Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
54,142
Mitigations
Mitigation rules
17,856
No official patch
13,576
In triage
991
Published soon
133
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
music-metadata
< 11.16.0
NPM: music-metadata: MP4 stsd sample-entry size==0 causes a synchronous infinite loop (DoS) — unreleased regression on master
6.2
42 minutes ago
music-metadata
<= 11.12.3
NPM: music-metadata: Uncontrolled memory allocation in APEv2 parser
6.2
42 minutes ago
music-metadata
<= 11.12.3
NPM: music-metadata: ID3v2 tag size not validated before allocation, causing memory exhaustion DoS
6.2
42 minutes ago
music-metadata
< 11.16.0
NPM: music-metadata: EBML parser trusts element lengths, allowing memory exhaustion or process abort
6.2
42 minutes ago
mariadb
< 3.2.5
NPM: MariaDB Connector/Node.js: SQL injection in the text protocol when the session uses NO_BACKSLASH_ESCAPES
7.4
43 minutes ago
mariadb
>= 3.2.0, < 3.2.5
NPM: MariaDB Connector/Node.js: SQL injection through object keys in SET expansion (permitSetMultiParamEntries)
8.1
43 minutes ago
mariadb
< 3.2.5
NPM: MariaDB Connector/Node.js exposes uninitialized process memory through malformed GeoJSON parameters
7.5
43 minutes ago
mariadb
>= 3.3.0, < 3.5.4
NPM: MariaDB Connector/Node.js: Uncaught exception crashes the client during ed25519 authentication with zero-configuration TLS
5.9
43 minutes ago
music-metadata
<= 11.14.0
NPM: music-metadata: uncatchable process crash parsing a crafted `.dsf` (residual of GHSA-v6c2-xwv6-8xf7)
6.2
44 minutes ago
handlebars
>= 4.0.0, <= 4.7.9
NPM: Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled Templates
4.7
2 hours ago
handlebars
>= 4.0.0, <= 4.7.9
NPM: Handlebars: JavaScript Injection via AST Type Confusion in compile (bypass of CVE-2026-33937)
9.8
2 hours ago
handlebars
>= 4.0.0, <= 4.7.9
NPM: Handlebars: JavaScript Injection via Own Property Check Bypass
9.2
2 hours ago
@langchain/mongodb
<= 1.3.0
NPM: LangChain: MongoDBChatMessageHistory query injection can allow cross-session access
6
2 hours ago
generator-jhipster
>= 7.0.0, < 9.4.0
NPM: JHipster: SQL Injection in the Parameter of JHipster-Generated Reactive (WebFlux + R2DBC) Applicationssort
8.8
2 hours ago
react-jhipster
<= 1.0.3
NPM: JHipster: Generated Applications Allow Stored XSS via Unrestricted Blob ContentType Opened as Same-Origin Blob
7.6
2 hours ago
generator-jhipster
< 9.4.0
NPM: JHipster: Generated Applications Allow Stored XSS via Unrestricted Blob ContentType Opened as Same-Origin Blob
7.6
2 hours ago
msgpack5
< 6.1.0
NPM: msgpack5: Truncated map32 headers throw an unexpected error
7.5
2 hours ago
msgpack5
< 6.1.0
NPM: msgpack5: Many buffered values can exhaust the streaming decoder stack
7.5
2 hours ago
msgpack5
< 6.1.0
NPM: msgpack5: Reserved byte can cause unbounded stream buffering
5.9
2 hours ago
msgpack5
< 6.1.0
NPM: msgpack5: Partial options disable prototype protection
6.5
2 hours ago
Load more