The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total51,671
Mitigations16,877
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
deepseek-tui>= 0.8.32, < 0.8.41
NPM: CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
7.5
33 minutes ago
codewhale>= 0.8.41, < 0.8.64
NPM: CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
7.5
33 minutes ago
@simplewebauthn/server<= 13.3.1
NPM: SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor
2
34 minutes ago
Restaurant Menu by MotoPress< 2.4.12
Unauthenticated Payment Bypass vulnerability
5.3
5 hours ago
Epayco< 8.4.7
Unauthenticated Payment Confirmation Bypass vulnerability
5.3
5 hours ago
Pods3.3-3.3.9.1
Author+ Arbitrary File Read vulnerability
4.9
5 hours ago
JetPopup<= 2.0.20.2
Broken Access Control vulnerability
5.3
7 hours ago
Taxi Booking Manager for WooCommerce< 2.0.5
Unauthenticated Price Manipulation vulnerability
5.3
8 hours ago
WoodMart< 8.3.8
Cross Site Scripting (XSS) vulnerability
6.5
8 hours ago
WP Rentals< 3.16.0
Insecure Direct Object References (IDOR) vulnerability
5.4
9 hours ago
WooCommerce<= 10.9.4
SQL Injection vulnerability
7.6
9 hours ago
MarketKing<= 2.1.60
Broken Access Control vulnerability
5.3
10 hours ago
WCFM Membership<= 2.11.11
Broken Access Control vulnerability
5.3
10 hours ago
Divi Ajax Filter<= 5.1.2
Unauthenticated Local File Inclusion vulnerability
9.8
10 hours ago
LearnDash LMS<= 5.1.5
Authenticated (Subscriber+) Arbitrary File Upload vulnerability
10
10 hours ago
Directorist< 8.9
Subscriber+ Arbitrary Post Meta Write vulnerability
3.1
12 hours ago
Xpro Elementor Addons< 1.7.8
Unauthenticated Draft/Private Product Disclosure vulnerability
5.3
12 hours ago
WPvivid Backup and Migration< 0.9.134
Admin+ Arbitrary File Deletion vulnerability
5.5
12 hours ago
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent< 4.4.2
Admin+ SQLi vulnerability
7.6
12 hours ago
Ninja Forms3.14.0-3.15.1
Authenticated Arbitrary Post Modification and Sensitive Information Disclosure vulnerability
5.9
12 hours ago