The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,990
Mitigations17,315
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
@nestjs/microservices< 11.2.4
NPM: Nest: Remote process termination via a deeply nested microservice message pattern
7.5
3 hours ago
fast-uri< 2.4.7
NPM: fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets
4.8
3 hours ago
fast-uri>= 4.1.3, < 4.1.5
NPM: fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization
4.8
3 hours ago
@xhmikosr/decompress<= 10.2.1
NPM: @xhmikosr/decompress: Path traversal via symlink chain
9.1
3 hours ago
decompress<= 4.2.1
NPM: @xhmikosr/decompress: Path traversal via symlink chain
9.1
3 hours ago
ip-address<= 10.7.0
NPM: ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range
6.3
3 hours ago
ip-address<= 10.7.0
NPM: ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process
6.3
3 hours ago
moment>= 2.29.2, < 2.31.0
NPM: moment vulnerable to Path Traversal via crafted non-string locale name
5.9
3 hours ago
brace-expansion< 1.1.21
NPM: brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service
5.3
3 hours ago
brace-expansion< 1.1.20
NPM: brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
7.5
3 hours ago
brace-expansion< 1.1.19
NPM: brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
7.5
3 hours ago
engine.io>= 6.6.0, < 6.6.10
NPM: Socket.IO: Engine.IO Protocol Revision Mismatch DoS
7.5
3 hours ago
nodemailer>= 9.1.0, < 10.0.9
NPM: Nodemailer: Quoted local-part can produce malformed envelope recipient through RFC 5322 comment parsing
5.3
3 hours ago
nodemailer<= 10.0.5
NPM: Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service
7.5
3 hours ago
adm-zip<= 0.6.0
NPM: adm-zip: Duplicate ZIP entry names: getEntry() and extractAllTo() resolve to different content
5.9
4 hours ago
adm-zip<= 0.6.0
NPM: adm-zip: getDataAsync() bypasses the maxOutputLength size guard enforced by the synchronous getData() path
5.3
4 hours ago
adm-zip<= 0.6.0
NPM: adm-zip: Unhandled error event in async DEFLATE decompression crashes Node.js process (DoS)
7.5
4 hours ago
adm-zip<= 0.6.0
NPM: adm-zip: Decompression-bomb protection (fix for CVE-2026-39244) can be bypassed by declaring uncompressed size as 0
7.5
9 hours ago
adm-zip<= 0.6.0
NPM: adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation
7.1
9 hours ago
nodemailer< 10.0.2
NPM: Nodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS
5.9
9 hours ago