npm — vulnerability landscape

Every CVE-affected package in the npm ecosystem, sorted by risk.

Last updated 6/5/2026, 4:49:27 AM

#PackageCVEsKEVMax EPSS
1electron48393.3%
2n8n67165.8%
3vite20189.8%
4systeminformation13194.0%
5jquery8134.7%
6react-server-dom-webpack7182.0%
7react-server-dom-turbopack7182.0%
8react-server-dom-parcel7182.0%
9mongo-express4194.4%
10@tanstack/vue-router-ssr-query1117.1%
11@tanstack/react-router1117.1%
12@tanstack/router-generator1117.1%
13@tanstack/react-start-server1117.1%
14@tanstack/vue-start-server1117.1%
15@tanstack/router-devtools1117.1%
16@tanstack/solid-start1117.1%
17@tanstack/eslint-plugin-start1117.1%
18@tanstack/vue-start-client1117.1%
19@tanstack/solid-start-server1117.1%
20@tanstack/react-router-devtools1117.1%
21eslint-plugin-prettier1114.7%
22@tanstack/solid-router1117.1%
23@tanstack/router-ssr-query-core1117.1%
24@tanstack/valibot-adapter1117.1%
25@tanstack/zod-adapter1117.1%
26napi-postinstall1114.7%
27synckit1114.7%
28@tanstack/router-vite-plugin1117.1%
29@tanstack/react-start-client1117.1%
30@tanstack/solid-router-devtools1117.1%
31@tanstack/router-utils1117.1%
32@tanstack/start-static-server-functions1117.1%
33eslint-config-prettier1114.7%
34@tanstack/router-cli1117.1%
35@tanstack/router-core1117.1%
36@tanstack/vue-router-devtools1117.1%
37@tanstack/router-plugin1117.1%
38puppeteer1189.9%
39@tanstack/start-storage-context1117.1%
40@tanstack/history1117.1%
41@tanstack/vue-router1117.1%
42@tanstack/start-plugin-core1117.1%
43@tanstack/react-start-rsc1117.1%
44@tanstack/vue-start1117.1%
45@pkgr/core1114.7%
46@tanstack/arktype-adapter1117.1%
47@tanstack/solid-router-ssr-query1117.1%
48@react-native-community/cli-server-api1120.1%
49@tanstack/nitro-v2-vite-plugin1117.1%
50@tanstack/react-router-ssr-query1117.1%
51@tanstack/start-fn-stubs1117.1%
52@tanstack/solid-start-client1117.1%
53@tanstack/react-start1117.1%
54@tanstack/start-server-core1117.1%
55@tanstack/eslint-plugin-router1117.1%
56@tanstack/start-client-core1117.1%
57got-fetch1114.7%
58@react-native-community/cli1120.1%
59@tanstack/router-devtools-core1117.1%
60@tanstack/virtual-file-routes1117.1%
61openclaw4041.0%
62parse-server10875.6%
63flowise6387.7%
64directus530.9%
65next4792.8%
66vm24184.6%
67nocodb333.8%
68axios3013.1%
69hono261.7%
70@anthropic-ai/claude-code240.5%
71undici220.6%
72ghost2194.1%
73@openzeppelin/contracts190.9%
74fuxa-server1965.5%
75@openzeppelin/contracts-upgradeable180.9%
76astro1710.8%
77@haxtheweb/haxcms-nodejs164.0%
78sequelize153.5%
79tar1585.0%
80jspdf150.7%
81liquidjs150.3%
82ckeditor41565.5%
83joplin1415.3%
84tinymce145.1%
85nodebb1456.8%
86flowise-components141.2%
87@nyariv/sandboxjs141.5%
88signalk-server130.1%
89dompurify132.6%
90jsrsasign121.8%
91angular124.3%
92matrix-js-sdk120.9%
93@directus/api120.8%
94protobufjs121.7%
95strapi1294.0%
96pnpm121.7%
97svelte120.7%
98@evershop/evershop121.3%
99node-forge122.1%
100handlebars1224.8%
101react-router120.5%
102sillytavern112.6%
103@strapi/strapi1117.9%
104@oneuptime/common110.4%
105electerm110.8%
106apostrophe110.4%
107@lobehub/chat1173.3%
108marked111.1%
109bootstrap109.8%
110shescape101.1%
111sanitize-html101.8%
112fast-xml-parser100.9%
113payload101.0%
114fastify105.9%
115lodash1014.8%
116clawdbot100.2%
117@sveltejs/kit100.3%
118npm93.2%
119matrix-appservice-irc90.8%
120xmldom91.3%
121validator90.6%
122open-webui92.7%
123uptime-kuma965.7%
124next-auth90.9%
125mermaid90.5%
126lodash-es814.8%
127matrix-react-sdk80.8%
128steal80.5%
129@builder.io/qwik-city80.2%
130fast-jwt82.1%
131url-parse81.7%
132@xmldom/xmldom81.2%
133urijs80.6%
134elliptic83.9%
135editor.md80.5%
136@budibase/server80.3%
137locutus81.7%
138nuxt82.1%
139@astrojs/node75.1%
140studiocms70.1%
141jquery-ui731.2%
142mattermost-desktop71.5%
143@strapi/plugin-users-permissions791.0%
144snyk-broker70.6%
145simple-git741.7%
146hermes-engine71.6%
147mongoose755.3%
148qs71.5%
149@backstage/plugin-scaffolder-backend79.1%
150vega70.5%
151total.js753.3%
152tarteaucitronjs70.5%
153n8n-mcp70.1%
154@auth0/nextjs-auth070.6%
155multer70.2%
156swagger-ui680.4%
157bootstrap-sass69.8%
158hapi635.8%
159rsshub61.4%
160@frangoteam/fuxa693.4%
161prismjs61.8%
162@fedify/fedify60.4%
163parse-url60.4%
164express60.3%
165openpgp61.1%
166@angular/ssr60.1%
167@tinacms/cli66.5%
168aaptjs61.2%
169koa50.5%
170@keystone-6/core52.1%
171keystone59.8%
172katex50.5%
173minimatch50.5%
174serve50.7%
175better-auth50.3%
176happy-dom50.7%
177h350.1%
178safe-eval58.1%
179@steipete/summarize50.1%
180rendertron50.4%
181yarn51.0%
182seroval50.3%
183xlsx58.8%
184froala-editor52.2%
185ws566.1%
186@perfood/couch-auth50.1%
187vditor50.3%
188path-to-regexp50.3%
189oneuptime50.5%
190vega-functions50.5%
191auth0-js50.3%
192total4556.9%
193trix50.6%
194ua-parser-js52.6%
195ejs593.5%
196dojo543.2%
197@tinacms/graphql50.2%
198mysql2568.3%
199devalue50.2%
200convict51.7%
201mathjs51.7%
202lodash-amd514.8%
203budibase50.1%
204kysely40.1%
205brace-expansion40.5%
206langsmith40.0%
207jquery-validation41.1%
208jsonwebtoken437.5%
209@strapi/admin40.3%
210@intlify/vue-i18n-core40.5%
211hummus42.6%
212socket.io-parser40.8%
213snyk44.7%
214@hono/node-server40.5%
215@apollo/gateway40.6%
216serialize-javascript42.9%
217basic-ftp42.0%
218remarkable40.4%
219@saltcorn/server40.2%
220yui40.3%
221follow-redirects41.3%
222xdlocalstorage40.4%
223postcss40.3%
224@finos/git-proxy40.2%
225vue-i18n40.5%
226webpack41.6%
227@feathersjs/authentication-oauth40.1%
228webpack-dev-server40.2%
229petite-vue-i18n40.5%
230wrangler40.2%
231valine41.6%
232passport-wsfed-saml240.4%
233@fastify/middie40.1%
234parse-dashboard40.0%
235express-cart40.9%
236@actual-app/sync-server40.2%
237elysia40.2%
238engine.io44.1%
239nodemailer40.5%
240@node-saml/node-saml44.6%
241aws-iot-device-sdk-v240.3%
242tar-fs41.0%
243erxes484.5%
244auth0-lock40.8%
245moment43.1%
246mongosh40.4%
247meshcentral41.4%
248mcp-server-kubernetes40.3%
249mercurius40.4%
250muhammara42.6%
251convert-svg-core42.0%
252angular-expressions430.3%
253code-server40.4%
254@angular/core41.2%
255materialize-css40.3%
256@builder.io/qwik426.2%
257@budibase/backend-core40.1%
258@clerk/nextjs40.3%
259libxmljs44.1%
260@uppy/companion40.5%
261yapi-vendor40.4%
262browserify-shim30.6%
263@langchain/community30.1%
264keycloak-connect31.7%
265json-pointer31.0%
266@strapi/utils33.2%
267jose-node-cjs-runtime30.6%
268@strapi/core30.0%
269jose30.6%
270jose-node-esm-runtime30.6%
271@strapi/plugin-content-manager30.4%
272jointjs31.5%
273@jmondi/url-to-png30.4%
274layui31.7%
275@janhq/core373.6%
276stimulsoft-dashboards-js330.5%
277@intlify/core-base30.5%
278blamer34.7%
279immer30.5%
280@intlify/core30.5%
281socket.io30.4%
282snowflake-sdk30.6%
283http-proxy-middleware30.4%
284@adonisjs/bodyparser30.1%
285i18next-http-middleware30.1%
286slpjs30.4%
287simplehttpserver30.4%
288simple-markdown30.5%
289slp-validate30.4%
290set-in33.9%
291sm-crypto30.0%
292send34.8%
293samlify30.2%
294@sequelize/core30.4%
295grunt32.4%
296@samanhappy/mcphub30.6%
297glance30.7%
298safer-eval310.8%
299sails30.5%
300@backstage/plugin-techdocs-node30.0%