Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2242916
AlmaLinux
5975
Alpaquita
16181
Alpine
4655
Android
3708
Azure Linux
17971
BellSoft Hardened Containers
771
Bitnami
9501
Chainguard
1048720
CleanStart
5479
CRAN
14
crates.io
2768
Debian
69013
Echo
7867
GHC
3
GIT
109123
GitHub Actions
55
Go
9332
Hackage
33
Hex
367
Julia
1713
Linux
29975
Mageia
6237
Maven
7055
MinimOS
148690
npm
229272
NuGet
1869
opam
29
openEuler
8900
openSUSE
14647
OSS-Fuzz
4019
Packagist
7103
Pub
11
PyPI
25495
Red Hat
23535
Rocky Linux
4354
Root
19660
RubyGems
5369
SUSE
23455
SwiftURL
61
TuxCare
9977
Ubuntu
66090
VSCode
21
Wolfi
293843
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-g84c-rxfj-3j2c
npm/webpack-dev-middleware
webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath
6 days ago
Fix available
Severity - 7.4 (High)
MAL-2026-14314
npm/webpack-cdn-fetcher
Malicious code in webpack-cdn-fetcher (npm)
19 Aug
No fix available
MAL-2026-13050
npm/boxy-global-modules-webpack-plugin
Malicious code in boxy-global-modules-webpack-plugin (npm)
05 Aug
No fix available
MAL-2026-13097
npm/boxy-webpack-test-utils
Malicious code in boxy-webpack-test-utils (npm)
05 Aug
No fix available
MAL-2026-13099
npm/boxy-wrapper-webpack-plugin
Malicious code in boxy-wrapper-webpack-plugin (npm)
05 Aug
No fix available
MAL-2026-12441
npm/sme-scripts-shared-library-webpack-plugin
Malicious code in sme-scripts-shared-library-webpack-plugin (npm)
05 Aug
No fix available
MAL-2026-12072
npm/specials-obid-webpack
Malicious code in specials-obid-webpack (npm)
05 Aug
No fix available
MAL-2026-11780
npm/@ornikar/webpack-config
Malicious code in @ornikar/webpack-config (npm)
04 Aug
No fix available
GHSA-wx67-qw84-cm4g
npm/react-server-dom-parcel
npm/react-server-dom-turbopack
npm/react-server-dom-webpack
react-server-dom: Denial of Service in Server Functions
24 Jul
Fix available
Severity - 7.5 (High)
GHSA-m28w-2pqf-7qgj
npm/webpack-dev-server
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
20 Jul
Fix available
Severity - 5.3 (Medium)
GHSA-f5vj-f2hx-8m93
npm/webpack-dev-server
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
20 Jul
Fix available
Severity - 4.7 (Medium)
MAL-2026-10859
npm/@gocortexio/npmgremlinbox-typosquat-webpack
Malicious code in @gocortexio/npmgremlinbox-typosquat-webpack (npm)
20 Jul
No fix available
MAL-2026-10653
npm/webpack-session-cache
Malicious code in webpack-session-cache (npm)
15 Jul
No fix available
GHSA-mx8g-39q3-5c79
npm/webpack-dev-server
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
17 Jun
Fix available
Severity - 5.3 (Medium)
GHSA-x6qj-4h56-5rj5
npm/@nuxt/rspack-builder
npm/@nuxt/webpack-builder
@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all absent (incomplete fix for GHSA-6m52-m754-pw2g)
16 Jun
Fix available
Severity - 5.9 (Medium)
MAL-2026-5579
npm/webpack-cache-cycle
Malicious code in webpack-cache-cycle (npm)
11 Jun
No fix available
Load more...
npm - OSV