Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2241582
AlmaLinux
5967
Alpaquita
16176
Alpine
4655
Android
3677
Azure Linux
17971
BellSoft Hardened Containers
770
Bitnami
9476
Chainguard
1048510
CleanStart
5235
CRAN
14
crates.io
2763
Debian
68963
Echo
7866
GHC
3
GIT
109042
GitHub Actions
55
Go
9328
Hackage
33
Hex
364
Julia
1713
Linux
29975
Mageia
6237
Maven
7050
MinimOS
148513
npm
229196
NuGet
1869
opam
29
openEuler
8900
openSUSE
14573
OSS-Fuzz
4018
Packagist
7101
Pub
11
PyPI
25464
Red Hat
23527
Rocky Linux
4343
Root
19638
RubyGems
5331
SUSE
23442
SwiftURL
60
TuxCare
9919
Ubuntu
65977
VSCode
21
Wolfi
293807
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-g84c-rxfj-3j2c
npm/webpack-dev-middleware
webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath
5 days ago
Fix available
Severity - 7.4 (High)
MAL-2026-14314
npm/webpack-cdn-fetcher
Malicious code in webpack-cdn-fetcher (npm)
19 Aug
No fix available
MAL-2026-13050
npm/boxy-global-modules-webpack-plugin
Malicious code in boxy-global-modules-webpack-plugin (npm)
05 Aug
No fix available
MAL-2026-13097
npm/boxy-webpack-test-utils
Malicious code in boxy-webpack-test-utils (npm)
05 Aug
No fix available
MAL-2026-13099
npm/boxy-wrapper-webpack-plugin
Malicious code in boxy-wrapper-webpack-plugin (npm)
05 Aug
No fix available
MAL-2026-12441
npm/sme-scripts-shared-library-webpack-plugin
Malicious code in sme-scripts-shared-library-webpack-plugin (npm)
05 Aug
No fix available
MAL-2026-12072
npm/specials-obid-webpack
Malicious code in specials-obid-webpack (npm)
05 Aug
No fix available
MAL-2026-11780
npm/@ornikar/webpack-config
Malicious code in @ornikar/webpack-config (npm)
04 Aug
No fix available
GHSA-wx67-qw84-cm4g
npm/react-server-dom-parcel
npm/react-server-dom-turbopack
npm/react-server-dom-webpack
react-server-dom: Denial of Service in Server Functions
24 Jul
Fix available
Severity - 7.5 (High)
GHSA-m28w-2pqf-7qgj
npm/webpack-dev-server
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
20 Jul
Fix available
Severity - 5.3 (Medium)
GHSA-f5vj-f2hx-8m93
npm/webpack-dev-server
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
20 Jul
Fix available
Severity - 4.7 (Medium)
MAL-2026-10859
npm/@gocortexio/npmgremlinbox-typosquat-webpack
Malicious code in @gocortexio/npmgremlinbox-typosquat-webpack (npm)
20 Jul
No fix available
MAL-2026-10653
npm/webpack-session-cache
Malicious code in webpack-session-cache (npm)
15 Jul
No fix available
GHSA-mx8g-39q3-5c79
npm/webpack-dev-server
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
17 Jun
Fix available
Severity - 5.3 (Medium)
GHSA-x6qj-4h56-5rj5
npm/@nuxt/rspack-builder
npm/@nuxt/webpack-builder
@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all absent (incomplete fix for GHSA-6m52-m754-pw2g)
16 Jun
Fix available
Severity - 5.9 (Medium)
MAL-2026-5579
npm/webpack-cache-cycle
Malicious code in webpack-cache-cycle (npm)
11 Jun
No fix available
Load more...
npm - OSV