Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,107
Mitigations
Mitigation rules
16,167
No official patch
13,193
In triage
1,105
Published soon
30
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
nuxt
>= 3.1.0, < 3.21.10
NPM: Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
7.5
1 hour ago
nuxt
>= 3.4.0, < 3.21.10
NPM: Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
8.1
2 hours ago
@nuxt/devtools
< 3.3.1
NPM: Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
9.6
2 hours ago
nuxt
>= 3.1.0, < 3.21.10
NPM: Nuxt: Unauthorized Component Instantiation via Server Island Props
4.8
2 hours ago
nuxt
>= 4.4.0, <= 4.5.0
NPM: Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
7.5
2 hours ago
nuxt
>= 3.21.7, < 3.21.10
NPM: Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
8.2
2 hours ago
nuxt
>= 3.1.0, < 3.21.10
NPM: Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
7.5
2 hours ago
electron
< 39.8.8
NPM: Electron: Sandboxed iframes can launch external protocol handlers
5.4
5 hours ago
electron
< 39.8.9
NPM: Electron: DevTools embedder handler executes arbitrary files via shell open
6.9
5 hours ago
electron
< 39.8.9
NPM: Electron: contextBridge object copy honors prototype setters
5.4
5 hours ago
electron
< 39.8.7
NPM: Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
5.7
6 hours ago
electron
< 39.8.10
NPM: Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
7.2
6 hours ago
electron
< 39.8.8
NPM: Electron: window.open features string controls some window options considered privileged
5.3
7 hours ago
electron
>= 40.0.0-alpha.1, < 40.10.6
NPM: Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
5.9
7 hours ago
electron
< 39.8.8
NPM: Electron: HTTP redirect followed into local file loader
5.9
7 hours ago
electron
< 39.8.10
NPM: Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
7.4
7 hours ago
electron
< 39.8.8
NPM: Electron: Extension tab APIs operate across session boundaries
6.6
7 hours ago
electron
< 39.8.6
NPM: Electron: shell.openPath path validation bypass via embedded null byte
6
7 hours ago
electron
< 39.8.9
NPM: Electron: Context isolation bypass via Function.prototype.bind hijack
7.5
7 hours ago
electron
< 39.8.8
NPM: Electron: Cross-origin iframe can position native autofill popup
3.1
7 hours ago
Load more