npmjs records
18 published records for vendor npmjs.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 88.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-61 UNIX Symbolic Link (Symlink) Following3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-1333 Inefficient Regular Expression Complexity2
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-345 Insufficient Verification of Data Authenticity1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2021-43616Proof of concept | The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differnpmjs · npm · CWE-345 | Critical9.8 | — | 2.7% | Nov 13, 2021 |
35Monitor | CVE-2021-37701No exploit | Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic linksnpmjs · tar · CWE-22 | High8.6 | — | 3.3% | Aug 31, 2021 |
35Monitor | CVE-2021-37712No exploit | Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic linksnpmjs · tar · CWE-22 | High8.6 | — | 1.9% | Aug 31, 2021 |
34Monitor | CVE-2021-37713No exploit | Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitizationnpmjs · tar · CWE-22 | High8.6 | — | 1.3% | Aug 31, 2021 |
33Monitor | CVE-2019-16776No exploit | Unauthorized File Access in npm CLI before before version 6.13.3npmjs · npm · CWE-22 | High8.1 | — | 3.4% | Dec 12, 2019 |
32Monitor | CVE-2016-3956No exploit | The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 beforeibm · sdk · CWE-200 | High7.5 | — | 6.7% | Jul 2, 2016 |
31Monitor | CVE-2022-29244No exploit | npm packing does not respect root-level ignore files in workspacesnpmjs · npm · CWE-200 | High7.5 | — | 3.9% | Jun 13, 2022 |
31Monitor | CVE-2020-7754No exploit | Regular Expression Denial of Service (ReDoS)npmjs · npm-user-validate | High7.5 | — | 3.5% | Oct 27, 2020 |
31Monitor | CVE-2022-25883No exploit | Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when npmjs · semver · CWE-1333 | High7.5 | — | 2.8% | Jun 21, 2023 |
31Monitor | CVE-2021-39134No exploit | UNIX Symbolic Link (Symlink) Following in @npmcli/arboristnpmjs · arborist · CWE-61 | High7.8 | — | 0.6% | Aug 31, 2021 |
31Monitor | CVE-2021-39135No exploit | UNIX Symbolic Link (Symlink) Following in @npmcli/arboristnpmjs · arborist · CWE-61 | High7.8 | — | 0.6% | Aug 31, 2021 |
31Monitor | CVE-2018-7408No exploit | An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically installed by an "npm upgnpmjs · npm · CWE-732 | High7.8 | — | 0.3% | Feb 22, 2018 |
30Monitor | CVE-2024-21523No exploit | All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different fuCWE-400 | High7.5 | — | 0.6% | Jul 10, 2024 |
30Monitor | CVE-2024-25354No exploit | RegEx Denial of Service in domain-suffix 1.0.8 allows attackers to crash the application via crafted input to the parse function. | High7.5 | — | 0.6% | Mar 27, 2024 |
27Monitor | CVE-2019-16775No exploit | Unauthorized File Access in npm CLI before before version 6.13.3redhat · enterprise linux · CWE-61 | Medium6.5 | — | 3.3% | Dec 12, 2019 |
27Monitor | CVE-2019-16777No exploit | Arbitrary File Overwrite in npm CLInpmjs · npm · CWE-22 | Medium6.5 | — | 2.1% | Dec 12, 2019 |
22Monitor | CVE-2021-23362No exploit | Regular Expression Denial of Service (ReDoS)npmjs · hosted-git-info · CWE-1333 | Medium5.3 | — | 3.6% | Mar 23, 2021 |
17Monitor | CVE-2020-15095No exploit | Sensitive information exposure through logs in npm clinpmjs · npm · CWE-532 | Medium4.4 | — | 0.4% | Jul 7, 2020 |
- CVE-2021-4361640Plan
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differ
CriticalCVSS 9.8Proof of conceptEPSS 3%npmjs · npmNov 13, 2021
- CVE-2021-3770135Monitor
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links
HighCVSS 8.6No exploitEPSS 3%npmjs · tarAug 31, 2021
- CVE-2021-3771235Monitor
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links
HighCVSS 8.6No exploitEPSS 2%npmjs · tarAug 31, 2021
- CVE-2021-3771334Monitor
Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization
HighCVSS 8.6No exploitEPSS 1%npmjs · tarAug 31, 2021
- CVE-2019-1677633Monitor
Unauthorized File Access in npm CLI before before version 6.13.3
HighCVSS 8.1No exploitEPSS 3%npmjs · npmDec 12, 2019
- CVE-2016-395632Monitor
The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before
HighCVSS 7.5No exploitEPSS 7%ibm · sdkJul 2, 2016
- CVE-2022-2924431Monitor
npm packing does not respect root-level ignore files in workspaces
HighCVSS 7.5No exploitEPSS 4%npmjs · npmJun 13, 2022
- CVE-2020-775431Monitor
Regular Expression Denial of Service (ReDoS)
HighCVSS 7.5No exploitEPSS 3%npmjs · npm-user-validateOct 27, 2020
- CVE-2022-2588331Monitor
Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when
HighCVSS 7.5No exploitEPSS 3%npmjs · semverJun 21, 2023
- CVE-2021-3913431Monitor
UNIX Symbolic Link (Symlink) Following in @npmcli/arborist
HighCVSS 7.8No exploitEPSS 1%npmjs · arboristAug 31, 2021
- CVE-2021-3913531Monitor
UNIX Symbolic Link (Symlink) Following in @npmcli/arborist
HighCVSS 7.8No exploitEPSS 1%npmjs · arboristAug 31, 2021
- CVE-2018-740831Monitor
An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically installed by an "npm upg
HighCVSS 7.8No exploitEPSS 0%npmjs · npmFeb 22, 2018
- CVE-2024-2152330Monitor
All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different fu
HighCVSS 7.5No exploitEPSS 1%Jul 10, 2024
- CVE-2024-2535430Monitor
RegEx Denial of Service in domain-suffix 1.0.8 allows attackers to crash the application via crafted input to the parse function.
HighCVSS 7.5No exploitEPSS 1%Mar 27, 2024
- CVE-2019-1677527Monitor
Unauthorized File Access in npm CLI before before version 6.13.3
MediumCVSS 6.5No exploitEPSS 3%redhat · enterprise linuxDec 12, 2019
- CVE-2019-1677727Monitor
Arbitrary File Overwrite in npm CLI
MediumCVSS 6.5No exploitEPSS 2%npmjs · npmDec 12, 2019
- CVE-2021-2336222Monitor
Regular Expression Denial of Service (ReDoS)
MediumCVSS 5.3No exploitEPSS 4%npmjs · hosted-git-infoMar 23, 2021
- CVE-2020-1509517Monitor
Sensitive information exposure through logs in npm cli
MediumCVSS 4.4No exploitEPSS 0%npmjs · npmJul 7, 2020