Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2242155
AlmaLinux
5975
Alpaquita
16176
Alpine
4655
Android
3708
Azure Linux
17971
BellSoft Hardened Containers
770
Bitnami
9501
Chainguard
1048512
CleanStart
5235
CRAN
14
crates.io
2764
Debian
68992
Echo
7849
GHC
3
GIT
109057
GitHub Actions
55
Go
9331
Hackage
33
Hex
365
Julia
1713
Linux
29975
Mageia
6237
Maven
7053
MinimOS
148636
npm
229239
NuGet
1869
opam
29
openEuler
8900
openSUSE
14647
OSS-Fuzz
4019
Packagist
7101
Pub
11
PyPI
25474
Red Hat
23535
Rocky Linux
4343
Root
19643
RubyGems
5369
SUSE
23455
SwiftURL
61
TuxCare
9965
Ubuntu
66087
VSCode
21
Wolfi
293807
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-g84c-rxfj-3j2c
npm/webpack-dev-middleware
webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath
6 days ago
Fix available
Severity - 7.4 (High)
MAL-2026-14314
npm/webpack-cdn-fetcher
Malicious code in webpack-cdn-fetcher (npm)
19 Aug
No fix available
MAL-2026-13050
npm/boxy-global-modules-webpack-plugin
Malicious code in boxy-global-modules-webpack-plugin (npm)
05 Aug
No fix available
MAL-2026-13097
npm/boxy-webpack-test-utils
Malicious code in boxy-webpack-test-utils (npm)
05 Aug
No fix available
MAL-2026-13099
npm/boxy-wrapper-webpack-plugin
Malicious code in boxy-wrapper-webpack-plugin (npm)
05 Aug
No fix available
MAL-2026-12441
npm/sme-scripts-shared-library-webpack-plugin
Malicious code in sme-scripts-shared-library-webpack-plugin (npm)
05 Aug
No fix available
MAL-2026-12072
npm/specials-obid-webpack
Malicious code in specials-obid-webpack (npm)
05 Aug
No fix available
MAL-2026-11780
npm/@ornikar/webpack-config
Malicious code in @ornikar/webpack-config (npm)
04 Aug
No fix available
GHSA-wx67-qw84-cm4g
npm/react-server-dom-parcel
npm/react-server-dom-turbopack
npm/react-server-dom-webpack
react-server-dom: Denial of Service in Server Functions
24 Jul
Fix available
Severity - 7.5 (High)
GHSA-m28w-2pqf-7qgj
npm/webpack-dev-server
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
20 Jul
Fix available
Severity - 5.3 (Medium)
GHSA-f5vj-f2hx-8m93
npm/webpack-dev-server
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
20 Jul
Fix available
Severity - 4.7 (Medium)
MAL-2026-10859
npm/@gocortexio/npmgremlinbox-typosquat-webpack
Malicious code in @gocortexio/npmgremlinbox-typosquat-webpack (npm)
20 Jul
No fix available
MAL-2026-10653
npm/webpack-session-cache
Malicious code in webpack-session-cache (npm)
15 Jul
No fix available
GHSA-mx8g-39q3-5c79
npm/webpack-dev-server
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
17 Jun
Fix available
Severity - 5.3 (Medium)
GHSA-x6qj-4h56-5rj5
npm/@nuxt/rspack-builder
npm/@nuxt/webpack-builder
@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all absent (incomplete fix for GHSA-6m52-m754-pw2g)
16 Jun
Fix available
Severity - 5.9 (Medium)
MAL-2026-5579
npm/webpack-cache-cycle
Malicious code in webpack-cache-cycle (npm)
11 Jun
No fix available
Load more...
npm - OSV