Vulnerability Library

ID
Packages
Summary
Affected versions
Published
Fix
GHSA-jjff-q3q4-5hh8
  • npm/@andrei-tatar/nora-firebase-common
@andrei-tatar/nora-firebase-common Prototype Pollution vulnerability
  • See details.
2024-04-18T15:30:49Z Fix available
MAL-2024-1277
  • npm/malpac
Malicious code in malpac (npm)
  • See details.
2024-04-18T07:28:46Z No fix available
MAL-2024-1278
  • npm/somepackage-marksl
Malicious code in somepackage-marksl (npm)
  • See details.
2024-04-18T07:28:45Z No fix available
MAL-2024-1274
Malicious code in ui-common-components-angular (npm)
  • 1.3.1
2024-04-18T01:15:48Z No fix available
GHSA-82jv-9wjw-pqh6
  • npm/derby
Prototype pollution in emit function
  • See details.
2024-04-17T22:26:37Z Fix available
GHSA-m64q-4jqh-f72f
  • npm/@excalidraw/excalidraw
Stored Cross-site Scripting (XSS) in excalidraw's web embed component
  • See details.
2024-04-17T21:32:57Z Fix available
MAL-2024-1273
Malicious code in metrics-balancer (npm)
  • 0.2.0
2024-04-17T19:28:56Z No fix available
GHSA-8m45-2rjm-j347
  • npm/@solana/web3.js
Handling untrusted input can result in a crash, leading to loss of availability / denial of service
  • 1.88.0
  • 1.86.0
  • 1.85.0
  • 1.84.0
  • 1.83.0
  • 1.82.0
  • 1.81.0
  • ...
2024-04-17T18:21:18Z Fix available
MAL-2024-1275
Malicious code in @portal-packages/utils (npm)
  • 3.0.99
2024-04-17T01:50:45Z No fix available
MAL-2024-1272
Malicious code in @portal-packages/core (npm)
  • 15.100.100
  • 15.105.105
  • 15.99.99
2024-04-17T01:45:53Z No fix available
MAL-2024-1276
Malicious code in cz-ifood-conventional-changelog (npm)
  • 1.0.101
2024-04-17T00:00:50Z No fix available
MAL-2024-1267
Malicious code in commitlint-config-ifood (npm)
  • 1.95.102
2024-04-16T21:55:10Z No fix available
MAL-2024-1268
  • npm/bluepurellwalker
Malicious code in bluepurellwalker (npm)
  • See details.
2024-04-16T05:39:28Z No fix available
MAL-2024-1269
  • npm/hosted-lenses-ui
Malicious code in hosted-lenses-ui (npm)
  • See details.
2024-04-16T05:39:28Z No fix available
MAL-2024-1270
  • npm/snap-orca
Malicious code in snap-orca (npm)
  • See details.
2024-04-16T05:39:28Z No fix available
MAL-2024-1271
  • npm/web-ar-player
Malicious code in web-ar-player (npm)
  • See details.
2024-04-16T05:39:28Z No fix available