OsVault/npm/serve
npm21 critical

serve

534 known vulnerabilities · 21 critical · 96 high

CVE-2018-3809MEDIUM

Information Exposure on Case Insensitive File Systems in serve

Published Jul 18, 2018
CVE-2018-3712MEDIUM

Directory Traversal in serve

Published Jul 27, 2018
CVE-2019-5417HIGH

Directory Traversal in serve

Published Mar 25, 2019
CVE-2018-3718MEDIUM

vercel/serve allows access to restricted files if filename is URL encoded.

Published Aug 9, 2021
CVE-2021-43803HIGH

Unexpected server crash in Next.js.

Published Dec 7, 2021
GHSA-5j59-xgg2-r9c4

Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up

Published Dec 12, 2025
CVE-2017-16101HIGH

Directory Traversal in serverwg

Published Sep 1, 2020
CVE-2025-24360

Opening a malicious website while running a Nuxt dev server could allow read-only access to code

Published Jan 27, 2025
CVE-2026-32064

OpenClaw's andbox browser noVNC observer lacked VNC authentication

Published Mar 3, 2026
CVE-2026-5323MEDIUM
Risk: 26.5/100

a11y-mcp: Server-Side Request Forgery (SSRF) vulnerability in A11yServer function

Published Apr 2, 2026
MAL-2025-191053

Malicious code in @seezo/sdr-mcp-server (npm)

Published Nov 24, 2025
CVE-2022-39225MEDIUM

parse-server's session object properties can be updated by foreign user if object ID is known

Published Sep 21, 2022
CVE-2015-8856MEDIUM

Cross-Site Scripting in serve-index

Published Oct 24, 2017
CVE-2026-3089

Actual Sync Server has an Authenticated Path Traversal

Published Mar 10, 2026
CVE-2022-41878HIGH

Parse Server vulnerable to Prototype Pollution via Cloud Code Webhooks or Cloud Code Triggers

Published Nov 9, 2022
CVE-2017-16095HIGH

Directory Traversal in serverliujiayi1

Published Sep 1, 2020
CVE-2017-16201HIGH

Directory Traversal in zjjserver

Published Sep 1, 2020
CVE-2023-7078HIGH

Miniflare vulnerable to Server-Side Request Forgery (SSRF)

Published Dec 29, 2023
MAL-2025-191519

Malicious code in mongodb-stitch-server-testutils (npm)

Published Dec 1, 2025
MAL-2025-9264

Malicious code in @protos-team/frontend-server (npm)

Published Aug 14, 2025
CVE-2022-36079HIGH

Parse Server vulnerable to brute force guessing of user sensitive data via search patterns

Published Sep 16, 2022
CVE-2024-29027CRITICAL

Server crashes on invalid Cloud Function or Cloud Job name

Published Mar 19, 2024
CVE-2025-5276

Markdownify MCP Server allows Server-Side Request Forgery (SSRF) via the Markdownify.get() function

Published May 29, 2025
CVE-2021-40823MEDIUM

matrix-js-sdk can be tricked into disclosing E2EE room keys to a participating homeserver

Published Sep 14, 2021
GHSA-8g29-8xwr-qmhr

@grackle-ai/server JSON.parse lacks try-catch logic in its gRPC Service AdapterConfig Handling

Published Mar 25, 2026
CVE-2020-7683HIGH

Directory traversal in rollup-plugin-server

Published Jul 29, 2020
CVE-2020-26938HIGH

oauth2-server through 3.1.1 vulnerable to Open Redirect

Published Aug 30, 2022
CVE-2025-30359

webpack-dev-server users' source code may be stolen when they access a malicious web site

Published Jun 4, 2025
CVE-2022-23080MEDIUM

Server-Side Request Forgery in Directus

Published Jun 23, 2022
CVE-2020-5251HIGH

Information disclosure in parse-server

Published Mar 4, 2020
CVE-2026-33409

Parse Server has an auth provider validation bypass on login via partial authData

Published Mar 19, 2026
CVE-2026-28792

TinaCMS CLI Dev Server Vulnerable to Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS

Published Mar 12, 2026
MAL-2026-2991

Malicious code in pgserve (npm)

Published Apr 22, 2026
CVE-2025-53364

Parse Server exposes the data schema via GraphQL API

Published Jul 10, 2025
CVE-2020-7684HIGH

Path traversal in rollup-plugin-serve

Published May 18, 2021
CVE-2024-56159

Astro's server source code is exposed to the public if sourcemaps are enabled

Published Dec 19, 2024
GHSA-jhm7-29pj-4xvf

@node-oauth/oauth2-server: PKCE code_verifier ABNF not enforced in token exchange allows brute-force redemption of intercepted authorization codes

Published Apr 16, 2026
CVE-2014-10066HIGH

Directory Traversal in fancy-server

Published Aug 31, 2020
CVE-2026-30962

Parse Server has a protected fields bypass via logical query operators

Published Mar 11, 2026
CVE-2026-30947

Parse Server has a bypass of class-level permissions in LiveQuery

Published Mar 11, 2026
CVE-2026-27203

eBay API MCP Server Affected by Environment Variable Injection

Published Feb 19, 2026
CVE-2025-68272

Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request Flooding

Published Jan 2, 2026
CVE-2022-2216CRITICAL

Server-Side Request Forgery in parse-url

Published Jun 28, 2022
CVE-2022-25848HIGH

static-dev-server vulnerable to path traversal

Published Nov 29, 2022
CVE-2024-53983

Backstage Scaffolder plugin vulnerable to Server-Side Request Forgery

Published Dec 2, 2024
CVE-2020-7686HIGH

Directory traversal in rollup-plugin-server

Published Jul 29, 2020
CVE-2025-30360

webpack-dev-server users' source code may be stolen when they access a malicious web site with non-Chromium based browser

Published Jun 4, 2025
CVE-2018-3771MEDIUM

statics-server Cross-site Scripting vulnerability

Published May 13, 2022
CVE-2017-16147HIGH

Directory Traversal in shit-server

Published Sep 1, 2020
CVE-2026-22812

OpenCode's Unauthenticated HTTP Server Allows Arbitrary Command Execution

Published Jan 13, 2026
CVE-2025-64745

Astro development server error page is vulnerable to reflected Cross-site Scripting

Published Nov 13, 2025
CVE-2023-5572CRITICAL

Server-Side Request Forgery (SSRF) in vriteio/vrite

Published Oct 13, 2023
CVE-2026-32944

Parse Server crash via deeply nested query condition operators

Published Mar 17, 2026
GHSA-4xqg-gf5c-ghwq

MCP Server Kubernetes has an Argument Injection in port_forward tool via space-splitting

Published Apr 14, 2026
GHSA-45q2-gjvg-7973

Angular: SSRF via protocol-relative and backslash URLs in Angular Platform-Server

Published Apr 16, 2026
CVE-2024-39338HIGH

Server-Side Request Forgery in axios

Published Aug 12, 2024
CVE-2025-24010

Websites were able to send any requests to the development server and read the response in vite

Published Jan 21, 2025
CVE-2026-30229

parse-server's endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any user

Published Mar 6, 2026
GHSA-q4gf-8mx6-v5v3

Next.js has a Denial of Service with Server Components

Published Apr 10, 2026
CVE-2022-25931HIGH

easy-static-server vulnerable to Directory Traversal

Published Dec 20, 2022
CVE-2026-29772

Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands

Published Mar 24, 2026
CVE-2020-8134HIGH

Server-side request forgery in Ghost CMS

Published May 6, 2021
CVE-2022-36046MEDIUM

Unexpected server crash in Next.js

Published Aug 30, 2022
CVE-2017-16209HIGH

Directory Traversal in enserver

Published Sep 1, 2020
CVE-2026-32234

Parse Server has a SQL injection via query field name when using PostgreSQL

Published Mar 12, 2026
CVE-2026-33060

SSRF in @aborruso/ckan-mcp-server via base_url allows access to internal networks

Published Mar 18, 2026
CVE-2024-23340MEDIUM

@hono/node-server cannot handle "double dots" in URL

Published Jan 23, 2024
CVE-2026-28471

OpenClaw has a Matrix allowlist bypass via displayName and cross-homeserver localpart matching

Published Feb 17, 2026
CVE-2020-28360CRITICAL

Server-Side Request Forgery in private-ip

Published Apr 13, 2021
CVE-2024-47183

Parse Server's custom object ID allows to acquire role privileges

Published Oct 4, 2024
CVE-2026-31901

Parse Server vulnerable to user enumeration via email verification endpoint

Published Mar 11, 2026
CVE-2016-10650HIGH

Downloads Resources over HTTP in ntfserver

Published Feb 18, 2019
GHSA-wr4h-v87w-p3r7

h3 has a Path Traversal via Percent-Encoded Dot Segments in serveStatic Allows Arbitrary File Read

Published Mar 18, 2026
CVE-2021-3810HIGH

Inefficient Regular Expression Complexity in code-server

Published Sep 20, 2021
CVE-2026-30854

Parse Server: GraphQL `__type` introspection bypass via inline fragments when public introspection is disabled

Published Mar 9, 2026
CVE-2020-36651MEDIUM

Path Traversal in web-node-server

Published Jan 18, 2023
CVE-2023-46119HIGH

Parse Server may crash when uploading file without extension

Published Oct 24, 2023
CVE-2025-68467

Dark Reader gives users the ability to request style sheets from local web servers

Published Mar 4, 2026
CVE-2026-33421

Parse Server's LiveQuery bypasses CLP pointer permission enforcement

Published Mar 20, 2026
CVE-2025-68273

Signal K Server Vulnerable to Unauthenticated Information Disclosure via Exposed Endpoints

Published Jan 2, 2026
CVE-2026-31875

Parse Server's MFA recovery codes not consumed after use

Published Mar 11, 2026
CVE-2025-53355

MCP Server Kubernetes vulnerable to command injection in several tools

Published Jul 8, 2025
CVE-2021-23682HIGH

Prototype Pollution in litespeed.js and appwrite/server-ce

Published Feb 17, 2022
CVE-2025-59155

HackMD MCP Server has Server-Side Request Forgery (SSRF) vulnerability

Published Sep 15, 2025
CVE-2026-24473

Hono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)

Published Jan 27, 2026
CVE-2018-3726MEDIUM

Cross-site Scripting (XSS) - Stored in crud-file-server

Published Jul 18, 2018
CVE-2018-3713MEDIUM

Path Traversal in angular-http-server

Published Jul 26, 2018
CVE-2017-16197HIGH

Directory Traversal in qinserve

Published Sep 1, 2020
CVE-2021-42648MEDIUM

Cross site scripting in code-server

Published May 12, 2022
CVE-2026-32770

Parse Server LiveQuery subscription with invalid regular expression crashes server

Published Mar 17, 2026
CVE-2020-8128CRITICAL

Server-Side Request Forgery and Inclusion of Functionality from Untrusted Control Sphere in jsreport

Published Apr 13, 2021
CVE-2021-23430HIGH

Directory Traversal in startserver

Published Sep 2, 2021
MAL-2022-5764

Malicious code in resize-observe (npm)

Published Jun 20, 2022
MAL-2022-7155

Malicious code in wise_lena_bot_server (npm)

Published Jun 20, 2022
CVE-2019-5457MEDIUM

Cross-Site Scripting in min-http-server

Published Jul 31, 2019
CVE-2025-47828

@lumieducation/h5p-server Fails to Sanitize Plain Text Strings

Published May 11, 2025
MAL-2022-3255

Malicious code in fxa-admin-server (npm)

Published Jun 20, 2022
CVE-2025-15104

Nu Html Checker (vnu) contains a Server-Side Request Forgery (SSRF) vulnerability

Published Jan 16, 2026
GHSA-fmh4-wr37-44fp

React Server Components are Vulnerable to RCE

Published Dec 3, 2025
CVE-2026-27942

fast-xml-parser has stack overflow in XMLBuilder with preserveOrder

Published Feb 26, 2026
CVE-2026-30925

Parse Server has Regular Expression Denial of Service (ReDoS) via `$regex` query in LiveQuery

Published Mar 10, 2026
CVE-2014-10068HIGH

Hidden Directories Always Served in inert

Published Aug 31, 2020
CVE-2026-32742

Parse Server session creation endpoint allows overwriting server-generated session fields

Published Mar 17, 2026
CVE-2017-16105HIGH

Directory Traversal in serverwzl

Published Sep 1, 2020
CVE-2017-16158HIGH

Directory Traversal in dcserver

Published Sep 1, 2020
CVE-2019-5458MEDIUM

Cross-Site Scripting in http-file-server

Published Jul 31, 2019
CVE-2020-7747MEDIUM

Cross-site Scripting in lightning-server

Published May 10, 2021
CVE-2018-3787HIGH

simplehttpserver allows directory traversal and file listing

Published Sep 6, 2018
CVE-2025-11285

MCPHub's ServerController is vulnerable to Command Injection

Published Oct 5, 2025
CVE-2026-27524

OpenClaw's runtime /debug override path accepted prototype-reserved keys

Published Mar 3, 2026
CVE-2026-30966

Parse Server has role escalation and CLP bypass via direct `_Join` table write

Published Mar 11, 2026
GHSA-5j35-xr4g-vwf4

@grackle-ai/server has a Missing Secure Flag on Session Cookie

Published Mar 25, 2026
CVE-2017-16124HIGH

Directory Traversal in node-server-forfront

Published Jul 23, 2018
CVE-2017-16035HIGH

hubl-server downloads resources over HTTP

Published Jul 24, 2018
GHSA-pqhr-mp3f-hrpp

Nuxt OG Image vulnerable to Server-Side Request Forgery via user-controlled parameters

Published Mar 31, 2026
CVE-2026-30939

Parse Server has Denial of Service (DoS) and Cloud Function Dispatch Bypass via Prototype Chain Resolution

Published Mar 10, 2026
CVE-2026-32594

Parse Server's GraphQL WebSocket endpoint bypasses security middleware

Published Mar 13, 2026
MAL-2025-2151

Malicious code in dexter-server (npm)

Published Mar 5, 2025
CVE-2026-30850

Parse Server: File metadata endpoint bypasses `beforeFind` / `afterFind` trigger authorization

Published Mar 9, 2026
CVE-2026-31856

Parse Server vulnerable to SQL injection via `Increment` operation on nested object field in PostgreSQL

Published Mar 11, 2026
CVE-2023-49293MEDIUM

Vite XSS vulnerability in `server.transformIndexHtml` via URL payload

Published Dec 5, 2023
CVE-2023-26492MEDIUM

Directus vulnerable to Server-Side Request Forgery On File Import

Published Mar 3, 2023
CVE-2022-2900CRITICAL

Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url

Published Sep 15, 2022
CVE-2026-32269

Parse Server OAuth2 adapter app ID validation sends wrong token to introspection endpoint

Published Mar 13, 2026
CVE-2025-9611

Microsoft Playwright MCP Server vulnerable to DNS Rebinding Attack; Allows Attackers Access to All Server Tools

Published Jan 7, 2026
CVE-2017-16148HIGH

Directory Traversal in serve46

Published Sep 1, 2020
CVE-2025-67419

evershop allows unauthenticated attackers to exhaust application server's resources via "GET /images" API

Published Jan 5, 2026
CVE-2020-36851

cors-anywhere vulnerable to server-side request forgery

Published Sep 25, 2025
CVE-2024-31207MEDIUM

Vite's `server.fs.deny` did not deny requests for patterns with directories.

Published Apr 3, 2024
MAL-2025-3054

Malicious code in @hongfangze/simple-resource-server (npm)

Published Apr 2, 2025
GHSA-72gr-qfp7-vwhw

h3: Double Decoding in `serveStatic` Bypasses `resolveDotSegments` Path Traversal Protection via `%252e%252e`

Published Mar 20, 2026
CVE-2026-32878

Parse Server vulnerable to schema poisoning via prototype pollution in deep copy

Published Mar 17, 2026
CVE-2023-28155MEDIUM

Server-Side Request Forgery in Request

Published Mar 16, 2023
CVE-2024-27298CRITICAL

ZDI-CAN-19105: Parse Server literalizeRegexPart SQL Injection

Published Mar 1, 2024
CVE-2026-30941

Parse Server has a NoSQL injection via token type in password reset and email verification endpoints

Published Mar 11, 2026
CVE-2021-32738MEDIUM

Utils.readChallengeTx does not verify the server account signature

Published Jul 2, 2021
CVE-2026-27638

@actual-app/sync-server: Missing authorization in sync endpoints allows cross-user budget file access in multi-user mode

Published Feb 27, 2026
CVE-2026-25528

LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection

Published Feb 9, 2026
CVE-2025-53818

GitHub Kanban MCP Server vulnerable to Command Injection

Published Jul 15, 2025
GHSA-v2wj-q39q-566r

Vite: `server.fs.deny` bypassed with queries

Published Apr 6, 2026
CVE-2026-33508

Parse Server LiveQuery subscription query depth bypass

Published Mar 20, 2026
GHSA-6qvv-pj99-48qm

@adonisjs/http-server has an Open Redirect vulnerability

Published Apr 14, 2026
CVE-2026-30965

Parse Server vulnerable to session token exfiltration via `redirectClassNameForKey` query parameter

Published Mar 11, 2026
CVE-2025-6514

mcp-remote exposed to OS command injection via untrusted MCP server connections

Published Jul 9, 2025
CVE-2025-1520

PostHog Plugin Server SQL Injection Vulnerability

Published Apr 23, 2025
CVE-2026-25041

@budibase/server: Command Injection in PostgreSQL Dump Command

Published Mar 9, 2026
CVE-2017-16165HIGH

Directory Traversal in calmquist.static-server

Published Jul 23, 2018
MAL-2022-2352

Malicious code in datadog-serverless-macro (npm)

Published Jun 20, 2022
CVE-2026-25228

SignalK Server has Path Traversal leading to information disclosure

Published Feb 2, 2026
CVE-2017-16210HIGH

Directory Traversal in jn_jj_server

Published Jul 23, 2018
CVE-2025-30208

Vite bypasses server.fs.deny when using ?raw??

Published Mar 25, 2025
CVE-2025-67779

Denial of Service Vulnerability in React Server Components

Published Dec 12, 2025
MAL-2022-4618

Malicious code in mitui-base-server (npm)

Published Jun 20, 2022
CVE-2017-16182HIGH

Directory Traversal in serverxxx

Published Jul 23, 2018
GHSA-x8rx-789c-2pxq

RedwoodSDK has a CSRF vulnerability in server function dispatch via GET requests

Published Apr 8, 2026
CVE-2026-3484

MCP NMAP Server has an Injection vulnerability

Published Mar 3, 2026
CVE-2024-56332

Next.js Allows a Denial of Service (DoS) with Server Actions

Published Jan 3, 2025
CVE-2026-31828

Parse Server vulnerable to LDAP injection via unsanitized user input in DN and group filter construction

Published Mar 11, 2026
CVE-2019-5444MEDIUM

Path Traversal in serve-here.js

Published Sep 22, 2021
GHSA-7q9x-8g6p-3x75

@grackle-ai/server: Unescaped Error String in renderPairingPage() HTML Template

Published Mar 25, 2026
CVE-2026-33042

Parse Server affected by empty authData bypassing credential requirement on signup

Published Mar 17, 2026
CVE-2026-33624

Parse Server: MFA recovery code single-use bypass via concurrent requests

Published Mar 24, 2026
CVE-2025-5273

Markdownify MCP Server allows attackers to read arbitrary files

Published May 29, 2025
CVE-2019-1020012HIGH

Parse Server before v3.4.1 vulnerable to Denial of Service

Published Jun 13, 2019
CVE-2017-18924HIGH

Code Injection in oauth2-server

Published Apr 22, 2021
CVE-2023-22621HIGH

Strapi plugins vulnerable to Server-Side Template Injection and Remote Code Execution in the Users-Permissions Plugin

Published Apr 19, 2023
CVE-2026-2178

xcode-mcp-server vulnerable to Command Injection

Published Feb 8, 2026
CVE-2018-16485MEDIUM

m-server Vulnerable to Directory Traversal

Published Feb 18, 2019
CVE-2025-30168

Parse Server has an OAuth login vulnerability

Published Mar 21, 2025
CVE-2025-46565

Vite's server.fs.deny bypassed with /. for files under project root

Published Apr 30, 2025
CVE-2026-25536

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

Published Feb 4, 2026
MAL-2022-1678

Malicious code in breakout-chat-server (npm)

Published Jun 20, 2022
CVE-2025-32395

Vite has an `server.fs.deny` bypass with an invalid `request-target`

Published Apr 11, 2025
CVE-2025-62522

vite allows server.fs.deny bypass via backslash on Windows

Published Oct 20, 2025
CVE-2025-68150

Parse Server is vulnerable to Server-Side Request Forgery (SSRF) via Instagram OAuth Adapter

Published Dec 16, 2025
MAL-2023-7992

Malicious code in pingserver-test.01 (npm)

Published Sep 3, 2023
GHSA-3mjm-x6gw-2x42

@grackle-ai/server has Missing Content-Security-Policy and X-Frame-Options Headers

Published Mar 25, 2026
CVE-2025-53107

@cyanheads/git-mcp-server vulnerable to command injection in several tools

Published Jun 30, 2025
CVE-2018-16493HIGH

Path Traversal in simplehttpserver

Published Feb 7, 2019
MAL-2022-30

Malicious code in 47cliens_server (npm)

Published Jun 20, 2022
GHSA-92pp-h63x-v22m

@hono/node-server: Middleware bypass via repeated slashes in serveStatic

Published Apr 8, 2026
MAL-2022-3257

Malicious code in fxa-profile-server (npm)

Published Jun 20, 2022
CVE-2025-68619

Signal K Server Vulnerable to Remote Code Execution via Malicious npm Package

Published Jan 2, 2026
CVE-2026-32728

Parse Server has a stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entries

Published Mar 16, 2026
GHSA-43fj-qp3h-hrh5

Sync-in Server has Username Enumeration via Timing Attack

Published Apr 15, 2026
MAL-2022-5966

Malicious code in scilla-server (npm)

Published Jun 8, 2022
CVE-2023-36475CRITICAL

Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution

Published Jun 30, 2023
CVE-2026-33226

Budibase Unrestricted Server-Side Request Forgery (SSRF) via REST Datasource Query Preview

Published Mar 18, 2026
CVE-2026-30949

Parse Server missing audience validation in Keycloak authentication adapter

Published Mar 11, 2026
CVE-2026-33498

Parse Server has a query condition depth bypass via pre-validation transform pipeline

Published Mar 20, 2026
CVE-2020-28168MEDIUM

Axios vulnerable to Server-Side Request Forgery

Published Jan 4, 2021
CVE-2020-26288HIGH

Parse Server stores password in plain text

Published Dec 28, 2020
CVE-2017-16152HIGH

Directory Traversal in static-html-server

Published Jul 23, 2018
CVE-2020-8205HIGH

Server-Side Request Forgery in @uppy/companion

Published Aug 13, 2020
CVE-2026-30827

express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting on servers with dual-stack network

Published Mar 6, 2026
MAL-2023-8339

Malicious code in fas_elbridge_server (npm)

Published Oct 12, 2023
MAL-2025-146

Malicious code in showcase-server (npm)

Published Jan 20, 2025
MAL-2022-780

Malicious code in @xvideos/server (npm)

Published Jun 20, 2022
CVE-2024-45811MEDIUM

Vite's `server.fs.deny` is bypassed when using `?import&raw`

Published Sep 17, 2024
CVE-2025-67438

Sync-in Server has a stored cross-site scripting (XSS) vulnerability

Published Feb 20, 2026
CVE-2024-39309CRITICAL

ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability

Published Jul 1, 2024
CVE-2026-33128

h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields

Published Mar 18, 2026
CVE-2025-53372

Node.js Sandbox MCP Server vulnerability can lead to Sandbox Escape via Command Injection

Published Jul 8, 2025
GHSA-9q82-xgwf-vj6h

Apollo Server: Browser bug allows for bypass of XS-Search (read-only Cross-Site Request Forgery) prevention

Published Mar 26, 2026
CVE-2025-68620

Signal K Server vulnerable to JWT Token Theft via WebSocket Enumeration and Unauthenticated Polling

Published Jan 2, 2026
MAL-2023-8603

Malicious code in serverless-provisioned-memory-report (npm)

Published Nov 23, 2023
CVE-2017-16196HIGH

Directory Traversal in quickserver

Published Jul 23, 2018
CVE-2017-16055HIGH

sqlserver is malware

Published Nov 9, 2018
CVE-2021-45851HIGH

Server-Side Request Forgery in FUXA

Published Mar 17, 2022
CVE-2017-16191HIGH

Directory Traversal in cypserver

Published Sep 1, 2020
MAL-2025-190801

Malicious code in @asyncapi/server-api (npm)

Published Nov 24, 2025
CVE-2019-15596HIGH

Path Traversal in statics-server

Published Mar 31, 2020
CVE-2017-16085HIGH

Directory Traversal in tinyserver2

Published Jul 24, 2018
CVE-2026-30946

Parse Server affected by denial-of-service via unbounded query complexity in REST and GraphQL API

Published Mar 11, 2026
CVE-2026-27148

Storybook Dev Server is Vulnerable to WebSocket Hijacking

Published Feb 26, 2026
MAL-2024-10669

Malicious code in http-long-poll-server (npm)

Published Nov 13, 2024
CVE-2026-22030

React Router has CSRF issue in Action/Server Action Request Processing

Published Jan 8, 2026
CVE-2024-23331HIGH

Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem

Published Jan 19, 2024
GHSA-g4v2-qx3q-4p64

Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields`

Published Apr 8, 2026
CVE-2015-1164MEDIUM

Open Redirect in serve-static

Published Aug 31, 2020
CVE-2023-32688MEDIUM

Invalid push request payload crashes Parse Server

Published May 22, 2023
CVE-2022-24760CRITICAL

Command injection in Parse Server through prototype pollution

Published Mar 11, 2022
CVE-2025-66405

Portkey.ai Gateway: Server-Side Request Forgery (SSRF) in Custom Host

Published Dec 2, 2025
GHSA-p7mm-r948-4q3q

Paperclip: Approval decision attribution spoofing via client-controlled `decidedByUserId` in paperclip server

Published Apr 16, 2026
CVE-2025-64430

Parse Server Vulnerable to Server-Side Request Forgery (SSRF) in File Upload via URI Format

Published Nov 5, 2025
CVE-2018-14732HIGH

Missing Origin Validation in webpack-dev-server

Published Jan 4, 2019
MAL-2024-10563

Malicious code in nfs-server-alpine (npm)

Published Nov 8, 2024
CVE-2024-43800MEDIUM

serve-static vulnerable to template injection that can lead to XSS

Published Sep 10, 2024
CVE-2025-64496

Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events

Published Nov 7, 2025
CVE-2022-0508MEDIUM

Server-Side Request Forgery in @peertube/embed-api

Published Feb 9, 2022
CVE-2022-39231LOW

parse-server auth adapter app ID validation can be circumvented

Published Sep 21, 2022
CVE-2026-30967

Parse Server OAuth2 authentication adapter account takeover via identity spoofing

Published Mar 11, 2026
CVE-2019-15600HIGH

Cross-Site Scripting in http_server

Published Mar 31, 2020
CVE-2017-16102HIGH

Directory Traversal in serverhuwenhui

Published Sep 1, 2020
GHSA-7gcj-phff-2884

Signal K Server has an Unauthenticated Regular Expression Denial of Service (ReDoS) via WebSocket Subscription Paths

Published Apr 21, 2026
GHSA-v457-wxvj-p9w9

@vitejs/plugin-rsc has a Denial of Service with React Server Components

Published Apr 10, 2026
CVE-2017-16142HIGH

Directory Traversal in infraserver

Published Jul 23, 2018
CVE-2025-67427

evershop allows unauthenticated attackers to force server to initiate HTTP request via "GET /images" API

Published Jan 5, 2026
CVE-2026-31800

Parse Server: Classes `_GraphQLConfig` and `_Audience` master key bypass via generic class routes

Published Mar 11, 2026
CVE-2024-34351HIGH

Next.js Server-Side Request Forgery in Server Actions

Published May 9, 2024
CVE-2023-26104HIGH

Denial of Service vulnerability in lite-web-server

Published Feb 25, 2023
CVE-2023-26114HIGH

code-server vulnerable to Missing Origin Validation in WebSockets

Published Mar 23, 2023
CVE-2025-66404

mcp-server-kubernetes has potential security issue in exec_in_pod tool

Published Dec 3, 2025
CVE-2026-23864

React Server Components have multiple Denial of Service Vulnerabilities

Published Jan 29, 2026
CVE-2021-23797HIGH

Path Traversal in http-server-node

Published Jan 5, 2022
CVE-2026-30848

Parse Server: `PagesRouter` path traversal allows reading files outside configured pages directory

Published Mar 9, 2026
CVE-2025-31486

Vite allows server.fs.deny to be bypassed with .svg or relative paths

Published Apr 4, 2025
CVE-2026-33538

Parse Server: Denial of Service via unindexed database query for unconfigured auth providers

Published Mar 24, 2026
CVE-2026-30948

Parse Server vulnerable to stored cross-site scripting (XSS) via SVG file upload

Published Mar 11, 2026
CVE-2020-7740HIGH

Server-Side Request Forgery in node-pdf-generator

Published May 10, 2021
CVE-2017-16038HIGH

Directory Traversal in f2e-server

Published Jul 24, 2018
MAL-2025-191052

Malicious code in @relyt/mcp-server-relytone (npm)

Published Nov 24, 2025
CVE-2019-1020013MEDIUM

Sensitive Data Exposure in parse-server

Published Jul 11, 2019
CVE-2025-55183

Source Code Exposure Vulnerability in React Server Components

Published Dec 11, 2025
CVE-2022-41879HIGH

Parse Server is vulnerable to Prototype Pollution via Cloud Code Webhooks

Published Nov 10, 2022
MAL-2022-1543

Malicious code in bfx-lib-server-js (npm)

Published Jun 20, 2022
CVE-2017-16171HIGH

Directory Traversal in hcbserver

Published Sep 1, 2020
CVE-2026-28787

OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing credential replay

Published Mar 2, 2026
MAL-2025-2254

Malicious code in ee-server-auth-nodejs (npm)

Published Mar 11, 2025
CVE-2026-30835

parse-server: Malformed `$regex` query leaks database error details in API response

Published Mar 6, 2026
MAL-2026-2646

Malicious code in okfe-serverless-conf (npm)

Published Apr 14, 2026
CVE-2026-33539

Parse Server has SQL Injection through aggregate and distinct field names in PostgreSQL adapter

Published Mar 24, 2026
CVE-2023-34238MEDIUM

Gatsby develop server has Local File Inclusion vulnerability

Published Jun 9, 2023
GHSA-c6m7-q6pr-c64r

Vite Plugin React has a Source Code Exposure Vulnerability in React Server Components

Published Dec 12, 2025
GHSA-cpqf-f22c-r95x

Vite Plugin React has a Denial of Service Vulnerability in React Server Components

Published Dec 12, 2025
MAL-2026-1622

Malicious code in @f5rest/odata-v4-server (npm)

Published Mar 18, 2026
CVE-2026-34083MEDIUM
Risk: 30.5/100

Signal K Server: OAuth Authorization Code Theft via Unvalidated Host Header in OIDC Flow

Published Apr 3, 2026
CVE-2025-9862

Ghost vulnerable to Server Side Request Forgery (SSRF) via oEmbed Bookmark

Published Sep 15, 2025
CVE-2025-68115

Parse Server has a Cross-Site Scripting (XSS) vulnerability via Unescaped Mustache Template Variables

Published Dec 16, 2025
MAL-2025-4881

Malicious code in server-bare-log (npm)

Published Jun 10, 2025
CVE-2022-25876MEDIUM

Server-Side Request Forgery in link-preview-js

Published Jul 2, 2022
CVE-2025-55182

React Server Components are Vulnerable to RCE

Published Dec 3, 2025
MAL-2025-5820

Malicious code in preview-server-auth (npm)

Published Jul 10, 2025
GHSA-mmpq-5hcv-hf2v

Parse Server has a login timing side-channel reveals user existence

Published Apr 8, 2026
CVE-2025-58751

Vite middleware may serve files starting with the same name with the public directory

Published Sep 9, 2025
MAL-2023-8532

Malicious code in jobserver (npm)

Published Nov 18, 2023
MAL-2025-48540

Malicious code in @jd-org/clear-server (npm)

Published Oct 21, 2025
CVE-2026-33951
Risk: 0.09/100

Signal K Server: Unauthenticated Source Priorities Manipulation

Published Apr 3, 2026
CVE-2020-15152CRITICAL

Server-Side Request Forgery in ftp-srv

Published Aug 17, 2020
MAL-2025-2675

Malicious code in gson-server (npm)

Published Mar 25, 2025
CVE-2026-27567

Payload: Server-Side Request Forgery (SSRF) in External File URL Uploads

Published Feb 24, 2026
CVE-2026-31871

Parse Server vulnerable to SQL Injection via dot-notation sub-key name in `Increment` operation on PostgreSQL

Published Mar 11, 2026
CVE-2023-28444CRITICAL

angular-server-side-configuration information disclosure vulnerability in monorepo with node.js backend

Published Mar 24, 2023
CVE-2022-39313HIGH

parse-server crashes when receiving file download request with invalid byte range

Published Oct 18, 2022
MAL-2022-3077

Malicious code in flipper-server-companion (npm)

Published Jul 29, 2022
MAL-2025-3167

Malicious code in xnil-server (npm)

Published Apr 7, 2025
CVE-2026-32098

Parse Server has a protected fields bypass via LiveQuery subscription WHERE clause

Published Mar 12, 2026
CVE-2020-7739HIGH

Server-Side Request Forgery in phantomjs-seo

Published May 10, 2021
CVE-2026-33527

Parse Server's Session Update endpoint allows overwriting server-generated session fields

Published Mar 24, 2026
MAL-2025-3842

Malicious code in nayan-apis-server (npm)

Published May 15, 2025
CVE-2026-30938

Parse Server has denylist `requestKeywordDenylist` keyword scan bypass through nested object placement

Published Mar 10, 2026
CVE-2026-33429

Parse Server has a protected field change detection oracle via LiveQuery watch parameter

Published Mar 20, 2026
CVE-2022-31830CRITICAL

Server-Side Request Forgery in kityminder

Published Jun 10, 2022
MAL-2025-4036

Malicious code in vue-dev-serverr (npm)

Published May 19, 2025
CVE-2026-31840

Parse Server: SQL injection via dot-notation field name in PostgreSQL

Published Mar 10, 2026
CVE-2017-16103HIGH

Directory Traversal in serveryztyzt

Published Sep 1, 2020
MAL-2026-945

Malicious code in ui5-cap-event-app-server (npm)

Published Feb 18, 2026
CVE-2017-16185HIGH

Directory Traversal in uekw1511server

Published Sep 1, 2020
GHSA-qrmm-w75w-3wpx

Server side request forgery in SwaggerUI

Published Dec 9, 2021
CVE-2026-30587

Seafile Server has multiple stored XSS vulnerabilities

Published Mar 25, 2026
CVE-2021-23664HIGH

Server side request forgery in @isomorphic-git/cors-proxy

Published Jan 26, 2022
MAL-2025-5062

Malicious code in truth-loop-server (npm)

Published Jun 10, 2025
CVE-2017-16146HIGH

Directory Traversal in mockserve

Published Jul 23, 2018
CVE-2026-35038
Risk: 0.03/100

Signal K Server: Arbitrary Prototype Read via `from` Field Bypass

Published Apr 3, 2026
CVE-2023-22474HIGH

Parse Server option `masterKeyIps` vulnerability to IP spoofing

Published Jan 31, 2023
CVE-2026-2229

Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation

Published Mar 13, 2026
CVE-2018-3733HIGH

Path Traversal in crud-file-server

Published Jul 18, 2018
CVE-2026-32943

Parse Server has a password reset token single-use bypass via concurrent requests

Published Mar 17, 2026
MAL-2025-191536

Malicious code in @wxi-dev/serverless-tsc-config (npm)

Published Dec 2, 2025
CVE-2017-16144HIGH

Directory Traversal in myserver.alexcthomas18

Published Jul 23, 2018
MAL-2026-356

Malicious code in react-server-dom-unbundled (npm)

Published Jan 20, 2026
CVE-2017-16215HIGH

Directory Traversal in sgqserve

Published Sep 1, 2020
CVE-2021-23718MEDIUM

Server-Side Request Forgery in ssrf-agent

Published Dec 2, 2021
CVE-2026-31868

Parse Server vulnerable to stored XSS via file upload of HTML-renderable file types

Published Mar 11, 2026
CVE-2025-66398

Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE)

Published Jan 2, 2026
GHSA-vffh-c9pq-4crh

Uptime Kuma Server-side Template Injection (SSTI) in Notification Templates Allows Arbitrary File Read

Published Oct 20, 2025
CVE-2017-16170HIGH

Directory Traversal in liuyaserver

Published Sep 1, 2020
MAL-2023-457

Malicious code in foxy.io-serverless-functions-on-netlify-demo (npm)

Published Jul 14, 2023
CVE-2026-29087

@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware

Published Mar 4, 2026
CVE-2022-25940HIGH

lite-server vulnerable to Denial of Service

Published Dec 20, 2022
CVE-2017-16149HIGH

Directory Traversal in zwserver

Published Sep 1, 2020
MAL-2025-2522

Malicious code in picl-server (npm)

Published Mar 18, 2025
CVE-2017-16090HIGH

Directory Traversal in fsk-server

Published Sep 1, 2020
CVE-2026-27818

TerriaJS-Server has a domain validation bypass vulnerability in its proxy allowlist

Published Feb 26, 2026
CVE-2026-34215MEDIUM
Risk: 32.51/100

Parse Server exposes auth data via verify password endpoint

Published Mar 29, 2026
CVE-2017-16168HIGH

Directory Traversal in wffserve

Published Sep 1, 2020
CVE-2022-25875MEDIUM

Svelte vulnerable to XSS when using objects during server-side rendering

Published Jul 13, 2022
CVE-2026-33627

Parse Server exposes auth data via /users/me endpoint

Published Mar 24, 2026
MAL-2025-190848

Malicious code in lite-serper-mcp-server (npm)

Published Nov 24, 2025
CVE-2026-26801

pdfmake is vulnerable to server-side request forgery (SSRF)

Published Mar 10, 2026
CVE-2025-64757

Astro Development Server has Arbitrary Local File Read

Published Nov 19, 2025
CVE-2026-27804

Parse Server: Account takeover via JWT algorithm confusion in Google auth adapter

Published Feb 25, 2026
CVE-2026-30863

Parse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adapters

Published Mar 9, 2026
MAL-2025-4057

Malicious code in @confluence-classic/confluence-frontend-server (npm)

Published May 21, 2025
CVE-2026-33163

Parse Server leaks protected fields via LiveQuery afterEvent trigger

Published Mar 18, 2026
CVE-2025-69256

serverless MCP Server vulnerable to Command Injection in list-projects tool

Published Dec 31, 2025
CVE-2020-8214HIGH

Path traversal in servey

Published May 7, 2021
CVE-2018-3724HIGH

Path Traversal in general-file-server

Published Jul 26, 2018
CVE-2019-5480MEDIUM

Path Traversal in statichttpserver

Published Sep 4, 2019
CVE-2025-55184

Denial of Service Vulnerability in React Server Components

Published Dec 11, 2025
CVE-2025-64764

Astro vulnerable to reflected XSS via the server islands feature

Published Nov 19, 2025
CVE-2025-31125

Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query

Published Mar 31, 2025
MAL-2025-362

Malicious code in node-server-sdk (npm)

Published Jan 23, 2025
CVE-2026-32886

Parse Server's Cloud function dispatch crashes server via prototype chain traversal

Published Mar 17, 2026
CVE-2022-0086CRITICAL

uppy's companion module is vulnerable to Server-Side Request Forgery (SSRF)

Published Jan 6, 2022
MAL-2025-190909

Malicious code in @postman/postman-mcp-server (npm)

Published Nov 24, 2025
CVE-2020-15500MEDIUM

Cross-site scripting in TileServer GL

Published May 17, 2021
GHSA-3xp3-pr8x-f755

Agions taskflow-ai vulnerable to os command injection in src/mcp/server/handlers.ts

Published Apr 9, 2026
CVE-2024-32869MEDIUM

Hono vulnerable to Restricted Directory Traversal in serveStatic with deno

Published Apr 23, 2024
CVE-2026-32248

Parse Server: Account takeover via operator injection in authentication data identifier

Published Mar 12, 2026
GHSA-67mh-4wv8-2f99

esbuild enables any website to send any requests to the development server and read the response

Published Feb 10, 2025
CVE-2017-16214HIGH

Directory Traversal in peiserver

Published Sep 1, 2020
MAL-2025-2047

Malicious code in paypal-sdk-server-side-integration (npm)

Published Mar 3, 2025
MAL-2025-1197

Malicious code in whatsapp-otp-sample-server (npm)

Published Feb 3, 2025
MAL-2025-2269

Malicious code in nodes-tree-visualizer-server (npm)

Published Mar 11, 2025
CVE-2025-65513

Fetch MCP Server has a Server-Side Request Forgery (SSRF) vulnerability

Published Dec 10, 2025
CVE-2025-59333

@executeautomation/database-server does not properly restrict access, bypassing a "read-only" mode

Published Sep 16, 2025
MAL-2022-4777

Malicious code in mz-server (npm)

Published Jun 20, 2022
CVE-2026-26118

Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network

Published Mar 10, 2026
CVE-2017-16096HIGH

Directory Traversal in serveryaozeyan

Published Sep 1, 2020
CVE-2026-33323

Parse Server email verification resend page leaks user existence

Published Mar 19, 2026
CVE-2025-67489

@vitejs/plugin-rsc Remote Code Execution through unsafe dynamic imports in RSC server function APIs on development server

Published Dec 8, 2025
MAL-2025-191107

Malicious code in ids-enterprise-mcp-server (npm)

Published Nov 24, 2025
CVE-2026-27978

Next.js: null origin can bypass Server Actions CSRF checks

Published Mar 17, 2026
CVE-2024-37818HIGH

Strapi Server-Side Request Forgery (SSRF)

Published Jun 20, 2024
CVE-2018-16484MEDIUM

Cross-Site Scripting in m-server

Published Feb 7, 2019
CVE-2020-8135CRITICAL

Server-Side Request Forgery in @uppy/companion

Published Sep 3, 2020
CVE-2017-16213HIGH

Directory Traversal in mfrserver

Published Sep 1, 2020
CVE-2025-47269

code-server's session cookie can be extracted by having user visit specially crafted proxy URL

Published May 9, 2025
MAL-2022-2327

Malicious code in dapp-inter-agservers (npm)

Published Jun 20, 2022
MAL-2022-2391

Malicious code in dedicated-servers (npm)

Published Jul 26, 2022
CVE-2026-27729

Astro has memory exhaustion DoS due to missing request body size limit in Server Actions

Published Feb 25, 2026
CVE-2025-58752

Vite's `server.fs` settings were not applied to HTML files

Published Sep 9, 2025
CVE-2022-25895HIGH

lite-dev-server vulnerable to Directory Traversal

Published Dec 21, 2022
MAL-2025-3520

Malicious code in @reserach_org_jfhalsdhfkslsfds/openai-server-skfghdg (npm)

Published Apr 29, 2025
MAL-2025-48757

Malicious code in replit-desktop-release-server (npm)

Published Oct 23, 2025
CVE-2026-27584

ActualBudget server is Missing Authentication for SimpleFIN and Pluggy AI bank sync endpoints

Published Feb 24, 2026
CVE-2026-34595MEDIUM
Risk: 21.51/100

Parse Server has a LiveQuery protected-field guard bypass via array-like logical operator value

Published Apr 1, 2026
CVE-2026-27971

Qwik vulnerable to Unauthenticated RCE via server$ Deserialization

Published Mar 2, 2026
CVE-2017-16183HIGH

Directory Traversal in iter-server

Published Sep 1, 2020
CVE-2018-16478MEDIUM

Path Traversal in simplehttpserver

Published Dec 6, 2018
MAL-2022-6754

Malicious code in ui-extensions-server-kit (npm)

Published Jun 20, 2022
CVE-2024-32964CRITICAL

lobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerability

Published May 10, 2024
CVE-2026-32242

Parse Server's OAuth2 adapter shares mutable state across providers via singleton instance

Published Mar 12, 2026
CVE-2026-30228

parse-server's file creation and deletion bypasses `readOnlyMasterKey` write restriction

Published Mar 6, 2026
MAL-2022-2742

Malicious code in engage-digital-source-server-template-js (npm)

Published Jun 20, 2022
MAL-2022-2208

Malicious code in cors-typescript-server (npm)

Published Jun 20, 2022
CVE-2017-16216HIGH

Directory Traversal in tencent-server

Published Sep 1, 2020
CVE-2024-36421HIGH

Flowise Cors Misconfiguration in packages/server/src/index.ts

Published Aug 5, 2024
CVE-2024-53843

@dapperduckling/keycloak-connector-server has Reflected XSS Vulnerability in Authentication Flow URL Handling

Published Nov 26, 2024
CVE-2026-29182

Parse Server's Cloud Hooks and Cloud Jobs bypass `readOnlyMasterKey` write restriction

Published Mar 5, 2026
MAL-2025-2465

Malicious code in homeappserver (npm)

Published Mar 17, 2025
CVE-2021-41109HIGH

LiveQuery publishes user session tokens in parse-server

Published Sep 30, 2021
CVE-2026-31818CRITICAL
Risk: 48/100

Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklist

Published Apr 3, 2026
CVE-2017-16135HIGH

Directory Traversal in serverzyy

Published Sep 1, 2020
GHSA-wmmm-f939-6g9c

Hono: Middleware bypass via repeated slashes in serveStatic

Published Apr 8, 2026
GHSA-95hg-3c55-xf9x

awwaiid mcp-server-taskwarrior vulnerable to command injection

Published Apr 9, 2026
MAL-2022-3456

Malicious code in grenache-fib-server (npm)

Published Jun 20, 2022
GHSA-w37m-7fhw-fmv9

Next Server Actions Source Code Exposure

Published Dec 11, 2025
GHSA-cxcw-jm67-3wwp

Duplicate Advisory: OpenClaw's andbox browser noVNC observer lacked VNC authentication

Published Mar 21, 2026
GHSA-w3hv-x4fp-6h6j

@grackle-ai/server has Missing WebSocket Origin Header Validation

Published Mar 25, 2026
CVE-2026-31829

Flowise affected by Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network Access

Published Mar 11, 2026
CVE-2026-0969

next-mdx-remote affected by arbitrary code execution in React server-side rendering of untrusted MDX content

Published Feb 12, 2026
GHSA-h25m-26qc-wcjf

Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components

Published Jan 28, 2026
CVE-2026-34784HIGH
Risk: 37.51/100

Parser Server's streaming file download bypasses afterFind file trigger authorization

Published Apr 1, 2026
CVE-2018-3716MEDIUM

Stored Cross-Site Scripting in simplehttpserver

Published Jul 26, 2018
GHSA-m2m6-cff5-3w7c

RedwoodSDK has Same-site CSRF through lack of origin validation in its server actions

Published Apr 24, 2026
MAL-2026-2714

Malicious code in @gameforge/http-server (npm)

Published Apr 16, 2026
CVE-2026-33950CRITICAL
Risk: 47.01/100

Signal K Server: Privilege Escalation by Admin Role Injection via /enableSecurity

Published Apr 3, 2026
GHSA-vmhw-fhj6-m3g5

Path Traversal in angular-http-server

Published May 31, 2019
MAL-2022-782

Malicious code in @xvideos/server-inherited (npm)

Published Jun 20, 2022
MAL-2022-824

Malicious code in ace_authorization_server (npm)

Published Jun 20, 2022
CVE-2017-16180HIGH

Directory Traversal in serverabc

Published Jul 23, 2018
GHSA-prp4-2f49-fcgp

Actual has Privilege Escalation via 'change-password' Endpoint on OpenID-Migrated Servers

Published Apr 23, 2026
MAL-2024-8980

Malicious code in defillama-apy-server (npm)

Published Sep 26, 2024
CVE-2022-28118CRITICAL

RCE in SiteServer CMS

Published May 4, 2022
CVE-2026-29045

Hono vulnerable to arbitrary file access via serveStatic vulnerability

Published Mar 4, 2026
MAL-2022-893

Malicious code in agoric-servers (npm)

Published Jun 20, 2022
CVE-2024-49770

Path traversal in oak allows transfer of hidden files within the served root directory

Published Nov 1, 2024
MAL-2025-47929

Malicious code in mcp-server-fixthis (npm)

Published Oct 7, 2025
MAL-2022-3538

Malicious code in gxm-reference-web-auth-server (npm)

Published Jun 20, 2022
MAL-2022-1872

Malicious code in chain-reserve-wallet-adapter (npm)

Published Jun 20, 2022
MAL-2025-4492

Malicious code in nayan-apis-servers (npm)

Published May 27, 2025
MAL-2025-3883

Malicious code in driver-app-server (npm)

Published May 16, 2025
MAL-2025-4980

Malicious code in raise-http-server (npm)

Published Jun 16, 2025
MAL-2026-3123

Malicious code in apple-app-store-server-library-poc (npm)

Published Apr 27, 2026
CVE-2020-15135MEDIUM

CSRF vulnerability in save-server

Published Aug 4, 2020
CVE-2021-39187HIGH

Parse Server crashes with query parameter

Published Sep 2, 2021
CVE-2022-31089HIGH

Invalid file request can crash server

Published Jun 20, 2022
MAL-2023-1232

Malicious code in matlab-language-server (npm)

Published Jul 26, 2023
MAL-2022-854

Malicious code in addons-server (npm)

Published Jun 20, 2022
MAL-2022-6970

Malicious code in vro-language-server (npm)

Published May 31, 2022
MAL-2022-561

Malicious code in @rezserver/fetlife-assets (npm)

Published Jun 20, 2022
MAL-2025-192601

Malicious code in vscode-azure-mcp-server (npm)

Published Dec 16, 2025
MAL-2025-47838

Malicious code in @lanyer640/mcp-runcommand-server (npm)

Published Sep 29, 2025
MAL-2022-748

Malicious code in @xvideos/auth-server (npm)

Published Jun 20, 2022
MAL-2022-2918

Malicious code in exodus-update-server (npm)

Published Jun 20, 2022
MAL-2022-4499

Malicious code in mattermost-metrics-server (npm)

Published Jun 20, 2022
MAL-2025-6304

Malicious code in react-server-dom-turbopack-experimental (npm)

Published Jul 25, 2025
MAL-2023-629

Malicious code in node-config-server-utils (npm)

Published Jan 24, 2023
MAL-2022-3825

Malicious code in ing-kit-dev-server (npm)

Published Jun 20, 2022
MAL-2025-2159

Malicious code in @adminproxy/module-utils-server (npm)

Published Mar 5, 2025
MAL-2023-641

Malicious code in notebooklanguageserver (npm)

Published Feb 24, 2023
MAL-2022-3846

Malicious code in inno-basic-server (npm)

Published Jun 20, 2022
MAL-2022-3458

Malicious code in grenache-nodejs-example-fib-server (npm)

Published Jun 20, 2022
MAL-2022-3460

Malicious code in grenache-nodejs-fib-server (npm)

Published Jun 20, 2022
MAL-2023-771

Malicious code in serverless-action (npm)

Published May 5, 2023
MAL-2022-4065

Malicious code in jscs-server (npm)

Published Jun 20, 2022
MAL-2022-6800

Malicious code in upchieve-server (npm)

Published Jun 20, 2022
MAL-2022-4794

Malicious code in near-api-server (npm)

Published Jun 20, 2022
MAL-2025-3584

Malicious code in serverlog-dispatch (npm)

Published May 2, 2025
CVE-2017-16089HIGH

Directory Traversal in serverlyr

Published Sep 1, 2020
MAL-2022-5486

Malicious code in proof-of-reserves-adapter (npm)

Published Jun 20, 2022
MAL-2024-11061

Malicious code in operation-server-sdk (npm)

Published Nov 27, 2024
CVE-2026-39363
Risk: 44.23/100

Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket

Published Apr 6, 2026
MAL-2025-46986

Malicious code in mcp-server-everything (npm)

Published Sep 9, 2025
CVE-2026-35200MEDIUM
Risk: 30.18/100

Parse Server: File upload Content-Type override via extension mismatch

Published Apr 4, 2026
CVE-2026-34224MEDIUM
Risk: 22.01/100

Parse Server has an MFA single-use token bypass via concurrent authData login requests

Published Mar 29, 2026
MAL-2022-5192

Malicious code in pagespeed-server (npm)

Published Jun 20, 2022
MAL-2022-781

Malicious code in @xvideos/server-base (npm)

Published Jun 20, 2022
MAL-2022-5249

Malicious code in paypay-sample-ecommerce-server (npm)

Published Jun 20, 2022
MAL-2023-1343

Malicious code in webpack-dev-server.legacy (npm)

Published May 1, 2023
MAL-2023-1528

Malicious code in usaa-mock-server (npm)

Published Aug 21, 2023
MAL-2026-1377

Malicious code in adroit-websdk-server (npm)

Published Mar 13, 2026
MAL-2024-10267

Malicious code in webhooks-resources-nodejs-server (npm)

Published Oct 29, 2024
CVE-2021-39138MEDIUM

parse-server new anonymous user session acts as if it's created with password

Published Aug 23, 2021
MAL-2026-2247

Malicious code in cua-primitives-server (npm)

Published Mar 27, 2026
MAL-2026-2483

Malicious code in strapi-plugin-server (npm)

Published Apr 3, 2026
MAL-2025-191403

Malicious code in prompt-eng-server (npm)

Published Nov 25, 2025
MAL-2022-5673

Malicious code in react-server-dom-vite (npm)

Published Sep 5, 2022
MAL-2024-11147

Malicious code in nayan-server (npm)

Published Nov 29, 2024
MAL-2024-11807

Malicious code in nayan-api-server (npm)

Published Dec 12, 2024
MAL-2025-190769

Malicious code in discord-bot-server (npm)

Published Nov 24, 2025
MAL-2025-190899

Malicious code in @posthog/web-dev-server (npm)

Published Nov 24, 2025
MAL-2025-190947

Malicious code in @posthog/plugin-server (npm)

Published Nov 24, 2025
MAL-2025-191196

Malicious code in @browserbasehq/mcp-server-browserbase (npm)

Published Nov 25, 2025
MAL-2022-5925

Malicious code in samples-cors-typescript-server (npm)

Published Jun 20, 2022
MAL-2025-192571

Malicious code in paypal-scripts-server-utils (npm)

Published Dec 15, 2025
MAL-2022-5987

Malicious code in seal_online_node_server (npm)

Published Jun 20, 2022
MAL-2022-4189

Malicious code in klook-tetris-server (npm)

Published Jun 20, 2022
MAL-2022-6019

Malicious code in server_qa_automation (npm)

Published Jun 20, 2022
MAL-2022-6020

Malicious code in serverbeat (npm)

Published Jun 20, 2022
MAL-2022-6021

Malicious code in serverjsdefine (npm)

Published Jun 20, 2022
MAL-2022-6022

Malicious code in serverless-api-partners (npm)

Published Jun 20, 2022
MAL-2022-6023

Malicious code in serverless-infrastructure (npm)

Published Jun 20, 2022
MAL-2022-6024

Malicious code in serverless-push-hasura (npm)

Published Jul 21, 2022
MAL-2022-6025

Malicious code in serverless-yandex-cloud-template (npm)

Published Jun 20, 2022
MAL-2025-190811

Malicious code in @ensdomains/server-analytics (npm)

Published Nov 24, 2025
MAL-2022-6119

Malicious code in sifchain-changes-server (npm)

Published Jun 20, 2022
MAL-2022-6156

Malicious code in skywriter_server (npm)

Published Nov 7, 2022
MAL-2022-4763

Malicious code in myfirstdependencywithserver (npm)

Published Jul 26, 2022
CVE-2019-5447MEDIUM

Path Traversal in http-file-server

Published Jul 16, 2019
MAL-2022-4533

Malicious code in media-server-embed (npm)

Published Jun 20, 2022
GHSA-2r2p-4cgf-hv7h

engram: HTTP server CORS wildcard + auth-off-by-default enables CSRF graph exfiltration and persistent indirect prompt injection

Published Apr 22, 2026
MAL-2022-763

Malicious code in @xvideos/facade-server (npm)

Published Jun 20, 2022
GHSA-479c-33wc-g2pg

React Server Components have a Denial of Service Vulnerability

Published Apr 10, 2026
CVE-2026-25535

jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions

Published Feb 19, 2026
MAL-2025-1162

Malicious code in paypal-server-sdk (npm)

Published Feb 3, 2025
CVE-2026-30972

Parse Server has a rate limit bypass via batch request endpoint

Published Mar 11, 2026
MAL-2025-141

Malicious code in serve-static-corell (npm)

Published Jan 19, 2025
MAL-2026-2236

Malicious code in onboarding-server (npm)

Published Mar 26, 2026
CVE-2023-7079MEDIUM

Arbitrary remote file read in Wrangler dev server

Published Jan 3, 2024
MAL-2022-7249

Malicious code in www-server (npm)

Published Sep 8, 2022
CVE-2026-34574MEDIUM
Risk: 27.01/100

Parse Server has a session field immutability bypass via falsy-value guard

Published Apr 1, 2026
CVE-2021-38384CRITICAL

Incorrect Authorization in serverless-offline

Published Sep 1, 2021
CVE-2026-34573HIGH
Risk: 37.52/100

parse-server has GraphQL complexity validator exponential fragment traversal DoS

Published Mar 31, 2026
GHSA-mwv6-3258-q52c

Next Vulnerable to Denial of Service with Server Components

Published Dec 11, 2025
CVE-2024-57177

CouchAuth has a Server-Side Template Injection vulnerability in its email functionality

Published Feb 10, 2025
MAL-2025-4080

Malicious code in gatsby-mars-pet-parent-journey--server (npm)

Published May 21, 2025
MAL-2025-2068

Malicious code in unms-server (npm)

Published Mar 4, 2025
CVE-2017-16036HIGH

Directory Traversal in badjs-sourcemap-server

Published Jul 24, 2018
CVE-2026-31872

Parse Server has a protected fields bypass via dot-notation in query and sort

Published Mar 11, 2026
CVE-2025-69203

Signal K Server Vulnerable to Access Request Spoofing

Published Jan 2, 2026
CVE-2026-34532CRITICAL
Risk: 45.51/100

parse-server has cloud function validator bypass via prototype chain traversal

Published Mar 31, 2026
MAL-2022-7097

Malicious code in webhooks-server (npm)

Published Jun 20, 2022
MAL-2025-4812

Malicious code in apple-appstore-server-library (npm)

Published Jun 10, 2025
MAL-2026-769

Malicious code in https-servers (npm)

Published Feb 5, 2026
MAL-2025-48012

Malicious code in webpack-dev-serve-middleware (npm)

Published Oct 7, 2025
MAL-2025-174

Malicious code in console-webapp-static-server (npm)

Published Jan 20, 2025
MAL-2026-2328

Malicious code in mcp-server-todo (npm)

Published Apr 1, 2026
MAL-2026-2086

Malicious code in falcor-server (npm)

Published Mar 23, 2026
MAL-2026-460

Malicious code in pay-by-bank-dashboard-server (npm)

Published Jan 22, 2026
MAL-2025-4958

Malicious code in snapshot-server (npm)

Published Jun 14, 2025
MAL-2025-6305

Malicious code in react-server-dom-webpack-experimental (npm)

Published Jul 25, 2025
MAL-2025-190707

Malicious code in @actbase/node-server (npm)

Published Nov 24, 2025
MAL-2026-1955

Malicious code in kyxserver-everything (npm)

Published Mar 20, 2026
MAL-2026-2133

Malicious code in server-fpti (npm)

Published Mar 24, 2026
MAL-2025-191373

Malicious code in @voiceflow/serverless-plugin-typescript (npm)

Published Nov 25, 2025
MAL-2025-4882

Malicious code in server-log-engine (npm)

Published Jun 10, 2025
MAL-2025-4883

Malicious code in server-tiny-log (npm)

Published Jun 10, 2025
MAL-2025-4762

Malicious code in react-server-dom-fb (npm)

Published Jun 9, 2025
MAL-2025-92

Malicious code in inspector-server (npm)

Published Jan 14, 2025
MAL-2026-136

Malicious code in npe-toolkit-server-deps (npm)

Published Jan 7, 2026
MAL-2025-48558

Malicious code in demo-mercadopago-mcp-server (npm)

Published Oct 23, 2025
Check your entire dependency tree at onceRun dependency scan →