The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total49,475
Mitigations15,973
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
axios>= 1.7.0, < 1.18.0
NPM: Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
6.3
20 minutes ago
axios< 0.33.0
NPM: Axios: Prototype pollution gadgets can alter axios request construction
6.3
22 minutes ago
axios>= 0.31.0, < 0.33.0
NPM: Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
6.9
27 minutes ago
protobufjs>= 8.2.0, <= 8.6.4
NPM: protobufjs: Text Format string map parsing can mutate returned map object prototype
4.8
43 minutes ago
protobufjs>= 7.5.0, <= 7.6.4
NPM: protobufjs: Denial of Service via infinite loop in .proto option parsing
5.3
44 minutes ago
webpack-dev-server<= 5.2.5
NPM: webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
5.3
44 minutes ago
webpack-dev-server<= 5.2.5
NPM: webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
4.7
45 minutes ago
astro>= 6.4.7, < 6.4.8
NPM: Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
8.2
48 minutes ago
tar<= 7.5.17
NPM: node-tar: Process crash via PAX numeric path type confusion
5.3
54 minutes ago
tar<= 7.5.18
NPM: node-tar: Decompression/parse DoS via unlimited input
7.5
55 minutes ago
tar<= 7.5.17
NPM: node-tar: Negative tar entry size causes infinite loop in archive replace
7.5
55 minutes ago
tar<= 7.5.16
NPM: node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
5.3
56 minutes ago
engine.io>= 4.1.0, < 6.6.7
NPM: Socket.IO: Engine.IO Polling Transport Connection Exhaustion
7.5
57 minutes ago
shell-quote<= 1.8.4
NPM: shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
7.5
57 minutes ago
directus< 12.0.0
NPM: Directus: Authorization-dependent response served from unsegmented cache key
8.6
59 minutes ago
directus< 12.0.0
NPM: Directus: SSRF Protection Bypass via 0.0.0.0 in File Import
7.7
1 hour ago
js-yaml>= 5.0.0, <= 5.1.0
NPM: js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml
5.3
1 hour ago
js-yaml>= 3.0.0, < 3.15.0
NPM: js-yaml: YAML merge-key chains can force quadratic CPU consumption
7.5
1 hour ago
js-yaml>= 5.0.0, <= 5.2.0
NPM: js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA
5.3
1 hour ago
astro>= 2.9.0, <= 7.0.9
NPM: Astro: Reflected XSS via unescaped View Transition animation properties
5.3
1 hour ago