Showing 1-20 of 290 packages
Fix the React 2 Shell vulnerability (CVE-2025-66478) in Next.js apps with one command
Regular expression matching for URL's. Maintained, safe, and browser-friendly version of url-regex. Resolves CVE-2020-7661. Works in Node v10.12.0+ and browsers.
Security module - CVE fixes, input validation, path security
Patched Vue 2.7.16 template compiler to fix XSS (CVE-2024-6783) and ReDoS (CVE-2024-9506) security vulnerabilities.
Fork of Vue 2.7.16 with patched CVE-2024-9506 (regex ReDoS vulnerability)
Forked template compiler for Vue with CVE-2024-9506 patch
MCP server for searching and retrieving CVE vulnerability information from NVD
The lodash method _.template exported as node.js module but without cve
[libxmljs2](https://www.npmjs.com/package/libxmljs2) has critical, unresolved security issues, ([CVE-2024-34393](https://github.com/advisories/GHSA-mjr4-7xg5-pfvh), [CVE-2024-34394](https://github.com/advisories/GHSA-78h3-pg4x-j8cv)), but is no longer mai
It's a react table for bootstrap fork from AllenFang and fix dangerouslySetInnerHTML issue (CVE-2021-23398)
Fork isvalid 1.6.7 - Patch merge 1.2.2 CVE (Prototype Pollution) The Unkillable Fork
Universal security validation framework for Next.js - Protects against CVE-2025-55182 and major attack vectors
Authentication for Next.js - Sanitize compliant with CVE-2022-31127
TypeScript implementation of SSVC (Stakeholder-Specific Vulnerability Categorization). A prioritization framework to triage CVE vulnerabilities as an alternative or compliment to CVSS
Secure expression evaluator - Drop-in replacement for expr-eval without CVE-2025-12735 vulnerability
Next generation of react-bootstrap-table minus CVE-2021-23358
Security scanner for CVE-2025-55182 - Critical React Server Components RCE vulnerability. Scan lockfiles, SBOMs, Docker images, and live URLs.
Lite Model Context Protocol server for comprehensive CVE intelligence gathering with multi-source exploit discovery, designed for security professionals and cybersecurity researchers
Regular expression matching for URL's. Maintained, and browser-friendly version of url-regex. This package is vulnerable to CVE-2020-7661. Works in Node v10.12.0+ and browsers.
Bazaarvoice utilities for working with CVE IDs