The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,789
Mitigations17,239
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Knit Pay<= 9.6.1.0
Authenticated (Subscriber+) Privilege Escalation vulnerability
8.8
2 hours ago
Wawp<= 4.8.6
Unauthenticated Privilege Escalation vulnerability
9.8
2 hours ago
s2Member<= 260814
Unauthenticated Remote Code Execution vulnerability
8.8
2 hours ago
Optima Express + MarketBoost IDX Plugin<= 8.7.5
Unauthenticated Privilege Escalation to 'ihf_clear_cache' AJAX Action to Author Role Assignment vulnerability
7.3
2 hours ago
cline< 3.0.30
NPM: Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` endpoint)
8.8
4 hours ago
@rsdoctor/rspack-plugin<= 1.5.15
NPM: @rsdoctor/rspack-plugin has Unauthenticated HTTP API that Exposes Project Source Code and Build Metadata
7.5
4 hours ago
@bytebase/dbhub< 0.22.6
NPM: @bytebase/dbhub's read-only mode does not prevent database writes
7.4
4 hours ago
@bytebase/dbhub<= 0.22.4
NPM: DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution
9.3
4 hours ago
xhtml-purifier<= 0.4.1
NPM: xhtml-purifier has HTML attribute-injection (sanitizer bypass) that leads to XSS
6.1
4 hours ago
@bsv/wallet-toolbox>= 1.1.47, < 2.4.0
NPM: `@bsv/wallet-toolbox` / `-client` / `-mobile` don't verify storage-supplied recipient output scripts against caller-requested outputs in createAction
8.7
4 hours ago
@bsv/wallet-toolbox-client>= 1.1.47, < 2.4.0
NPM: `@bsv/wallet-toolbox` / `-client` / `-mobile` don't verify storage-supplied recipient output scripts against caller-requested outputs in createAction
8.7
4 hours ago
@bsv/wallet-toolbox-mobile>= 1.3.21, < 2.4.0
NPM: `@bsv/wallet-toolbox` / `-client` / `-mobile` don't verify storage-supplied recipient output scripts against caller-requested outputs in createAction
8.7
4 hours ago
cyberchef< 11.2.0
NPM: CyberChef: Prototype pollution in Series Chart operation
5
4 hours ago
@aws/lsp-codewhisperer< 0.0.117
NPM: Language Servers for AWS vulnerable to arbitrary file write
7.8
4 hours ago
@aws/lsp-codewhisperer< 0.0.113
NPM: Language Servers for AWS Vulnerable to Arbitrary Code Execution
8.5
4 hours ago
suneditor<= 2.47.10
sanitizer bypass
10
8 hours ago
King Addons for Elementor<= 51.1.85
Cross Site Scripting (XSS) vulnerability
6.5
13 hours ago
Pixel Manager for WooCommerce<= 1.69.0
Cross Site Scripting (XSS) vulnerability
6.5
13 hours ago
Business Directory<= 6.4.27
Insecure Direct Object References (IDOR) vulnerability
5.4
13 hours ago
The Plus Addons for Elementor Page Builder Lite<= 6.5.1
Cross Site Scripting (XSS) vulnerability
6.5
13 hours ago