blockchain.com 82 packages

Last scanned on Oct 27 at 06:10 PM
url-parse 1.5.1VulnerableOutdated
Small footprint URL parser that works seamlessly across Node.js and browser environments
License
MIT
Footprint
3 KB
Vulnerabilities
url-parse incorrectly parses hostname / protocol due to unstripped leading control characters.
Affected versions >=0 <1.5.9
Authorization bypass in url-parse
Affected versions >=0 <1.5.6
Open redirect in url-parse
Affected versions >=0 <1.5.2
Authorization Bypass Through User-Controlled Key in url-parse
Affected versions >=0 <1.5.8
url-parse Incorrectly parses URLs that include an '@'
Affected versions >=0 <1.5.7
Matched Modules
Version distribution in production
206
1.5.10
167
1.5.9
50
1.5.3
47
1.4.6
47
1.4.7
23
1.5.1
lodash 4.17.16VulnerableOutdated
Lodash modular utilities.
next 10.0.0 - 11.0.1VulnerableOutdated
The React Framework
rauchg
timneutkens
vercel-release-bot
xml2js 0.4.18 - 0.4.23VulnerableOutdated
Simple XML to JavaScript object converter.
leonidas
leonidas
tslib 1.2.0 - 2.4.0Outdated
Runtime library for TypeScript helper functions
readable-stream 3.6.0Outdated
Node.js Streams, a user-land copy of the stream library from Node.js
string_decoder 1.1.0 - 1.3.0
The string_decoder module from Node core
isarray 1.0.0 - 2.0.5
Array#isArray for older browsers
react-is 16.3.0 - 17.0.2Outdated
Brand checking of React Elements.
inherits 2.0.4
Browser-friendly inheritance fully compatible with standard node.js inherits()
buffer 4.6.0 - 4.9.2Outdated
Node.js Buffer API, for the browser
entities 2.2.0Outdated
Encode & decode XML and HTML entities with ease & speed
@babel/runtime 7.9.6 - 7.12.18Outdated
babel's modular runtime helpers
+1
hzoo
existentialism
nicolo-ribaudo
cookie 0.4.1 - 0.4.2Outdated
HTTP server cookie parsing and serialization
dougwilson
dougwilson
core-util-is 1.0.2 - 1.0.3
The `util.is*` functions introduced in Node v0.12.
base64-js 1.3.0 - 1.5.1
Base64 encoding/decoding in pure JS
events 3.0.0 - 3.3.0
Node's event emitter for all engines.
requires-port 1.0.0
Check if a protocol requires a certain port number to be added to an URL.
xmlbuilder 11.0.0 - 11.0.1Outdated
An XML builder for node.js
querystringify 2.2.0
Querystringify - Small, simple but powerful query string parser.
lodash.debounce 4.0.8
The lodash method `_.debounce` exported as a module.
date-fns 2.16.1 - 2.28.0Outdated
Modern JavaScript date utility library
kossnocorp
kossnocorp
minimalistic-assert 1.0.0 - 1.0.1
minimalistic-assert ===
cwmma
indutny
hoist-non-react-statics 3.3.1 - 3.3.2
Copies non-react specific statics from a child component to a parent component
mridgway
mridgway
@emotion/unitless 0.7.2 - 0.8.0Outdated
An object of css properties that don't accept values with units
+1
emmatown
tkh44
emotion-release-bot
classnames 2.3.0 - 2.3.1Outdated
A simple utility for conditionally joining classNames together
query-string 6.5.0 - 7.1.1Outdated
Parse and stringify URL query strings
sha.js 2.4.9 - 2.4.11
Streamable SHA hashes in pure javascript
dcousens
ljharb
cwmma
ramda 0.26.0 - 0.28.0Outdated
A practical functional library for JavaScript programmers.
asn1.js 5.2.0 - 5.4.1
ASN.1 encoder and decoder
hash-base 3.0.4 - 3.1.0
abstract base class for hash-streams
elliptic 6.5.4Outdated
EC cryptography
hash.js 1.1.2 - 1.1.7
Various hash functions that could be run by both browser and node
hmac-drbg 1.0.1
Deterministic random bit generator (hmac)
lodash-es 4.17.21
Lodash exported as ES modules.
des.js 1.0.1Outdated
DES implementation
md5.js 1.1.0 - 1.3.5
node style md5 on pure JavaScript
pbkdf2 3.1.0 - 3.1.2
This library provides the functionality of PBKDF2 with the ability to use any supported hashing algorithm returned from crypto.getHashes()
cipher-base 1.0.4
abstract base class for crypto-streams
parse-asn1 5.1.6Outdated
utility library for parsing asn1 files for use with browserify-sign.
+2
dcousens
ljharb
cwmma
browserify-sign 2.4.0 - 2.8.0Outdated
adds node crypto signing for browsers
+2
dcousens
ljharb
cwmma
browserify-aes 0.4.0 - 0.8.1Outdated
aes, for browserify
stream-http 2.8.2 - 2.8.3Outdated
Streaming http in the browser
evp_bytestokey 1.0.3
The insecure key derivation algorithm from OpenSSL
browserify-rsa 4.1.0
RSA for browserify
+2
dcousens
ljharb
cwmma
timers-browserify 2.0.9Outdated
timers module for browserify
create-ecdh 3.0.0 - 4.0.4
createECDH but browserifiable
public-encrypt 4.0.3
browserify version of publicEncrypt & privateDecrypt
+2
dcousens
ljharb
cwmma
diffie-hellman 1.1.2Outdated
pure js diffie-hellman
browserify-des 1.0.2
browserify-des ===
dcousens
ljharb
cwmma
miller-rabin 1.1.0 - 4.0.1
Miller Rabin algorithm for primality test
randomfill 1.0.0 - 1.0.4
random fill from browserify stand alone
querystring-es3 0.2.1
Node's querystring module for all engines. (ES3 compat fork)
filter-obj 1.1.0Outdated
Filter object keys and values into a new object
shallowequal 1.0.1 - 1.1.0
Like lodash isEqualWith but for shallow equal.
split-on-first 1.0.0 - 1.1.0Outdated
Split a string on the first occurance of a given separator
to-arraybuffer 1.0.1
Get an ArrayBuffer from a Buffer as fast as possible
styled-components 5.2.0 - 5.3.6Outdated
CSS for the <Component> Age. Style components your way with speed, strong typing, and flexibility.
throttle-debounce 2.2.0 - 3.0.1Outdated
Throttle and debounce functions.
@emotion/stylis 0.8.1Outdated
A custom build of Stylis
+1
emmatown
tkh44
emotion-release-bot
intl-messageformat 9.5.0 - 9.9.6Outdated
Formats ICU Message strings with number, date, plural, and select placeholders to create localized messages.
framer-motion 4.1.14 - 4.1.17Outdated
A simple and powerful JavaScript animation library
@formatjs/icu-messageformat-parser 0.2.1 - 1.1.2Outdated
Hand-written ICU MessageFormat parser with compatible output as [`intl-messageformat-parser`](https://www.npmjs.com/package/intl-messageformat-parser) but 6 - 10 times as fast.
longlho
redonkulus
pyrocat
@formatjs/icu-skeleton-parser 1.0.0 - 1.3.14Outdated
longlho
redonkulus
pyrocat
fp-ts 2.6.6 - 2.9.5Outdated
Functional programming in TypeScript
string-convert 0.2.0 - 0.2.1
String convertions
akiran
akiran
json2mq 0.2.0
Generate media query string from JSON or javascript object
akiran
akiran
framesync 4.1.0 - 6.1.2
A frame-synced render loop for JavaScript
popmotion
popmotion
react-intl 5.14.1 - 5.15.7Outdated
Internationalize React apps. This library provides React components and an API to format dates, numbers, and strings, including pluralization and handling translations.
universal-cookie 4.0.1 - 4.0.4Outdated
Universal cookies for JavaScript
popmotion 9.0.0 - 11.0.5
The animator's toolbox
style-value-types 4.1.0 - 4.1.5Outdated
Parsers, transformers and tests for special value types, eg: %, hex codes etc.
fast-memoize 2.3.0 - 2.5.2
Fastest memoization lib that supports N arguments
caiogondim
caiogondim
@formatjs/intl 1.3.4 - 1.14.3Outdated
Internationalize JS apps. This library provides an API to format dates, numbers, and strings, including pluralization and handling translations.
enquire.js 2.1.6
Awesome Media Queries in JavaScript
react-slick 0.27.11 - 0.28.1Outdated
React port of slick carousel
react-player 1.12.0 - 1.15.3Outdated
A React component for playing a variety of URLs, including file paths, YouTube, Facebook, Twitch, SoundCloud, Streamable, Vimeo, Wistia and DailyMotion
@chakra-ui/hooks 1.2.0 - 2.1.0Outdated
React hooks for Chakra components
react-native-web 0.0.72 - 0.18.9Outdated
React Native for Web
amplitude-js 5.2.0Outdated
Javascript library for Amplitude Analytics
deepcopy 2.0.0 - 2.1.0
deep copy data
sasaplus1
sasaplus1
react-amphtml 3.1.0 - 4.0.2
Use amphtml components inside your React apps easily!
dfrankland
dfrankland