The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,932
Mitigations17,300
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
nodemailer>= 5.0.0, < 10.0.2
NPM: Nodemailer: Process-global DNS cache reuses TLS `servername` across transports, enabling cross-tenant SMTP credential disclosure
5.9
1 hour ago
undici>= 6.25.0, < 6.28.1
NPM: undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression
5.9
1 hour ago
multer>= 2.2.0, < 2.4.0
NPM: multer vulnerable to Denial of Service via orphaned disk writes on aborted uploads
5.3
1 hour ago
morgan< 1.12.1
NPM: morgan vulnerable to Log Injection via unescaped double quote in quoted log fields
5.3
1 hour ago
@angular/platform-server<= 19.2.25
NPM: Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE
8.7
1 hour ago
fast-uri< 2.4.6
NPM: fast-uri vulnerable to authority injection via an unvalidated port in serialize
7.5
1 hour ago
fast-uri2.4.5
NPM: fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority
7.5
2 hours ago
ip-address<= 10.5.0
NPM: ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts
6.3
2 hours ago
ip-address>= 10.2.0, <= 10.5.0
NPM: ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass
6.9
2 hours ago
@angular/platform-server<= 19.2.25
NPM: Angular SSR: XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Content Elements
8.6
2 hours ago
@grpc/grpc-js-xds< 1.13.1
NPM: @grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches
6.5
3 hours ago
scim-patch< 0.9.2
NPM: scim-patch: Mutation of Inherited Built-in Method Objects
4.3
9 hours ago
code-ollama<= 0.36.0
NPM: code-ollama: `grep_search` Command Injection via Unescaped `$()` Shell Substitution (CWE-78)
7.8
9 hours ago
WP Review Slider Pro< 12.7.12
Subscriber+ Stored XSS vulnerability
6.5
9 hours ago
File Manager7.2.2-8.0.4
Unauthenticated Database Backup Disclosure vulnerability
5.9
10 hours ago
Verge3D4.1.0-4.13.0
Unauthenticated Payment Bypass vulnerability
5.3
10 hours ago
Best Payments Plugin for WP4.6.20-4.6.25
Unauthenticated Payment Bypass vulnerability
5.3
10 hours ago
Blacklist Manager &#8211; WooCommerce Anti-Fraud, Blacklist &amp; Checkout Verification1.3.0-2.3.1
Blocked User Restriction Bypass vulnerability
5.4
10 hours ago
Bookly< 28.3
Unauthenticated Payment Bypass vulnerability
5.3
10 hours ago
Contact Form by WPForms1.5.0.1-2.0.2.0
Unauthenticated Arbitrary Shortcode Execution vulnerability
6.5
10 hours ago