CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-102992 CRITICAL

piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadBalancer / env

CVSS 9.2 EPSS 0.55% Sep 30, 2026
npm
CVE-2026-102990 HIGH

basic-ftp: Quadratic-time CPU denial of service in Client.list() Unix directory-listing parser (RE_LINE backtracking)

CVSS 8.2 EPSS 0.51% Sep 30, 2026
npm
CVE-2026-55177 HIGH

CloudTAK: Authenticated full-read SSRF in /api/esri* routes — user-controlled URL fetched with no IP-classification guard

CVSS 7.6 EPSS 0.40% Sep 30, 2026
npm
CVE-2026-101896 HIGH

Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters

CVSS 8.2 EPSS n/a Sep 30, 2026
npm
CVE-2026-101899 MEDIUM

Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass for internal IP ranges

CVSS 6.9 EPSS n/a Sep 30, 2026
npm
CVE-2026-102984 HIGH

Astro: Malformed port in the Host header can crash the Node adapter

CVSS 8.2 EPSS 0.63% Sep 30, 2026
npm
CVE-2026-102983 MEDIUM

Astro: Netlify Image CDN allowlist bypass enables SSRF

CVSS 6.3 EPSS 0.54% Sep 30, 2026
npm
CVE-2026-102599 HIGH

Socket.IO: Engine.IO Protocol Revision Mismatch DoS

CVSS 7.5 EPSS n/a Sep 29, 2026
npm
CVE-2026-102282 HIGH

adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation

CVSS 7.1 EPSS n/a Sep 29, 2026
npm
CVE-2026-102677 HIGH

Electron: Sandboxed preload code cache can be poisoned by a compromised renderer

CVSS 7.8 EPSS 0.09% Sep 29, 2026
npm
CVE-2026-102672 MEDIUM

Electron: Local race condition in Squirrel.Mac update installation on macOS

CVSS 6.7 EPSS n/a Sep 29, 2026
npm
CVE-2026-102676 HIGH

Electron: <webview> can enable Node.js integration in Web Workers despite embedder restrictions

CVSS 8.3 EPSS 0.45% Sep 29, 2026
npm
CVE-2026-102675 HIGH

Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled

CVSS 7.4 EPSS 0.21% Sep 29, 2026
npm
CVE-2026-102674 HIGH

Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions

CVSS 8.2 EPSS 0.27% Sep 29, 2026
npm
CVE-2026-102673 HIGH

Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab

CVSS 8.2 EPSS 0.15% Sep 29, 2026
npm
CVE-2026-97711 LOW

Serialize JavaScript: Cross-site scripting (XSS) via unescaped </script> in serialized function bodies

CVSS 2.3 EPSS 0.30% Sep 29, 2026
npm
CVE-2026-101895 HIGH

Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE

CVSS 8.7 EPSS n/a Sep 28, 2026
npm
CVE-2026-102281 HIGH

Nest: Remote process termination via a deeply nested microservice message pattern

CVSS 7.5 EPSS 0.38% Sep 28, 2026
npm
CVE-2026-102278 HIGH

brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion

CVSS 7.5 EPSS 0.35% Sep 28, 2026
npm
CVE-2026-102277 MEDIUM

brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service

CVSS 5.3 EPSS 0.30% Sep 28, 2026
npm
CVE-2026-102276 HIGH

brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion

CVSS 7.5 EPSS 0.35% Sep 28, 2026
npm
CVE-2026-101916 HIGH

@grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized

CVSS 7.4 EPSS 0.21% Sep 28, 2026
npm
CVE-2026-101915 LOW

@grpc/grpc-js: The server transmits some error messages thrown by method handlers to the client in status messages

CVSS 3.7 EPSS 0.25% Sep 28, 2026
npm
CVE-2026-101914 MEDIUM

@grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches

CVSS 6.5 EPSS 0.25% Sep 28, 2026
npm
CVE-2026-101908 MEDIUM

Axios: Prototype pollution gadget in fetch adapter can alter outbound requests

CVSS 6.9 EPSS 0.41% Sep 28, 2026
npm

Showing 1 to 25 CVEs · page 1 (more available)