The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,252
Mitigations16,235
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
jsii-diff< 1.131.0
NPM: jsii-diff: Command Injection via npm: package argument
7.8
29 minutes ago
@sveltejs/kit<= 2.70.1
NPM: SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
5.3
1 hour ago
nuxt>= 3.21.7, < 3.21.10
NPM: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
5.3
1 hour ago
dompurify<= 3.4.12
NPM: DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
5.1
3 hours ago
WordPress< 7.0.3
SSRF vulnerability
5.4
15 hours ago
WordPress< 7.0.3
CSS Injection vulnerability
5.9
15 hours ago
WordPress< 7.0.3
Sensitive Data Exposure vulnerability
5.3
15 hours ago
WordPress< 7.0.3
Sensitive Data Exposure vulnerability
5.3
16 hours ago
WordPress< 7.0.3
Stored XSS vulnerabiliity
6.5
16 hours ago
WordPress7.0-7.0.2
Unauthenticated Sensitive Data Exposure vulnerability
5.3
20 hours ago
WordPress< 7.0.3
Multiple Contributor+ Stored XSS vulnerabilities
6.5
20 hours ago
re2<= 1.26.0
NPM: node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript
5.1
21 hours ago
re2<= 1.25.0
NPM: node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length
6.2
21 hours ago
ngx-extended-pdf-viewer>= 27.0.0-rc.0, < 29.0.0-rc.3
NPM: ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633
8.6
21 hours ago
pdfjs-dist>= 5.6.83, < 6.2.108
NPM: PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF
8.6
21 hours ago
WordPress< 7.0.3
Subscriber+ Site Creation vulnerability
7.1
21 hours ago
js-yaml>= 3.0.0, < 3.15.1
NPM: JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
7.5
22 hours ago
nx>= 20.8.0, < 22.7.7
NPM: Nx: Zip-Slip in the self-hosted remote cache
8.7
22 hours ago
@nx/s3-cache<= 5.0.7
NPM: Nx: Zip-Slip in the self-hosted remote cache
8.7
22 hours ago
@nx/gcs-cache<= 5.0.7
NPM: Nx: Zip-Slip in the self-hosted remote cache
8.7
22 hours ago