The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total53,232
Mitigations17,424
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
vm2>= 3.11.3, <= 3.11.6
NPM: vm2 allows a sandboxed plugin to execute native code through `node:sqlite`
9.9
16 minutes ago
vm2>= 3.11.3, <= 3.11.6
NPM: vm2 crypto builtin loads attacker native code through setEngine
9.9
17 minutes ago
vm2>= 3.10.2, <= 3.11.6
NPM: vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector
9.8
17 minutes ago
vm2>= 3.11.3, <= 3.11.6
NPM: vm2 NodeVM can replace the host process TLS trust store
10
18 minutes ago
vm2<= 3.11.6
NPM: vm2: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted
4.2
19 minutes ago
devalue>= 5.1.0, <= 5.9.2
NPM: devalue: `stringify`/`uneval` serialize shared memory
7.5
27 minutes ago
devalue<= 5.9.2
NPM: devalue: Residual sparse-array CPU amplification in uneval
6.3
28 minutes ago
devalue<= 5.9.2
NPM: devalue: Repeated primitive strings cause quadratic expansion in uneval
8.2
28 minutes ago
devalue>= 1.0.0, <= 5.9.2
NPM: devalue: Sparse arrays emitted by uneval cause eager allocation when evaluated
2.3
28 minutes ago
devalue>= 5.8.0, <= 5.9.2
NPM: devalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise
8.2
30 minutes ago
devalue<= 5.9.2
NPM: devalue: Malformed null-prototype object keys bypass __proto__ rejection via property-key coercion
6.3
32 minutes ago
piscina< 4.9.4
NPM: piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadBalancer / env
9.2
42 minutes ago
basic-ftp<= 6.2.0
NPM: basic-ftp: Quadratic-time CPU denial of service in Client.list() Unix directory-listing parser (RE_LINE backtracking)
8.2
1 hour ago
CF7 Apps<= 3.7.2
Sensitive Data Exposure vulnerability
5.3
3 hours ago
Ultimate Member<= 2.13.1
SQL Injection vulnerability
7.6
3 hours ago
Captivate Sync<= 3.3.2
SQL Injection vulnerability
7.6
3 hours ago
ProfileGrid<= 6.0.0.2
Insecure Direct Object References (IDOR) vulnerability
5.3
3 hours ago
WpTravelly<= 2.3.1
Broken Access Control vulnerability
5.4
3 hours ago
Essential Addons for Elementor<= 6.8.4
Cross Site Scripting (XSS) vulnerability
6.5
3 hours ago
Metform<= 4.3.0
Cross Site Scripting (XSS) vulnerability
6.5
3 hours ago