CVE Tools

npm

5,579 CVEs tracked since 2010. Since Sep 2021, 8 of them reached CISA KEV.

npm CVEs per month

Sep 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
npm CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-09470
2021-10240
2021-11440
2021-12260
2022-01410
2022-02300
2022-03480
2022-04290
2022-05440
2022-06550
2022-07490
2022-08530
2022-09430
2022-10330
2022-11351
2022-12480
2023-01470
2023-02450
2023-03null or fewer
2023-04370
2023-05270
2023-06300
2023-07280
2023-08360
2023-09292
2023-10270
2023-11230
2023-12370
2024-01330
2024-02290
2024-03430
2024-04320
2024-05400
2024-06330
2024-07470
2024-08320
2024-09470
2024-10530
2024-11220
2024-12220
2025-01230
2025-02470
2025-03521
2025-04470
2025-05320
2025-06340
2025-07591
2025-08510
2025-091000
2025-10550
2025-11571
2025-12752
2026-011420
2026-022270
2026-035620
2026-043090
2026-05860
2026-06890
2026-071580
2026-08330
2026-09200

Products

The products that kept showing up in npm's monthly top three, with their CVEs summed over those months.

  1. Openclaw7036 months
  2. Flowise749 months
  3. N8N664 months
  4. Parse-server414 months
  5. Directus289 months
  6. @budibase/server191 month
  7. Nocodb173 months
  8. Fuxa-server152 months
  9. Flowise-components111 month
  10. Node-forge103 months

Latest CVEs

The 15 most recently published vulnerabilities affecting npm.

  1. GHSA-29h2-jr22-frmhOpenZeppelin Confidential Contracts `VestingWalletConfidential`: a malicious ERC-7984 token is able to extract private data from the vesting wallet—
  2. GHSA-5648-rgj9-v224@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS—
  3. GHSA-x7m8-jrm8-hpvx@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name—
  4. GHSA-wmmp-3585-3rmpNodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain—
  5. GHSA-2x7j-588g-ccc2Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list—
  6. GHSA-cc9r-2j5m-2m83Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain—
  7. GHSA-2q42-4q24-7rgvOpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree—
  8. GHSA-26w7-cxv4-gfx2Astro: Remote code execution through AVIF image optimization—
  9. GHSA-rgj7-g3m4-5g8csharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545—
  10. GHSA-j95f-988m-3j2fTiptap: Quadratic ReDoS in block and inline Markdown attribute parsing—
  11. GHSA-2xp9-vwfh-vxw4Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used—
  12. GHSA-8m3c-c648-2xjjNodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature—
  13. GHSA-7q9c-hpx7-9cwmTypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop—
  14. GHSA-6hxq-p678-4hr2SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor—
  15. GHSA-w8wf-3qvj-6xqfOpenClaw Feishu permission tools could ignore per-account disablement—

The record

Peak rank
#1 in Mar 2026
Busiest month shown
Mar 2026, 562 CVEs
Months with a KEV entry
6 since Sep 2021
Monthly snapshots
124 since 2010
npm's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store