Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,990
Mitigations
Mitigation rules
17,315
No official patch
13,369
In triage
1,425
Published soon
38
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@nestjs/microservices
< 11.2.4
NPM: Nest: Remote process termination via a deeply nested microservice message pattern
7.5
1 hour ago
fast-uri
< 2.4.7
NPM: fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets
4.8
1 hour ago
fast-uri
>= 4.1.3, < 4.1.5
NPM: fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization
4.8
1 hour ago
@xhmikosr/decompress
<= 10.2.1
NPM: @xhmikosr/decompress: Path traversal via symlink chain
9.1
1 hour ago
decompress
<= 4.2.1
NPM: @xhmikosr/decompress: Path traversal via symlink chain
9.1
1 hour ago
ip-address
<= 10.7.0
NPM: ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range
6.3
1 hour ago
ip-address
<= 10.7.0
NPM: ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process
6.3
1 hour ago
moment
>= 2.29.2, < 2.31.0
NPM: moment vulnerable to Path Traversal via crafted non-string locale name
5.9
1 hour ago
brace-expansion
< 1.1.21
NPM: brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service
5.3
1 hour ago
brace-expansion
< 1.1.20
NPM: brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
7.5
1 hour ago
brace-expansion
< 1.1.19
NPM: brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
7.5
1 hour ago
engine.io
>= 6.6.0, < 6.6.10
NPM: Socket.IO: Engine.IO Protocol Revision Mismatch DoS
7.5
1 hour ago
nodemailer
>= 9.1.0, < 10.0.9
NPM: Nodemailer: Quoted local-part can produce malformed envelope recipient through RFC 5322 comment parsing
5.3
1 hour ago
nodemailer
<= 10.0.5
NPM: Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service
7.5
1 hour ago
adm-zip
<= 0.6.0
NPM: adm-zip: Duplicate ZIP entry names: getEntry() and extractAllTo() resolve to different content
5.9
2 hours ago
adm-zip
<= 0.6.0
NPM: adm-zip: getDataAsync() bypasses the maxOutputLength size guard enforced by the synchronous getData() path
5.3
2 hours ago
adm-zip
<= 0.6.0
NPM: adm-zip: Unhandled error event in async DEFLATE decompression crashes Node.js process (DoS)
7.5
2 hours ago
adm-zip
<= 0.6.0
NPM: adm-zip: Decompression-bomb protection (fix for CVE-2026-39244) can be bypassed by declaring uncompressed size as 0
7.5
6 hours ago
adm-zip
<= 0.6.0
NPM: adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation
7.1
6 hours ago
nodemailer
< 10.0.2
NPM: Nodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS
5.9
6 hours ago
Load more