Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2192872
AlmaLinux
5906
Alpaquita
15522
Alpine
4594
Android
3674
Azure Linux
17170
BellSoft Hardened Containers
744
Bitnami
9227
Chainguard
1022425
CleanStart
3529
CRAN
14
crates.io
2730
Debian
67904
Echo
6685
GHC
3
GIT
107255
GitHub Actions
55
Go
9202
Hackage
32
Hex
358
Julia
1713
Linux
29602
Mageia
6222
Maven
7011
MinimOS
143505
npm
228724
NuGet
1867
opam
29
openEuler
8800
openSUSE
14377
OSS-Fuzz
4006
Packagist
7091
Pub
11
PyPI
25150
Red Hat
23316
Rocky Linux
4279
Root
19521
RubyGems
5325
SUSE
23077
SwiftURL
60
TuxCare
9421
Ubuntu
64999
VSCode
21
Wolfi
287716
ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-14314
npm/webpack-cdn-fetcher
Malicious code in webpack-cdn-fetcher (npm)
19 Aug
No fix available
MAL-2026-13050
npm/boxy-global-modules-webpack-plugin
Malicious code in boxy-global-modules-webpack-plugin (npm)
05 Aug
No fix available
MAL-2026-13097
npm/boxy-webpack-test-utils
Malicious code in boxy-webpack-test-utils (npm)
05 Aug
No fix available
MAL-2026-13099
npm/boxy-wrapper-webpack-plugin
Malicious code in boxy-wrapper-webpack-plugin (npm)
05 Aug
No fix available
MAL-2026-12441
npm/sme-scripts-shared-library-webpack-plugin
Malicious code in sme-scripts-shared-library-webpack-plugin (npm)
05 Aug
No fix available
MAL-2026-12072
npm/specials-obid-webpack
Malicious code in specials-obid-webpack (npm)
05 Aug
No fix available
MAL-2026-11780
npm/@ornikar/webpack-config
Malicious code in @ornikar/webpack-config (npm)
04 Aug
No fix available
GHSA-wx67-qw84-cm4g
npm/react-server-dom-parcel
npm/react-server-dom-turbopack
npm/react-server-dom-webpack
react-server-dom: Denial of Service in Server Functions
24 Jul
Fix available
Severity - 7.5 (High)
GHSA-m28w-2pqf-7qgj
npm/webpack-dev-server
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
20 Jul
Fix available
Severity - 5.3 (Medium)
GHSA-f5vj-f2hx-8m93
npm/webpack-dev-server
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
20 Jul
Fix available
Severity - 4.7 (Medium)
MAL-2026-10859
npm/@gocortexio/npmgremlinbox-typosquat-webpack
Malicious code in @gocortexio/npmgremlinbox-typosquat-webpack (npm)
20 Jul
No fix available
MAL-2026-10653
npm/webpack-session-cache
Malicious code in webpack-session-cache (npm)
15 Jul
No fix available
GHSA-mx8g-39q3-5c79
npm/webpack-dev-server
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
17 Jun
Fix available
Severity - 5.3 (Medium)
GHSA-x6qj-4h56-5rj5
npm/@nuxt/rspack-builder
npm/@nuxt/webpack-builder
@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all absent (incomplete fix for GHSA-6m52-m754-pw2g)
16 Jun
Fix available
Severity - 5.9 (Medium)
MAL-2026-5579
npm/webpack-cache-cycle
Malicious code in webpack-cache-cycle (npm)
11 Jun
No fix available
MAL-2026-5581
npm/webpack-patch
Malicious code in webpack-patch (npm)
11 Jun
No fix available
Load more...
npm - OSV