boxscore/security
ECOSYSTEM · referenceEcosystems · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

npm

Package ecosystem npm. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDPackages affected
514828

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▂▅█▃

2025-11 1 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 6 · 2026-07 3 · 2026-08 12 · 2026-09 19 · 2026-10 6

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-119539.899.8KEVCommand injection in React Native Community CLI allows remote attackers to perform remo…
CVE-2026-559688.762.5—Apache Thrift: Node.js quadratic-time DoS in server receive transports
CVE-2024-343948.161.4—libxmljs2 namespaces type confusion RCE
CVE-2026-1024377.861.3—Improper Neutralization of Special Elements used in an OS Command ('OS Command Injectio…
CVE-2024-343938.160.5—libxmljs2 attrs type confusion RCE
CVE-2026-452496.159.2—Apache ECharts: XSS in Lines series tooltip rendering
CVE-2026-92779.255.9—shell-quote `quote()` does not validate object-token shapes, allowing command injection…
CVE-2026-568126.354.9—Phoenix JavaScript presence client crashes on presence keys colliding with Object.proto…
CVE-2026-474309.554.2—Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched with…
CVE-2026-936878.753.0—braces through 3.0.3 Stack Overflow via Deeply Nested Patterns
CVE-2026-920008.750.9—adm-zip 0.5.14 through 0.6.0 Denial of Service via Zero Declared Uncompressed Size
CVE-2026-936908.750.9—uri-js through 4.4.1 Denial of Service via removeDotSegments
CVE-2026-121438.750.2—form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF inje…
CVE-2026-142577.549.0—brace-expansion DoS via unbounded expansion length causing an out-of-memory process crash
CVE-2026-782068.748.4—exceljs through 4.4.0 Uncontrolled Resource Consumption via Unbounded xlsx Decompression
CVE-2026-782079.347.0—exceljs through 4.4.0 Prototype Pollution via deepMerge Reached From Note Serialization
CVE-2026-133118.746.6—shell-quote parse() is quadratic in token count, enabling denial of service
CVE-2026-54238.246.1—Subscription Authentication Bypass via Unverified connectionParams.jwt
CVE-2026-825626.343.5—qs.parse does not enforce arrayLimit on comma groups under bracket-push keys when throw…
CVE-2026-866008.241.5—Workload identity attestation generated before login host validation in Snowflake drivers

Most-affected packages

Packages with the most advisories
PackageCVEs
thrift7
exceljs4
shell-quote3
snowflake-sdk3
@neo4j/graphql2
adm-zip2
brace-expansion2
libxmljs22
qs2
9router1
@penpot/mcp1
@react-native-community/cli-server-api1
@vaadin/charts1
@vaadin/component-base1
angular1