Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

HIGH 7.5
npm

CVE-2026-53950

XSS in Ghost's ActivityPub client

HIGH 7.5
npm

CVE-2026-69152

brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

HIGH 8.2
npm

GHSA-2p49-hgcm-8545

SVGO removeScripts plugin leaves some executable scripts intact

HIGH 7.5
npm

CVE-2026-18446

fast-uri vulnerable to host confusion via backslash authority introducer

HIGH 7.4
npm

CVE-2026-13697

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

HIGH 7.5
npm

CVE-2022-21680

Inefficient Regular Expression Complexity in marked

HIGH 7.5
npm

CVE-2022-21681

Inefficient Regular Expression Complexity in marked

HIGH 7.5
npm

CVE-2026-52746

jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion

HIGH 7.5
npm

CVE-2026-69185

Socket.IO: Zero-attachment Memory Exhaustion

HIGH 7.1
npm

CVE-2025-71400

Better Auth Passkey Plugin allows passkey deletion through IDOR

HIGH 8.6
npm

CVE-2025-71399

Better Auth's rou3 Dependency has Double-Slash Path Normalization which can Bypass disabledPaths Config and Rate Limits

HIGH 8.3
npm

CVE-2026-67331

@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers

HIGH 8.7
npm

CVE-2026-67336

Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default

HIGH 7.7
npm

CVE-2026-67333

Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp

HIGH 8.3
npm

CVE-2026-67327

Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in

HIGH 7.1
npm

CVE-2025-71403

Better Auth allows bypassing the trustedOrigins Protection which leads to ATO

HIGH 7.1
npm

CVE-2026-67329

@better-auth/stripe: cross-organization billing tampering in organization subscription actions

HIGH 8.7
npm

CVE-2026-53608

@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag

HIGH 7.5
npm

CVE-2026-59725

Socket.IO: Engine.IO Polling Transport Connection Exhaustion

HIGH 7.5
npm

CVE-2026-14257

brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash

HIGH 7.2
npm

CVE-2026-58263

Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier

HIGH 7.3
npm

CVE-2026-54737

@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging

HIGH 7.5
npm

GHSA-p7w7-4929-vpj5

`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation

HIGH 8.8
npm

CVE-2026-11572

degit has a Command Injection issue

HIGH 7.5
npm

GHSA-xmf8-cvqr-rfgj

Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers

HIGH 8.3
npm

CVE-2026-54666

swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies

HIGH 8.3
npm

CVE-2026-54661

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template

HIGH 8.3
npm

CVE-2026-54664

swagger-typescript-api vulnerable to code injection via unescaped enum string values

HIGH 7.4
npm

CVE-2026-54660

swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`

HIGH 8.3
npm

CVE-2026-54662

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template

HIGH 7.5
npm

CVE-2026-50272

dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS

HIGH 8.8
npm

CVE-2026-54639

Style Dictionary - Prototype Pollution in convertTokenData utility function

HIGH 7.5
npm

CVE-2026-13311

shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)

HIGH 7.1
npm

CVE-2026-54545

@wakaru/cli arbitrary file write during bundle unpack

HIGH 8.6
npm

CVE-2026-50131

Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges

HIGH 7.5
npm

CVE-2026-42342

React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint

HIGH 7.5
npm

GHSA-pm4m-ph32-ghv5

js-yaml: Exponential parsing time in flow collections leads to denial of service

HIGH 7.5
npm

GHSA-r28c-9q8g-f849

PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure

HIGH 7.5
npm

CVE-2026-45623

PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments

HIGH 7.5
npm

CVE-2026-59887

linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text

HIGH 8.5
npm

GHSA-v42f-v8xc-j435

Budibase: SSRF via DNS rebinding in the REST datasource integration

HIGH 7.5
npm

GHSA-g5vv-q72c-7j78

@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion

HIGH 7.1
npm

GHSA-pmpg-2mxq-6xwr

Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete

HIGH 7.7
npm

GHSA-pvcr-8mvp-w8qr

Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)

HIGH 8.5
npm

GHSA-xg5g-26x8-cvf4

Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution

HIGH 8.3
npm

GHSA-qw6m-8fw2-2v64

Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution

HIGH 7.7
npm

GHSA-xcx6-4f2g-hhgx

Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs

HIGH 7.5
npm

GHSA-hr66-5mqr-8mpx

Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint

HIGH 7.6
npm

GHSA-2xgg-r2wc-c5r2

Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector

HIGH 8.8
npm

GHSA-j9fc-w3mr-x6mv

Budibase: Privilege escalation via public role assignment API missing app-level authorization

HIGH 7.5
npm

CVE-2026-44907

react-server-dom: Denial of Service in Server Functions

HIGH 7.5
npm

CVE-2026-59892

OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header

HIGH 7.5
npm

CVE-2026-15074

@fastify/static vulnerable to route guard bypass via path traversal

HIGH 7.8
npm

CVE-2026-54672

electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`

HIGH 7.5
npm

CVE-2026-47219

find-my-way: DDoS with HTTP2

HIGH 7.5
npm

CVE-2026-59879

Immutable.js `List` 32-bit trie overflow → unrecoverable DoS

HIGH 7.5
npm

CVE-2026-16221

fast-uri vulnerable to host confusion via literal backslash authority delimiter

HIGH 8.8
npm

GHSA-2qp2-6frj-p9pq

Duplicate Advisory: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation

HIGH 7.5
npm

CVE-2026-59869

js-yaml: YAML merge-key chains can force quadratic CPU consumption

HIGH 7.3
npm

CVE-2026-13760

aws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling

Ready to move

Start Securing

Free, no credit card | First findings in minutes