The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,784
Mitigations17,235
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
cline< 3.0.30
NPM: Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` endpoint)
8.8
13 minutes ago
@rsdoctor/rspack-plugin<= 1.5.15
NPM: @rsdoctor/rspack-plugin has Unauthenticated HTTP API that Exposes Project Source Code and Build Metadata
7.5
20 minutes ago
@bytebase/dbhub< 0.22.6
NPM: @bytebase/dbhub's read-only mode does not prevent database writes
7.4
24 minutes ago
@bytebase/dbhub<= 0.22.4
NPM: DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution
9.3
25 minutes ago
xhtml-purifier<= 0.4.1
NPM: xhtml-purifier has HTML attribute-injection (sanitizer bypass) that leads to XSS
6.1
28 minutes ago
@bsv/wallet-toolbox>= 1.1.47, < 2.4.0
NPM: `@bsv/wallet-toolbox` / `-client` / `-mobile` don't verify storage-supplied recipient output scripts against caller-requested outputs in createAction
8.7
30 minutes ago
@bsv/wallet-toolbox-client>= 1.1.47, < 2.4.0
NPM: `@bsv/wallet-toolbox` / `-client` / `-mobile` don't verify storage-supplied recipient output scripts against caller-requested outputs in createAction
8.7
30 minutes ago
@bsv/wallet-toolbox-mobile>= 1.3.21, < 2.4.0
NPM: `@bsv/wallet-toolbox` / `-client` / `-mobile` don't verify storage-supplied recipient output scripts against caller-requested outputs in createAction
8.7
30 minutes ago
cyberchef< 11.2.0
NPM: CyberChef: Prototype pollution in Series Chart operation
5
37 minutes ago
@aws/lsp-codewhisperer< 0.0.117
NPM: Language Servers for AWS vulnerable to arbitrary file write
7.8
46 minutes ago
@aws/lsp-codewhisperer< 0.0.113
NPM: Language Servers for AWS Vulnerable to Arbitrary Code Execution
8.5
48 minutes ago
suneditor<= 2.47.10
sanitizer bypass
10
5 hours ago
King Addons for Elementor<= 51.1.85
Cross Site Scripting (XSS) vulnerability
6.5
9 hours ago
Pixel Manager for WooCommerce<= 1.69.0
Cross Site Scripting (XSS) vulnerability
6.5
9 hours ago
Business Directory<= 6.4.27
Insecure Direct Object References (IDOR) vulnerability
5.4
9 hours ago
The Plus Addons for Elementor Page Builder Lite<= 6.5.1
Cross Site Scripting (XSS) vulnerability
6.5
9 hours ago
Simply Schedule Appointments<= 1.6.12.31
Insecure Direct Object References (IDOR) vulnerability
5.3
9 hours ago
Blacklist Manager &#8211; WooCommerce Anti-Fraud, Blacklist &amp; Checkout Verification<= 2.3.1
Cross Site Request Forgery (CSRF) vulnerability
8.8
9 hours ago
GiveWP<= 4.16.9
Insecure Direct Object References (IDOR) vulnerability
5.3
9 hours ago
Client Invoicing by Sprout Invoices<= 20.8.17
Insecure Direct Object References (IDOR) vulnerability
5.3
9 hours ago