The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total51,951
Mitigations16,968
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
@openhop/server<= 0.3.5
NPM: @openhop/server: Path Traversal in Flow ID File Operations
8.3
3 hours ago
functype-mcp-server<= 1.4.3
NPM: functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import
7.8
3 hours ago
@yeger/turbo-graph<= 2.8.8
NPM: @yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run
8.8
3 hours ago
nuxt-ollama>= 1.2.26, < 1.3.1
NPM: Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients
7.5
3 hours ago
smol-toml<= 1.7.0
NPM: smol-toml: Denial of Service via malformed TOML documents
8.2
8 hours ago
Brevo<= 3.1.77
Reflected Cross-Site Scripting vulnerability
7.1
13 hours ago
TelSender<= 1.14.14
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
13 hours ago
Podlove Podcast Publisher<= 4.5.1
Arbitrary File Upload vulnerability
N/A
13 hours ago
Drag and Drop File Upload for Elementor Forms<= 1.6.0
Unauthenticated Arbitrary File Upload via 'type' Parameter vulnerability
10
13 hours ago
SlideShowPro SC<= 1.0.2
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
13 hours ago
CI HUB Connector<= 1.2.106
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
13 hours ago
Inquiry Cart<= 3.4.2
Cross-Site Request Forgery vulnerability
6.1
13 hours ago
Gallagher Website Design<= 2.6.4
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
13 hours ago
Table Manager<= 1.0.0
Authenticated (Contributor+) Sensitive Information Exposure vulnerability
4.3
13 hours ago
HTTP Headers<= 1.19.2
Authenticated (Administrator+) External Control of File Name or Path to RCE vulnerability
7.2
13 hours ago
TP Restore Categories And Taxonomies<= 1.0.1
Missing Authorization to Authenticated (Subscriber+) Taxonomy Deletion vulnerability
5.4
13 hours ago
CalJ Shabbat Times<= 1.5
Authenticated (Subscriber+) Arbitrary Settings Modification vulnerability
5.3
13 hours ago
Gutentools<= 1.1.3
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
13 hours ago
RTMKit<= 2.0.2
Authenticated (Author+) Local File Inclusion vulnerability
7.2
13 hours ago
RTMKit<= 2.0.7
Authenticated (Contributor+) Limited Local File Inclusion vulnerability
4.3
13 hours ago