| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-26118 | Azure MCP Server Tools Elevation of Privilege Vulnerability | Microsoft | Azure MCP Server Tools 1.0.0 (npm) | High | 8.8 | 2026-03-10 17:05:21 | Deep Dive |
| CVE-2026-1615 | jsonpath 安全漏洞 | - | jsonpath | Critical | 9.8 | 2026-02-09 05:00:09 | Deep Dive |
| CVE-2026-0775 | npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability | npm | cli | 高危 | - | 2026-01-23 03:29:15 | Deep Dive |
| CVE-2025-9910 | jsondiffpatch 安全漏洞 | - | jsondiffpatch | Medium | 4.7 | 2025-09-11 05:00:02 | Deep Dive |
| CVE-2025-54885 | Thinbus generates insufficient entropy: 252 bits vs minimum 256 bits | simbo1905 | thinbus-srp-npm | - | - | 2025-08-07 00:02:43 | Deep Dive |
| CVE-2024-21541 | npm dom-iterator 安全漏洞 | - | dom-iterator | High | 7.3 | 2024-11-13 05:00:12 | Deep Dive |
| CVE-2024-21538 | cross-spawn 安全漏洞 | - | cross-spawn | High | 7.5 | 2024-11-08 05:00:05 | Deep Dive |
| CVE-2024-21534 | JSONPath Plus 安全漏洞 | - | jsonpath-plus | Critical | 9.8 | 2024-10-11 05:00:02 | Deep Dive |
| CVE-2024-21512 | MySQL2 安全漏洞 | - | mysql2 | High | 8.2 | 2024-05-29 05:00:02 | Deep Dive |
| CVE-2024-21501 | Apostrophe sanitize-html 安全漏洞 | - | sanitize-html | Medium | 5.3 | 2024-02-24 05:00:03 | Deep Dive |
| CVE-2024-21490 | angular 安全漏洞 | - | angular | High | 7.5 | 2024-02-10 05:00:02 | Deep Dive |
| CVE-2024-21484 | jsrsasign 安全漏洞 | - | jsrsasign | High | 7.5 | 2024-01-22 05:00:02 | Deep Dive |
| CVE-2023-31999 | Fastify 跨站请求伪造漏洞 | npm | @fastify/oauth2 | 高危 | - | 2023-07-04 16:29:20 | Deep Dive |
| CVE-2023-26115 | word-wrap 安全漏洞 | - | word-wrap | Medium | 5.3 | 2023-06-22 05:00:01 | Deep Dive |
| CVE-2023-26116 | Angular 安全漏洞 | - | angular | Medium | 5.3 | 2023-03-30 05:00:03 | Deep Dive |
| CVE-2023-26118 | Angular 安全漏洞 | - | angular | Medium | 5.3 | 2023-03-30 05:00:02 | Deep Dive |
| CVE-2023-26117 | Angular 安全漏洞 | - | angular | Medium | 5.3 | 2023-03-30 05:00:01 | Deep Dive |
| CVE-2021-32850 | jQuery MiniColors vulnerable to Cross-site Scripting | npm | @claviska/jquery-minicolors | Medium | 6.1 | 2023-02-20 00:00:00 | Deep Dive |
| CVE-2021-32851 | jQuery MiniColors vulnerable to Cross-site Scripting | npm | mind-elixir | Medium | 6.1 | 2023-02-20 00:00:00 | Deep Dive |
| CVE-2021-32853 | Erxes vulnerable to Cross-site Scripting | npm | erxes | Medium | 6.1 | 2023-02-20 00:00:00 | Deep Dive |