Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
54,142
Mitigations
Mitigation rules
17,856
No official patch
13,576
In triage
991
Published soon
133
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
music-metadata
< 11.16.0
NPM: music-metadata: MP4 stsd sample-entry size==0 causes a synchronous infinite loop (DoS) — unreleased regression on master
6.2
2 hours ago
music-metadata
<= 11.12.3
NPM: music-metadata: Uncontrolled memory allocation in APEv2 parser
6.2
2 hours ago
music-metadata
<= 11.12.3
NPM: music-metadata: ID3v2 tag size not validated before allocation, causing memory exhaustion DoS
6.2
2 hours ago
music-metadata
< 11.16.0
NPM: music-metadata: EBML parser trusts element lengths, allowing memory exhaustion or process abort
6.2
2 hours ago
mariadb
< 3.2.5
NPM: MariaDB Connector/Node.js: SQL injection in the text protocol when the session uses NO_BACKSLASH_ESCAPES
7.4
2 hours ago
mariadb
>= 3.2.0, < 3.2.5
NPM: MariaDB Connector/Node.js: SQL injection through object keys in SET expansion (permitSetMultiParamEntries)
8.1
2 hours ago
mariadb
< 3.2.5
NPM: MariaDB Connector/Node.js exposes uninitialized process memory through malformed GeoJSON parameters
7.5
2 hours ago
mariadb
>= 3.3.0, < 3.5.4
NPM: MariaDB Connector/Node.js: Uncaught exception crashes the client during ed25519 authentication with zero-configuration TLS
5.9
2 hours ago
music-metadata
<= 11.14.0
NPM: music-metadata: uncatchable process crash parsing a crafted `.dsf` (residual of GHSA-v6c2-xwv6-8xf7)
6.2
2 hours ago
handlebars
>= 4.0.0, <= 4.7.9
NPM: Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled Templates
4.7
4 hours ago
handlebars
>= 4.0.0, <= 4.7.9
NPM: Handlebars: JavaScript Injection via AST Type Confusion in compile (bypass of CVE-2026-33937)
9.8
4 hours ago
handlebars
>= 4.0.0, <= 4.7.9
NPM: Handlebars: JavaScript Injection via Own Property Check Bypass
9.2
4 hours ago
@langchain/mongodb
<= 1.3.0
NPM: LangChain: MongoDBChatMessageHistory query injection can allow cross-session access
6
4 hours ago
generator-jhipster
>= 7.0.0, < 9.4.0
NPM: JHipster: SQL Injection in the Parameter of JHipster-Generated Reactive (WebFlux + R2DBC) Applicationssort
8.8
4 hours ago
react-jhipster
<= 1.0.3
NPM: JHipster: Generated Applications Allow Stored XSS via Unrestricted Blob ContentType Opened as Same-Origin Blob
7.6
4 hours ago
generator-jhipster
< 9.4.0
NPM: JHipster: Generated Applications Allow Stored XSS via Unrestricted Blob ContentType Opened as Same-Origin Blob
7.6
4 hours ago
msgpack5
< 6.1.0
NPM: msgpack5: Truncated map32 headers throw an unexpected error
7.5
4 hours ago
msgpack5
< 6.1.0
NPM: msgpack5: Many buffered values can exhaust the streaming decoder stack
7.5
4 hours ago
msgpack5
< 6.1.0
NPM: msgpack5: Reserved byte can cause unbounded stream buffering
5.9
4 hours ago
msgpack5
< 6.1.0
NPM: msgpack5: Partial options disable prototype protection
6.5
4 hours ago
Load more