Vulnerability database
Supply-chain news
The incidents behind a package’s reputation. Read what happened, which releases were affected, and what the original investigators found.
Reviewed reports · last reviewed 2026-09-05. This is a selected incident record, not an exhaustive live threat feed. A past compromise does not establish that the current release is compromised.
No reviewed stories for this ecosystem yet. This does not mean no incidents have occurred.
From the security news feeds
Checked every five minutes. Last completed check: 2026-09-05T20:58:24.610Z. Package mentions are automated leads, not confirmed vulnerability findings. Their checks refresh maintenance signals and do not prove an affected version is safe.
No matching feed articles recorded yet.
High-profile vulnerabilities and your dependencies
Astra’s top-ten article ↗ collects historical CVEs from 2020–2022. It is not a live ranking or the OWASP Top 10. The mapping below explains which entries relate to package identities we check.
An identity match is a reason to investigate, not confirmation that your installed release is vulnerable. Manifest checks do not establish runtime configuration or resolve every transitive dependency.
| Vulnerability | Product / package relationship |
|---|---|
| ZeroLogon CVE-2020-1472 ↗ | Windows / Netlogon Host and domain-controller assessment required. Outside package-only scan coverage |
| Log4Shell CVE-2021-44228 ↗ | Apache Log4j Core Applies to specific log4j-core releases, not log4j-api alone. Check resolved and bundled dependencies against Apache’s affected-version ranges. org.apache.logging.log4j:log4j-core |
| ICMAD CVE-2022-22536 ↗ | SAP NetWeaver / related SAP services Requires SAP product and deployment inventory. Outside package-only scan coverage |
| ProxyLogon CVE-2021-26855 ↗ | Microsoft Exchange Server Check the Exchange deployment; a NuGet package name cannot establish exposure. Outside package-only scan coverage |
| Spring4Shell CVE-2022-22965 ↗ | Spring Framework Historical affected branches include 5.3.0–5.3.17 and 5.2.19 and earlier. Exploitability depends on runtime and deployment; consult Spring’s advisory. org.springframework:spring-webmvc · org.springframework:spring-webflux · org.springframework:spring-beans |
| Confluence RCE CVE-2022-26134 ↗ | Atlassian Confluence Requires Confluence Server or Data Center version inventory. Outside package-only scan coverage |
| vCenter RCE CVE-2021-21972 ↗ | VMware vCenter Server Requires infrastructure product and version inventory. Outside package-only scan coverage |
| Chrome use-after-free CVE-2022-0609 ↗ | Google Chrome Check the installed browser; JavaScript package names do not identify its version. Outside package-only scan coverage |
| Follina CVE-2022-30190 ↗ | Windows MSDT Requires Windows patch and configuration assessment. Outside package-only scan coverage |
| PetitPotam CVE-2021-36942 ↗ | Windows LSA / EFSRPC Requires Windows and domain configuration assessment. Outside package-only scan coverage |
Runtime vulnerabilities on OpenCVE
Browse CVEs by vendor and product. Runtime CVEs do not automatically apply to every package in that ecosystem; verify affected versions and configurations.
News & advisory sources
RSS sources are polled independently every five minutes. Clear tracked-package mentions trigger priority checks; they do not establish that an installed version is vulnerable. Sources without an RSS link and Feedspot’s directory are browsing resources. Reviewed reports above remain curated.
Container security advisories
Chainguard Security Advisories ↗
Security research
Wiz Blog ↗
Security publisher
The Hacker News ↗
Security publisher
Dark Reading ↗
Security publisher
Help Net Security ↗
Security publisher
SecurityWeek ↗
Government advisories
CISA Alerts & Advisories ↗
Government advisories
NCSC Netherlands ↗
Vendor advisories
Palo Alto Networks Security Advisories ↗
Feed directory