- CRITICAL9.6CVE-2026-45321⚠ KEVEPSS 17.1%Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
- CRITICAL9.9CVE-2025-68613⚠ KEVEPSS 65.8%n8n Vulnerable to Remote Code Execution via Expression Injection
- CRITICAL10.0CVE-2025-55182⚠ KEVEPSS 82.0%React Server Components are Vulnerable to RCE
- CRITICAL9.8CVE-2025-11953⚠ KEVEPSS 20.1%@react-native-community/cli has arbitrary OS command injection
- HIGH7.5CVE-2025-54313⚠ KEVEPSS 14.7%eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core, napi-postinstall have embedded malicious code
- MEDIUM5.3CVE-2025-31125⚠ KEVEPSS 83.2%Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
- HIGH8.8CVE-2023-5217⚠ KEVEPSS 5.0%Electron affected by libvpx's heap buffer overflow in vp8 encoding
- HIGH8.8CVE-2023-4863⚠ KEVEPSS 93.3%libwebp: OOB write in BuildHuffmanTable
- CRITICAL9.6CVE-2022-4135⚠ KEVEPSS 0.08%Heap buffer overflow in GPU
- HIGH7.8CVE-2021-21315⚠ KEVEPSS 94.0%Command Injection Vulnerability
- MEDIUM6.5CVE-2019-5786⚠ KEVEPSS 89.9%Use-After-Free in puppeteer
- MEDIUM6.9CVE-2020-11023⚠ KEVEPSS 34.7%Potential XSS vulnerability in jQuery
- CRITICAL9.9CVE-2019-10758⚠ KEVEPSS 94.4%Remote Code Execution Vulnerability in NPM mongo-express