The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total49,774
Mitigations16,024
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
@anthropic-ai/claude-code>= 2.1.38, < 2.1.163
NPM: Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
7.7
3 hours ago
js-yaml>= 5.0.0, <= 5.2.1
NPM: js-yaml: Exponential parsing time in flow collections leads to denial of service
7.5
3 hours ago
react-router>= 7.12.0, < 8.3.0
NPM: React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
7.1
3 hours ago
aws-cdk-lib< 2.253.0
NPM: AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
3 hours ago
@aws-cdk/aws-codebuild>= 1.75.0, <= 1.204.0
NPM: AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
3 hours ago
@fastify/static<= 10.1.1
NPM: @fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
5.3
3 hours ago
@fastify/static<= 10.1.0
NPM: @fastify/static vulnerable to route guard bypass via path traversal
7.5
3 hours ago
tar<= 7.5.20
NPM: node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
5.3
4 hours ago
postcss<= 8.5.17
NPM: PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
7.5
4 hours ago
@prompty/core<= 0.1.4
NPM: Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
10
4 hours ago
mongoose< 6.13.10
NPM: Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
6.5
4 hours ago
velocityjs<= 2.1.6
NPM: Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
9.8
4 hours ago
@backstage/plugin-auth-backend<= 0.29.1
NPM: @backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass
4.7
4 hours ago
trix< 2.1.18
NPM: Trix: Stored XSS via HTMLParser attribute injection on paste
4.6
4 hours ago
valibot<= 1.4.1
NPM: Valibot: record() issue paths can make flatten() throw for inherited Object property names
6.9
4 hours ago
seroval<= 1.5.2
NPM: seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
9.8
4 hours ago
@sveltejs/kit<= 2.69.0
NPM: SvelteKit: Prototype pollution in file input deletion path in remote-function forms
4.3
4 hours ago
@sveltejs/kit<= 2.69.0
NPM: SvelteKit: Big remote form function payloads can cause Node process to crash
5.3
4 hours ago
better-auth>= 1.1.3, < 1.6.22
NPM: Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
8.3
4 hours ago
@better-auth/stripe>= 1.4.11, < 1.6.21
NPM: @better-auth/stripe: cross-organization billing tampering in organization subscription actions
7.1
4 hours ago