Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-17305
  • npm/esm-dotenv
Malicious code in esm-dotenv (npm) 19 minutes ago
  • No fix available
MAL-2026-17309
  • npm/stestenv
Malicious code in stestenv (npm) 20 minutes ago
  • No fix available
MAL-2026-17310
  • npm/tailwind-forms-kit
Malicious code in tailwind-forms-kit (npm) 20 minutes ago
  • No fix available
MAL-2026-17307
  • npm/fabric-mod-utils
Malicious code in fabric-mod-utils (npm) 21 minutes ago
  • No fix available
MAL-2026-17304
  • npm/dotenv-precheck
Malicious code in dotenv-precheck (npm) 21 minutes ago
  • No fix available
MAL-2026-17306
  • npm/fabric-loader-core
Malicious code in fabric-loader-core (npm) 22 minutes ago
  • No fix available
MAL-2026-17308
  • npm/mfahelper
Malicious code in mfahelper (npm) 47 minutes ago
  • No fix available
MAL-2026-17302
  • npm/solidity-lock
Malicious code in solidity-lock (npm) 1 hour ago
  • No fix available
MAL-2026-17303
  • npm/web-vitals-polyfill-core-v1
Malicious code in web-vitals-polyfill-core-v1 (npm) 1 hour ago
  • No fix available
GHSA-m8vh-jmq9-5rjg
  • npm/@nestjs/microservices
Nest: Remote process termination via a deeply nested microservice message pattern 1 hour ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-hrr3-gc8f-f4qj
  • npm/fast-uri
fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets 1 hour ago
  • Fix available
  • Severity - 4.8 (Medium)
GHSA-jvvf-x445-j334
  • npm/fast-uri
fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization 1 hour ago
  • Fix available
  • Severity - 4.8 (Medium)
GHSA-hrh2-vp3x-79xf
  • npm/@xhmikosr/decompress
  • npm/decompress
@xhmikosr/decompress: Path traversal via symlink chain 1 hour ago
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-j6r3-76f7-8jcv
  • npm/ip-address
ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range 2 hours ago
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-h3mg-xc3c-68pw
  • npm/ip-address
ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process 2 hours ago
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-4p3w-j4w9-5jqw
  • npm/moment
moment vulnerable to Path Traversal via crafted non-string locale name 2 hours ago
  • Fix available
  • Severity - 5.9 (Medium)