Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
49,700
Mitigations
Mitigation rules
16,012
No official patch
13,112
In triage
1,266
Published soon
132
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
n8n
< 1.123.67
NPM: n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
5.3
13 hours ago
n8n
< 1.123.67
NPM: n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
5.8
13 hours ago
n8n
< 1.123.67
NPM: n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
5.8
13 hours ago
next
>= 14.1.1, < 15.5.21
NPM: Next.js: Server-Side Request Forgery in Server Actions on custom servers
8.3
14 hours ago
next
>= 13.0.0, < 15.5.21
NPM: Next.js: Cache confusion of response bodies for requests with bodies
6
14 hours ago
next
>= 13.0.0, < 15.5.21
NPM: Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
6.3
14 hours ago
next
>= 13.0.0, < 15.5.21
NPM: Next.js: Unbounded Server Action payload in Edge runtime
6.3
14 hours ago
next
>= 12.0.0, < 15.5.21
NPM: Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
8.3
14 hours ago
next
>= 15.5.0, < 15.5.21
NPM: Next.js: Denial of Service in the Image Optimization API using SVGs
6.3
14 hours ago
next
>= 13.0.0, < 15.5.21
NPM: Next.js: Unauthenticated disclosure of internal Server Function endpoints
6.3
14 hours ago
next
>= 16.0.0, < 16.2.11
NPM: Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
8.3
14 hours ago
next
>= 13.0.0, < 15.5.21
NPM: Next.js: Denial of Service in App Router using Server Actions
8.2
14 hours ago
n8n
< 1.123.64
NPM: n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
5.1
14 hours ago
n8n
< 2.27.4
NPM: n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook
6.3
14 hours ago
n8n
< 1.123.64
NPM: n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
5.1
14 hours ago
n8n
< 2.29.8
NPM: n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
5.1
14 hours ago
n8n
< 2.29.8
NPM: n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows
5.5
14 hours ago
n8n
< 1.123.58
NPM: n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
5.3
14 hours ago
n8n
< 2.28.0
NPM: n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
5.3
14 hours ago
n8n
< 2.27.4
NPM: n8n: External Secrets Accessible via Workflow Expressions Outside Credentials
6.3
14 hours ago
Load more