The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,973
Mitigations17,315
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
adm-zip<= 0.6.0
NPM: adm-zip: Decompression-bomb protection (fix for CVE-2026-39244) can be bypassed by declaring uncompressed size as 0
7.5
1 hour ago
adm-zip<= 0.6.0
NPM: adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation
7.1
1 hour ago
nodemailer< 10.0.2
NPM: Nodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS
5.9
1 hour ago
undici>= 7.11.0, < 7.29.1
NPM: undici vulnerable to Denial of Service via orphaned RetryHandler response body
5.9
1 hour ago
undici< 6.28.1
NPM: undici vulnerable to downstream response splitting via retry interceptor
3.7
1 hour ago
undici>= 6.7.0, < 6.28.1
NPM: undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
7.5
2 hours ago
undici>= 7.15.0, < 7.29.1
NPM: undici vulnerable to Denial of Service via unbounded decompression of compressed responses
5.9
2 hours ago
undici>= 7.0.0, < 7.29.1
NPM: undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches
6.5
2 hours ago
undici>= 7.1.0, < 7.29.1
NPM: undici vulnerable to response truncation via oversized chunked responses in the dump interceptor
3.7
2 hours ago
undici>= 7.24.1, < 7.29.1
NPM: undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool
7.4
2 hours ago
undici>= 7.0.0, < 7.29.1
NPM: undici vulnerable to caching and replay of unsafe HTTP method responses
3.7
2 hours ago
undici>= 8.10.0, < 8.10.2
NPM: undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors
7.4
2 hours ago
undici>= 7.0.0, < 7.29.1
NPM: undici vulnerable to Denial of Service via WebSocketStream unclean close
5.9
2 hours ago
joi>= 17.2.0, < 17.13.7
NPM: joi: Quadratic regular-expression backtracking in `Joi.string().isoDate()`
7.5
2 hours ago
electron< 39.8.10
NPM: Electron: Local race condition in Squirrel.Mac update installation on macOS
6.7
2 hours ago
electron< 41.10.4
NPM: Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab
8.2
2 hours ago
electron< 41.10.6
NPM: Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions
8.2
2 hours ago
electron< 41.10.6
NPM: Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled
7.4
2 hours ago
electron< 41.10.6
NPM: Electron: <webview> can enable Node.js integration in Web Workers despite embedder restrictions
8.3
2 hours ago
electron>= 42.3.3, < 42.10.0
NPM: Electron: Sandboxed preload code cache can be poisoned by a compromised renderer
7.8
2 hours ago