Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
53,232
Mitigations
Mitigation rules
17,424
No official patch
13,358
In triage
1,280
Published soon
52
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
vm2
>= 3.11.3, <= 3.11.6
NPM: vm2 allows a sandboxed plugin to execute native code through `node:sqlite`
9.9
16 minutes ago
vm2
>= 3.11.3, <= 3.11.6
NPM: vm2 crypto builtin loads attacker native code through setEngine
9.9
17 minutes ago
vm2
>= 3.10.2, <= 3.11.6
NPM: vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector
9.8
17 minutes ago
vm2
>= 3.11.3, <= 3.11.6
NPM: vm2 NodeVM can replace the host process TLS trust store
10
18 minutes ago
vm2
<= 3.11.6
NPM: vm2: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted
4.2
19 minutes ago
devalue
>= 5.1.0, <= 5.9.2
NPM: devalue: `stringify`/`uneval` serialize shared memory
7.5
27 minutes ago
devalue
<= 5.9.2
NPM: devalue: Residual sparse-array CPU amplification in uneval
6.3
28 minutes ago
devalue
<= 5.9.2
NPM: devalue: Repeated primitive strings cause quadratic expansion in uneval
8.2
28 minutes ago
devalue
>= 1.0.0, <= 5.9.2
NPM: devalue: Sparse arrays emitted by uneval cause eager allocation when evaluated
2.3
28 minutes ago
devalue
>= 5.8.0, <= 5.9.2
NPM: devalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise
8.2
30 minutes ago
devalue
<= 5.9.2
NPM: devalue: Malformed null-prototype object keys bypass __proto__ rejection via property-key coercion
6.3
32 minutes ago
piscina
< 4.9.4
NPM: piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadBalancer / env
9.2
42 minutes ago
basic-ftp
<= 6.2.0
NPM: basic-ftp: Quadratic-time CPU denial of service in Client.list() Unix directory-listing parser (RE_LINE backtracking)
8.2
1 hour ago
CF7 Apps
<= 3.7.2
Sensitive Data Exposure vulnerability
5.3
3 hours ago
Ultimate Member
<= 2.13.1
SQL Injection vulnerability
7.6
3 hours ago
Captivate Sync
<= 3.3.2
SQL Injection vulnerability
7.6
3 hours ago
ProfileGrid
<= 6.0.0.2
Insecure Direct Object References (IDOR) vulnerability
5.3
3 hours ago
WpTravelly
<= 2.3.1
Broken Access Control vulnerability
5.4
3 hours ago
Essential Addons for Elementor
<= 6.8.4
Cross Site Scripting (XSS) vulnerability
6.5
3 hours ago
Metform
<= 4.3.0
Cross Site Scripting (XSS) vulnerability
6.5
3 hours ago
Load more