Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
54,156
Mitigations
Mitigation rules
17,864
No official patch
13,581
In triage
986
Published soon
136
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Ocean Pro Demos
<= 1.5.4
Unauthenticated Stored Cross-Site Scripting vulnerability
7.2
1 hour ago
Ocean eComm Treasure Box
<= 1.8.0
Unauthenticated Stored Cross-Site Scripting vulnerability
7.2
1 hour ago
Redux Framework
<= 4.5.11
Redux Framework <= 4.5.11 – Authenticated (Subscriber+) Privilege Escalation vulnerability
6.8
1 hour ago
fast-jwt
<= 6.3.3
NPM: fast-jwt: Verifier cache accepts expired JWTs without iat.
4.2
10 hours ago
@adonisjs/http-server
<= 8.2.2
NPM: AdonisJS: Unencoded route parameters can produce open redirects
6.1
10 hours ago
fast-jwt
<= 6.3.0
NPM: fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is explicitly set
7.4
10 hours ago
fast-jwt
>= 6.2.0, <= 6.2.4
NPM: fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS256 algorithm confusion
9.8
10 hours ago
fast-jwt
<= 6.2.4
NPM: fast-jwt clockTolerance: Infinity silently bypasses both exp and nbf validation (and persists in the verifier cache)
5.9
10 hours ago
fast-jwt
<= 6.2.4
NPM: fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array
8.1
10 hours ago
fast-jwt
6.2.4
NPM: fast-jwt treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgery
7.4
10 hours ago
praisonai
< 1.7.3
NPM: PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosure
8.6
10 hours ago
music-metadata
< 11.16.0
NPM: music-metadata: MP4 stsd sample-entry size==0 causes a synchronous infinite loop (DoS) — unreleased regression on master
6.2
12 hours ago
music-metadata
<= 11.12.3
NPM: music-metadata: Uncontrolled memory allocation in APEv2 parser
6.2
12 hours ago
music-metadata
<= 11.12.3
NPM: music-metadata: ID3v2 tag size not validated before allocation, causing memory exhaustion DoS
6.2
12 hours ago
music-metadata
< 11.16.0
NPM: music-metadata: EBML parser trusts element lengths, allowing memory exhaustion or process abort
6.2
12 hours ago
mariadb
< 3.2.5
NPM: MariaDB Connector/Node.js: SQL injection in the text protocol when the session uses NO_BACKSLASH_ESCAPES
7.4
12 hours ago
mariadb
>= 3.2.0, < 3.2.5
NPM: MariaDB Connector/Node.js: SQL injection through object keys in SET expansion (permitSetMultiParamEntries)
8.1
12 hours ago
mariadb
< 3.2.5
NPM: MariaDB Connector/Node.js exposes uninitialized process memory through malformed GeoJSON parameters
7.5
12 hours ago
mariadb
>= 3.3.0, < 3.5.4
NPM: MariaDB Connector/Node.js: Uncaught exception crashes the client during ed25519 authentication with zero-configuration TLS
5.9
12 hours ago
music-metadata
<= 11.14.0
NPM: music-metadata: uncatchable process crash parsing a crafted `.dsf` (residual of GHSA-v6c2-xwv6-8xf7)
6.2
12 hours ago
Load more