Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2199764
AlmaLinux
5919
Alpaquita
15755
Alpine
4608
Android
3677
Azure Linux
17638
BellSoft Hardened Containers
746
Bitnami
9292
Chainguard
1023665
CleanStart
3591
CRAN
14
crates.io
2734
Debian
68378
Echo
7422
GHC
3
GIT
108138
GitHub Actions
55
Go
9203
Hackage
32
Hex
364
Julia
1713
Linux
29974
Mageia
6227
Maven
7040
MinimOS
144439
npm
228748
NuGet
1869
opam
29
openEuler
8800
openSUSE
14455
OSS-Fuzz
4013
Packagist
7095
Pub
11
PyPI
25171
Red Hat
23355
Rocky Linux
4298
Root
19558
RubyGems
5326
SUSE
23169
SwiftURL
60
TuxCare
9524
Ubuntu
65374
VSCode
21
Wolfi
288261
ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-16453
npm/semver-bump-io
Malicious code in semver-bump-io (npm)
5 days ago
No fix available
MAL-2026-13081
npm/boxy-semver
Malicious code in boxy-semver (npm)
05 Aug
No fix available
GHSA-c2qf-rxjj-qqgw
npm/semver
semver vulnerable to Regular Expression Denial of Service
21 Jun 2023
Fix available
Severity - 7.5 (High)
GHSA-8h3g-hcwp-6hxq
npm/semver-tags
semver-tags is vulnerable to Command Injection via the getGitTagsRemote function
06 Feb 2023
No fix available
Severity - 7.8 (High)
MAL-2022-696
npm/@unpkg-semver/pedops-logger
Malicious code in @unpkg-semver/pedops-logger (npm)
20 Jun 2022
No fix available
MAL-2022-697
npm/@unpkg-semver/wix-recorder
Malicious code in @unpkg-semver/wix-recorder (npm)
20 Jun 2022
No fix available
GHSA-4x5v-gmq8-25ch
npm/semver-regex
Regular expression denial of service in semver-regex
03 Jun 2022
Fix available
GHSA-44c6-4v22-4mhx
npm/semver-regex
semver-regex Regular Expression Denial of Service (ReDOS)
20 Sep 2021
Fix available
Severity - 7.5 (High)
GHSA-x6fg-f45m-jf5q
npm/semver
Regular Expression Denial of Service in semver
24 Oct 2017
Fix available
Severity - 7.5 (High)
npm - OSV