The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total54,142
Mitigations17,856
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
music-metadata< 11.16.0
NPM: music-metadata: MP4 stsd sample-entry size==0 causes a synchronous infinite loop (DoS) — unreleased regression on master
6.2
2 hours ago
music-metadata<= 11.12.3
NPM: music-metadata: Uncontrolled memory allocation in APEv2 parser
6.2
2 hours ago
music-metadata<= 11.12.3
NPM: music-metadata: ID3v2 tag size not validated before allocation, causing memory exhaustion DoS
6.2
2 hours ago
music-metadata< 11.16.0
NPM: music-metadata: EBML parser trusts element lengths, allowing memory exhaustion or process abort
6.2
2 hours ago
mariadb< 3.2.5
NPM: MariaDB Connector/Node.js: SQL injection in the text protocol when the session uses NO_BACKSLASH_ESCAPES
7.4
2 hours ago
mariadb>= 3.2.0, < 3.2.5
NPM: MariaDB Connector/Node.js: SQL injection through object keys in SET expansion (permitSetMultiParamEntries)
8.1
2 hours ago
mariadb< 3.2.5
NPM: MariaDB Connector/Node.js exposes uninitialized process memory through malformed GeoJSON parameters
7.5
2 hours ago
mariadb>= 3.3.0, < 3.5.4
NPM: MariaDB Connector/Node.js: Uncaught exception crashes the client during ed25519 authentication with zero-configuration TLS
5.9
2 hours ago
music-metadata<= 11.14.0
NPM: music-metadata: uncatchable process crash parsing a crafted `.dsf` (residual of GHSA-v6c2-xwv6-8xf7)
6.2
2 hours ago
handlebars>= 4.0.0, <= 4.7.9
NPM: Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled Templates
4.7
4 hours ago
handlebars>= 4.0.0, <= 4.7.9
NPM: Handlebars: JavaScript Injection via AST Type Confusion in compile (bypass of CVE-2026-33937)
9.8
4 hours ago
handlebars>= 4.0.0, <= 4.7.9
NPM: Handlebars: JavaScript Injection via Own Property Check Bypass
9.2
4 hours ago
@langchain/mongodb<= 1.3.0
NPM: LangChain: MongoDBChatMessageHistory query injection can allow cross-session access
6
4 hours ago
generator-jhipster>= 7.0.0, < 9.4.0
NPM: JHipster: SQL Injection in the Parameter of JHipster-Generated Reactive (WebFlux + R2DBC) Applicationssort
8.8
4 hours ago
react-jhipster<= 1.0.3
NPM: JHipster: Generated Applications Allow Stored XSS via Unrestricted Blob ContentType Opened as Same-Origin Blob
7.6
4 hours ago
generator-jhipster< 9.4.0
NPM: JHipster: Generated Applications Allow Stored XSS via Unrestricted Blob ContentType Opened as Same-Origin Blob
7.6
4 hours ago
msgpack5< 6.1.0
NPM: msgpack5: Truncated map32 headers throw an unexpected error
7.5
4 hours ago
msgpack5< 6.1.0
NPM: msgpack5: Many buffered values can exhaust the streaming decoder stack
7.5
4 hours ago
msgpack5< 6.1.0
NPM: msgpack5: Reserved byte can cause unbounded stream buffering
5.9
4 hours ago
msgpack5< 6.1.0
NPM: msgpack5: Partial options disable prototype protection
6.5
4 hours ago