The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,187
Mitigations16,181
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
sequelize< 6.37.4
NPM: Sequelize: SQL Injection (Oracle DB)
9.8
58 minutes ago
hono< 4.12.34
NPM: Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
5.3
1 hour ago
ip-address<= 10.3.0
NPM: ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
7.7
1 hour ago
ip-address>= 10.1.1, <= 10.2.1
NPM: ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks
6.9
1 hour ago
ip-address>= 10.1.1, <= 10.2.0
NPM: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
6.9
1 hour ago
undici< 6.28.0
NPM: undici vulnerable to CRLF Injection via blob-like body 'type' property
4.2
1 hour ago
undici>= 7.0.0, < 7.29.0
NPM: undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
5.9
1 hour ago
undici< 6.28.0
NPM: undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
4.8
1 hour ago
undici< 6.28.0
NPM: undici vulnerable to downstream response desynchronization via retry interceptor
4.8
2 hours ago
undici>= 7.0.0, < 7.29.0
NPM: undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
7.4
2 hours ago
fast-uri< 2.4.4
NPM: fast-uri vulnerable to host confusion via backslash authority introducer
7.5
2 hours ago
socket.io-parser< 3.3.6
NPM: Socket.IO: Zero-attachment Memory Exhaustion
7.5
2 hours ago
postcss<= 8.5.22
NPM: PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset
6.3
4 hours ago
brace-expansion< 1.1.18
NPM: brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
7.5
4 hours ago
@angular/core<= 19.2.25
NPM: Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes
7.6
5 hours ago
@angular/compiler<= 19.2.25
NPM: Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes
7.6
5 hours ago
@angular/platform-server<= 19.2.25
NPM: Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)
8.6
5 hours ago
@angular/common<= 19.2.25
NPM: Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning
8.8
5 hours ago
VikBooking Hotel Booking Engine & PMS<= 1.8.13
Reflected Cross-Site Scripting vulnerability
7.1
9 hours ago
WPify Woo Czech<= 5.4.16
Authenticated (Shop Manager+) Privilege Escalation vulnerability
7.2
9 hours ago