Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
npm
Package ecosystem npm. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.
Totals
| CVEs all-time | CVEs YTD | Packages affected |
|---|---|---|
| 51 | 48 | 28 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▂▅█▃
2025-11 1 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 6 · 2026-07 3 · 2026-08 12 · 2026-09 19 · 2026-10 6
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-11953 | 9.8 | 99.8 | KEV | Command injection in React Native Community CLI allows remote attackers to perform remo… |
| CVE-2026-55968 | 8.7 | 62.5 | — | Apache Thrift: Node.js quadratic-time DoS in server receive transports |
| CVE-2024-34394 | 8.1 | 61.4 | — | libxmljs2 namespaces type confusion RCE |
| CVE-2026-102437 | 7.8 | 61.3 | — | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injectio… |
| CVE-2024-34393 | 8.1 | 60.5 | — | libxmljs2 attrs type confusion RCE |
| CVE-2026-45249 | 6.1 | 59.2 | — | Apache ECharts: XSS in Lines series tooltip rendering |
| CVE-2026-9277 | 9.2 | 55.9 | — | shell-quote `quote()` does not validate object-token shapes, allowing command injection… |
| CVE-2026-56812 | 6.3 | 54.9 | — | Phoenix JavaScript presence client crashes on presence keys colliding with Object.proto… |
| CVE-2026-47430 | 9.5 | 54.2 | — | Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched with… |
| CVE-2026-93687 | 8.7 | 53.0 | — | braces through 3.0.3 Stack Overflow via Deeply Nested Patterns |
| CVE-2026-92000 | 8.7 | 50.9 | — | adm-zip 0.5.14 through 0.6.0 Denial of Service via Zero Declared Uncompressed Size |
| CVE-2026-93690 | 8.7 | 50.9 | — | uri-js through 4.4.1 Denial of Service via removeDotSegments |
| CVE-2026-12143 | 8.7 | 50.2 | — | form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF inje… |
| CVE-2026-14257 | 7.5 | 49.0 | — | brace-expansion DoS via unbounded expansion length causing an out-of-memory process crash |
| CVE-2026-78206 | 8.7 | 48.4 | — | exceljs through 4.4.0 Uncontrolled Resource Consumption via Unbounded xlsx Decompression |
| CVE-2026-78207 | 9.3 | 47.0 | — | exceljs through 4.4.0 Prototype Pollution via deepMerge Reached From Note Serialization |
| CVE-2026-13311 | 8.7 | 46.6 | — | shell-quote parse() is quadratic in token count, enabling denial of service |
| CVE-2026-5423 | 8.2 | 46.1 | — | Subscription Authentication Bypass via Unverified connectionParams.jwt |
| CVE-2026-82562 | 6.3 | 43.5 | — | qs.parse does not enforce arrayLimit on comma groups under bracket-push keys when throw… |
| CVE-2026-86600 | 8.2 | 41.5 | — | Workload identity attestation generated before login host validation in Snowflake drivers |
Most-affected packages
| Package | CVEs |
|---|---|
| thrift | 7 |
| exceljs | 4 |
| shell-quote | 3 |
| snowflake-sdk | 3 |
| @neo4j/graphql | 2 |
| adm-zip | 2 |
| brace-expansion | 2 |
| libxmljs2 | 2 |
| qs | 2 |
| 9router | 1 |
| @penpot/mcp | 1 |
| @react-native-community/cli-server-api | 1 |
| @vaadin/charts | 1 |
| @vaadin/component-base | 1 |
| angular | 1 |