The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total53,242
Mitigations17,424
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
DevKit Pro<= 2.3.0
Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow vulnerability
9.8
5 minutes ago
vm2>= 3.11.4, <= 3.11.6
NPM: vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks
6.8
16 minutes ago
vm2>= 3.9.6, <= 3.11.6
NPM: vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape
9.9
17 minutes ago
vm2<= 3.11.6
host-realm require() is reachable from sandboxed scripts
8.6
18 minutes ago
vm2>= 3.11.3, <= 3.11.6
NPM: vm2 exposes host HTTPS credentials and TLS traffic through globalAgent
10
20 minutes ago
vm2<= 3.11.6
NPM: vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package
9.9
21 minutes ago
vm2<= 3.11.6
NPM: vm2: NodeVM builtin denylist bypass via fs/promises despite -fs, allowing host filesystem writes
8.5
22 minutes ago
vm2<= 3.11.6
NPM: vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process
9.9
22 minutes ago
vm2>= 3.9.6, <= 3.11.6
NPM: vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor
4
23 minutes ago
vm2>= 3.11.4, <= 3.11.6
NPM: vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE
9
24 minutes ago
vm23.11.6
NPM: vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection
10
26 minutes ago
vm2>= 3.11.3, <= 3.11.6
NPM: vm2 allows a sandboxed plugin to execute native code through `node:sqlite`
9.9
29 minutes ago
vm2>= 3.11.3, <= 3.11.6
NPM: vm2 crypto builtin loads attacker native code through setEngine
9.9
30 minutes ago
vm2>= 3.10.2, <= 3.11.6
NPM: vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector
9.8
30 minutes ago
vm2>= 3.11.3, <= 3.11.6
NPM: vm2 NodeVM can replace the host process TLS trust store
10
31 minutes ago
vm2<= 3.11.6
NPM: vm2: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted
4.2
32 minutes ago
devalue>= 5.1.0, <= 5.9.2
NPM: devalue: `stringify`/`uneval` serialize shared memory
7.5
40 minutes ago
devalue<= 5.9.2
NPM: devalue: Residual sparse-array CPU amplification in uneval
6.3
41 minutes ago
devalue<= 5.9.2
NPM: devalue: Repeated primitive strings cause quadratic expansion in uneval
8.2
41 minutes ago
devalue>= 1.0.0, <= 5.9.2
NPM: devalue: Sparse arrays emitted by uneval cause eager allocation when evaluated
2.3
41 minutes ago