Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-14352
  • npm/tailwind-animate-css-plugin
Malicious code in tailwind-animate-css-plugin (npm) 59 minutes ago
  • No fix available
MAL-2026-14346
  • npm/@next-fonts/font
Malicious code in @next-fonts/font (npm) 7 hours ago
  • No fix available
MAL-2026-14347
  • npm/mcq-session
Malicious code in mcq-session (npm) 7 hours ago
  • No fix available
MAL-2026-14348
  • npm/moidevy
Malicious code in moidevy (npm) 7 hours ago
  • No fix available
MAL-2026-14345
  • npm/express-session-handler
Malicious code in express-session-handler (npm) 8 hours ago
  • No fix available
MAL-2026-14344
  • npm/@js-lib-team/env-parser
Malicious code in @js-lib-team/env-parser (npm) 8 hours ago
  • No fix available
MAL-2026-14343
  • npm/chai-as-soul
Malicious code in chai-as-soul (npm) 8 hours ago
  • No fix available
MAL-2026-14342
  • npm/coin-fees
Malicious code in coin-fees (npm) 9 hours ago
  • No fix available
GHSA-f4jp-rw7w-ccwg
  • npm/gettext-converter
gettext-converter: Prototype pollution in js2i18next() via crafted translation keys 16 hours ago
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-ghvf-qf6h-g8x5
  • npm/@nocobase/server
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution 17 hours ago
  • Fix available
GHSA-v667-gc2r-2xm7
  • npm/@whyour/qinglong
Qinglong has an incomplete fix for CVE-2026-3965: Improper Authentication 17 hours ago
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-6wvw-vrw4-363w
  • npm/node-opcua
node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoS 17 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-mq36-523m-x7vv
  • npm/node-opcua
node-opcua missing nonce verification in UserNameIdentityToken authentication 17 hours ago
  • No fix available
  • Severity - 7.7 (High)
GHSA-2p39-2jf3-fv2q
  • npm/next-video
next-video: Unauthenticated arbitrary file read via /api/video request handler 17 hours ago
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-p853-83gj-wjj3
  • npm/@nocobase/plugin-backups
NocoBase backup restore schema name allows command injection 17 hours ago
  • Fix available
  • Severity - 6.7 (Medium)
MAL-2026-14331
  • npm/exam-kit
Malicious code in exam-kit (npm) 17 hours ago
  • No fix available