025-5995
npm/dascxcxcxcxcxcxxc
Malicious code in dascxcxcxcxcxcxxc (npm)
18 hours ago
No fix available
MAL-2025-5994
npm/acsascasccsaascascacs
Malicious code in acsascasccsaascascacs (npm)
19 hours ago
No fix available
Load more...
npm - OSV