The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,080
Mitigations16,167
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
electron>= 40.0.0-alpha.1, < 40.10.6
NPM: Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
5.9
10 minutes ago
electron< 39.8.8
NPM: Electron: HTTP redirect followed into local file loader
5.9
13 minutes ago
electron< 39.8.10
NPM: Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
7.4
18 minutes ago
electron< 39.8.8
NPM: Electron: Extension tab APIs operate across session boundaries
6.6
20 minutes ago
electron< 39.8.6
NPM: Electron: shell.openPath path validation bypass via embedded null byte
6
20 minutes ago
electron< 39.8.9
NPM: Electron: Context isolation bypass via Function.prototype.bind hijack
7.5
31 minutes ago
electron< 39.8.8
NPM: Electron: Cross-origin iframe can position native autofill popup
3.1
37 minutes ago
electron< 39.8.7
NPM: Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
5.9
41 minutes ago
electron< 39.8.10
NPM: Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
3.9
50 minutes ago
electron< 39.8.8
NPM: Electron: Parent process code-sign check is spoofable
6.3
56 minutes ago
ghost>= 5.46.1, < 6.21.2
NPM: Ghost Content API filter bypass reveals private fields
5.3
1 hour ago
ghost>= 4.9.0, < 6.54.1
NPM: Ghost: Cross-Site Scripting in Feature Image Captions
4.3
1 hour ago
ghost>= 6.26.0, < 6.54.1
NPM: Ghost: Server-Side Request Forgery Mitigation Issue
4
1 hour ago
Instagram Feed<= 6.11.3
Reflected Cross-Site Scripting vulnerability
7.1
3 hours ago
Dokan<=5.0.2-<=5.0.2
Missing Authorization to Authenticated (Vendor+) Privilege Escalation vulnerability
8.8
3 hours ago
Points and Rewards for WooCommerce< 2.10.1
Unauthenticated Arbitrary User Wallet & Points Manipulation vulnerability
5.9
3 hours ago
VikRentItems Flexible Rental Management System<= 1.2.1
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
3 hours ago
Advanced Views<= 3.9.1
Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure vulnerability
6.5
3 hours ago
Udimi Tools<= 3.2
Missing Authorization to Authenticated (Subscriber+) Plugin Configuration Reset vulnerability
6.5
3 hours ago
Layouts for WPBakery<= 1.1.3
Missing Authorization to Unauthenticated Template Cache Manipulation vulnerability
6.5
3 hours ago