The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total51,591
Mitigations16,860
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
fast-uri>= 2.4.2, < 2.4.5
NPM: fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references
7.5
2 hours ago
fast-uri>= 2.3.1, < 2.4.5
NPM: fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
7.5
2 hours ago
fast-uri>= 2.4.1, < 2.4.5
NPM: fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding
7.5
2 hours ago
fast-uri>= 2.3.1, < 2.4.5
NPM: fast-uri vulnerable to host confusion via percent-encoded scheme normalization
7.5
2 hours ago
@xmldom/xmldom>= 0.7.0, <= 0.8.14
NPM: xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization
6.3
3 hours ago
xmldom<= 0.6.0
NPM: xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization
6.3
3 hours ago
fastify>= 5.8.3, < 5.12.1
NPM: fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count
6.1
3 hours ago
fastify< 5.12.1
NPM: fastify vulnerable to schema validation bypass via root primitive coercion mismatch
5.4
3 hours ago
apostrophe<= 4.32.0
NPM: ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS
7.1
3 hours ago
@apostrophecms/import-export<= 3.6.1
NPM: ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal
6.5
3 hours ago
orval< 8.22.0
NPM: Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
7.1
3 hours ago
orval< 8.21.0
NPM: Orval: Import-time RCE via query-parameter default -> zod module-level template literal
9.3
3 hours ago
orval< 8.21.0
NPM: Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client
9.3
3 hours ago
@aborruso/ckan-mcp-server< 0.4.112
NPM: CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)
5.3
3 hours ago
qs>= 6.14.2, <= 6.15.3
NPM: qs array-limit bypass via bracket-key comma parsing
3.7
3 hours ago
qs>= 2.2.5, < 6.16.0
NPM: qs: Denial of Service via Attacker Controlled isBuffer
5.3
3 hours ago
@tiptap/core>= 2.0.0-alpha.0, < 3.30.4
NPM: Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes
6.4
3 hours ago
pnpm< 10.34.5
NPM: pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraph
7.1
3 hours ago
pnpm< 10.34.5
NPM: pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install
7.5
3 hours ago
@humanfs/node< 0.16.8
NPM: humanfs: Recursive copy follows symlinked files and copies data from outside the source tree
5.7
3 hours ago