Skip to content
Noroxi

npmjs records

18 published records for vendor npmjs.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
88.9%
Median publish → KEV
No record has entered KEV

All records

18 records
  • The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differ

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    npmjs · npmNov 13, 2021

  • Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links

    HighCVSS 8.6No exploitEPSS 3%

    npmjs · tarAug 31, 2021

  • Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links

    HighCVSS 8.6No exploitEPSS 2%

    npmjs · tarAug 31, 2021

  • Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization

    HighCVSS 8.6No exploitEPSS 1%

    npmjs · tarAug 31, 2021

  • Unauthorized File Access in npm CLI before before version 6.13.3

    HighCVSS 8.1No exploitEPSS 3%

    npmjs · npmDec 12, 2019

  • CVE-2016-3956
    32Monitor

    The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before

    HighCVSS 7.5No exploitEPSS 7%

    ibm · sdkJul 2, 2016

  • npm packing does not respect root-level ignore files in workspaces

    HighCVSS 7.5No exploitEPSS 4%

    npmjs · npmJun 13, 2022

  • CVE-2020-7754
    31Monitor

    Regular Expression Denial of Service (ReDoS)

    HighCVSS 7.5No exploitEPSS 3%

    npmjs · npm-user-validateOct 27, 2020

  • Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when

    HighCVSS 7.5No exploitEPSS 3%

    npmjs · semverJun 21, 2023

  • UNIX Symbolic Link (Symlink) Following in @npmcli/arborist

    HighCVSS 7.8No exploitEPSS 1%

    npmjs · arboristAug 31, 2021

  • UNIX Symbolic Link (Symlink) Following in @npmcli/arborist

    HighCVSS 7.8No exploitEPSS 1%

    npmjs · arboristAug 31, 2021

  • CVE-2018-7408
    31Monitor

    An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically installed by an "npm upg

    HighCVSS 7.8No exploitEPSS 0%

    npmjs · npmFeb 22, 2018

  • All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different fu

    HighCVSS 7.5No exploitEPSS 1%

    Jul 10, 2024

  • RegEx Denial of Service in domain-suffix 1.0.8 allows attackers to crash the application via crafted input to the parse function.

    HighCVSS 7.5No exploitEPSS 1%

    Mar 27, 2024

  • Unauthorized File Access in npm CLI before before version 6.13.3

    MediumCVSS 6.5No exploitEPSS 3%

    redhat · enterprise linuxDec 12, 2019

  • Arbitrary File Overwrite in npm CLI

    MediumCVSS 6.5No exploitEPSS 2%

    npmjs · npmDec 12, 2019

  • Regular Expression Denial of Service (ReDoS)

    MediumCVSS 5.3No exploitEPSS 4%

    npmjs · hosted-git-infoMar 23, 2021

  • Sensitive information exposure through logs in npm cli

    MediumCVSS 4.4No exploitEPSS 0%

    npmjs · npmJul 7, 2020