Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2232627
AlmaLinux
5964
Alpaquita
16124
Alpine
4635
Android
3677
Azure Linux
17766
BellSoft Hardened Containers
762
Bitnami
9476
Chainguard
1043084
CleanStart
5235
CRAN
14
crates.io
2747
Debian
68820
Echo
7730
GHC
3
GIT
108734
GitHub Actions
55
Go
9317
Hackage
33
Hex
364
Julia
1713
Linux
29975
Mageia
6233
Maven
7048
MinimOS
147720
npm
229054
NuGet
1869
opam
29
openEuler
8900
openSUSE
14526
OSS-Fuzz
4015
Packagist
7100
Pub
11
PyPI
25416
Red Hat
23452
Rocky Linux
4332
Root
19620
RubyGems
5326
SUSE
23401
SwiftURL
60
TuxCare
9809
Ubuntu
65805
VSCode
21
Wolfi
292652
ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-17426
npm/kartykgithub-ph-f
Malicious code in kartykgithub-ph-f (npm)
38 minutes ago
No fix available
MAL-2026-17425
npm/kartykgithub-ph-e
Malicious code in kartykgithub-ph-e (npm)
2 hours ago
No fix available
MAL-2026-17424
npm/kartykgithub-ph-b
Malicious code in kartykgithub-ph-b (npm)
3 hours ago
No fix available
MAL-2026-17423
npm/illusion-datalab
Malicious code in illusion-datalab (npm)
6 hours ago
No fix available
MAL-2026-17362
npm/@kelvdra/baileys
Malicious code in @kelvdra/baileys (npm)
11 hours ago
No fix available
MAL-2026-17351
npm/@bottino/baileys
Malicious code in @bottino/baileys (npm)
11 hours ago
No fix available
GHSA-jf8q-945g-9q4c
npm/vm2
vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks
13 hours ago
Fix available
Severity - 6.8 (Medium)
GHSA-qhwx-74w5-xhxq
npm/vm2
vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape
13 hours ago
Fix available
Severity - 9.9 (Critical)
GHSA-jxxv-8r27-vm4p
npm/vm2
vm2 CLI provides no sandbox isolation - host-realm require() is reachable from sandboxed scripts
13 hours ago
Fix available
Severity - 8.6 (High)
GHSA-h85j-hv3c-qfgq
npm/vm2
vm2 exposes host HTTPS credentials and TLS traffic through globalAgent
13 hours ago
Fix available
Severity - 10.0 (Critical)
GHSA-c48m-32m9-vx93
npm/vm2
vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package
13 hours ago
Fix available
Severity - 9.9 (Critical)
GHSA-6rh5-qq4q-97xh
npm/vm2
vm2: NodeVM builtin denylist bypass via fs/promises despite -fs, allowing host filesystem writes
13 hours ago
Fix available
Severity - 8.5 (High)
GHSA-8686-vhfx-7r3j
npm/vm2
vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process
13 hours ago
Fix available
Severity - 9.9 (Critical)
GHSA-633r-hq9m-c4ff
npm/vm2
vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor
13 hours ago
Fix available
Severity - 4.0 (Medium)
GHSA-8hr7-r645-pc6w
npm/vm2
vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE
13 hours ago
Fix available
Severity - 9.0 (Critical)
GHSA-647f-g98j-qq25
npm/vm2
vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection
13 hours ago
Fix available
Severity - 10.0 (Critical)
Load more...
npm - OSV