Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
604297
AlmaLinux
4250
Alpaquita
7881
Alpine
3928
Android
3134
BellSoft Hardened Containers
285
Bitnami
6306
Chainguard
33351
CRAN
12
crates.io
1921
Debian
51709
Echo
2489
GHC
3
GIT
76020
GitHub Actions
37
Go
5212
Hackage
26
Hex
45
Julia
332
Linux
22812
Mageia
5775
Maven
6103
MinimOS
8966
npm
213892
NuGet
1506
openEuler
5649
openSUSE
10313
OSS-Fuzz
3738
Packagist
5550
Pub
10
PyPI
17510
Red Hat
17888
Rocky Linux
2539
RubyGems
1839
SUSE
17064
SwiftURL
42
Ubuntu
49504
VSCode
15
Wolfi
16641
ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-190
npm/conmiyagi-map
Malicious code in conmiyagi-map (npm)
6 hours ago
No fix available
MAL-2026-188
npm/shopping-cart-service
Malicious code in shopping-cart-service (npm)
yesterday
No fix available
GHSA-jrmj-c5cx-3cw6
npm/@angular/compiler
npm/@angular/core
Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
yesterday
Fix available
Severity - 8.5 (High)
MAL-2026-182
npm/yunxohang10
Malicious code in yunxohang10 (npm)
2 days ago
No fix available
MAL-2026-185
npm/yunxohang5
Malicious code in yunxohang5 (npm)
2 days ago
No fix available
MAL-2026-172
npm/chai-tests-async
Malicious code in chai-tests-async (npm)
2 days ago
No fix available
MAL-2026-174
npm/dotenv-intended
Malicious code in dotenv-intended (npm)
2 days ago
No fix available
MAL-2026-175
npm/jwtdapp
Malicious code in jwtdapp (npm)
2 days ago
No fix available
MAL-2026-171
npm/amdocs-core
Malicious code in amdocs-core (npm)
2 days ago
No fix available
MAL-2026-181
npm/smintio-portals-component-sdk
Malicious code in smintio-portals-component-sdk (npm)
2 days ago
No fix available
MAL-2026-169
npm/secguest-lib
Malicious code in secguest-lib (npm)
2 days ago
No fix available
MAL-2026-170
npm/secguest-react-lib
Malicious code in secguest-react-lib (npm)
2 days ago
No fix available
GHSA-j965-2qgj-vjmq
npm/aws-sdk
JavaScript SDK v2 users should add validation to the region parameter value in or migrate to v3
2 days ago
No fix available
Severity - 3.7 (Low)
GHSA-6475-r3vj-m8vf
npm/@smithy/config-resolver
AWS SDK for JavaScript v3 adopted defense in depth enhancement for region parameter value
2 days ago
Fix available
Severity - 3.7 (Low)
GHSA-vmc4-9828-r48r
npm/ghost
Ghost has SSRF via External Media Inliner
2 days ago
Fix available
Severity - 5.1 (Medium)
GHSA-9xg7-mwmp-xmjx
npm/ghost
Ghost has Staff Token permission bypass
2 days ago
Fix available
Severity - 8.1 (High)
Load more...
npm - OSV