The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total51,895
Mitigations16,938
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
n8n< 2.37.7
NPM: n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy
5.3
50 minutes ago
nodemailer< 9.1.0
NPM: Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
6.5
50 minutes ago
nodemailer< 9.1.0
NPM: Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
7.5
50 minutes ago
nodemailer>= 6.9.16, < 9.1.0
NPM: Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
6.5
51 minutes ago
@typespec/openapi3<= 1.15.0
NPM: OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
7.1
53 minutes ago
@typespec/compiler<= 1.15.0
NPM: OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
7.1
53 minutes ago
multer< 2.3.0
NPM: multer vulnerable to Denial of Service via crafted multipart field names
7.5
53 minutes ago
multer2.2.0
NPM: multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
7.5
54 minutes ago
multer< 2.3.0
NPM: multer vulnerable to file size limit bypass via async fileFilter race condition
3.7
54 minutes ago
multer< 2.3.0
NPM: multer vulnerable to Denial of Service via oversized array index in field names
7.5
55 minutes ago
morgan< 1.12.0
NPM: morgan vulnerable to Log Forging via unescaped Unicode line separators
5.3
55 minutes ago
astro< 7.2.8
NPM: Astro: Remote code execution through AVIF image optimization
9.8
57 minutes ago
astro<= 7.2.3
NPM: Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
6.3
58 minutes ago
sharp< 0.35.4
NPM: sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545
8.9
58 minutes ago
js-yaml>= 3.0.0, < 3.15.2
NPM: js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
7.5
59 minutes ago
@tiptap/core>= 3.7.0, < 3.30.5
NPM: Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsing
8.7
1 hour ago
hono< 4.13.5
NPM: Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory
6.5
1 hour ago
hono< 4.13.5
NPM: Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion
5.3
1 hour ago
hono< 4.13.5
NPM: Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials
5.9
1 hour ago
next>= 10.0.0, < 15.5.24
NPM: Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
9.5
1 hour ago