Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
49,475
Mitigations
Mitigation rules
15,973
No official patch
13,050
In triage
1,416
Published soon
5
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
axios
>= 1.7.0, < 1.18.0
NPM: Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
6.3
20 minutes ago
axios
< 0.33.0
NPM: Axios: Prototype pollution gadgets can alter axios request construction
6.3
22 minutes ago
axios
>= 0.31.0, < 0.33.0
NPM: Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
6.9
27 minutes ago
protobufjs
>= 8.2.0, <= 8.6.4
NPM: protobufjs: Text Format string map parsing can mutate returned map object prototype
4.8
43 minutes ago
protobufjs
>= 7.5.0, <= 7.6.4
NPM: protobufjs: Denial of Service via infinite loop in .proto option parsing
5.3
44 minutes ago
webpack-dev-server
<= 5.2.5
NPM: webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
5.3
44 minutes ago
webpack-dev-server
<= 5.2.5
NPM: webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
4.7
45 minutes ago
astro
>= 6.4.7, < 6.4.8
NPM: Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
8.2
48 minutes ago
tar
<= 7.5.17
NPM: node-tar: Process crash via PAX numeric path type confusion
5.3
54 minutes ago
tar
<= 7.5.18
NPM: node-tar: Decompression/parse DoS via unlimited input
7.5
55 minutes ago
tar
<= 7.5.17
NPM: node-tar: Negative tar entry size causes infinite loop in archive replace
7.5
55 minutes ago
tar
<= 7.5.16
NPM: node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
5.3
56 minutes ago
engine.io
>= 4.1.0, < 6.6.7
NPM: Socket.IO: Engine.IO Polling Transport Connection Exhaustion
7.5
57 minutes ago
shell-quote
<= 1.8.4
NPM: shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
7.5
57 minutes ago
directus
< 12.0.0
NPM: Directus: Authorization-dependent response served from unsegmented cache key
8.6
59 minutes ago
directus
< 12.0.0
NPM: Directus: SSRF Protection Bypass via 0.0.0.0 in File Import
7.7
1 hour ago
js-yaml
>= 5.0.0, <= 5.1.0
NPM: js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml
5.3
1 hour ago
js-yaml
>= 3.0.0, < 3.15.0
NPM: js-yaml: YAML merge-key chains can force quadratic CPU consumption
7.5
1 hour ago
js-yaml
>= 5.0.0, <= 5.2.0
NPM: js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA
5.3
1 hour ago
astro
>= 2.9.0, <= 7.0.9
NPM: Astro: Reflected XSS via unescaped View Transition animation properties
5.3
1 hour ago
Load more