The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total49,506
Mitigations15,981
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
@opentelemetry/propagator-jaeger< 2.9.0
NPM: OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
7.5
35 minutes ago
linkify-it<= 5.0.1
NPM: linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
7.5
36 minutes ago
aws-cdk-lib< 2.260.0
NPM: aws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling
7.3
38 minutes ago
fast-uri>= 2.3.1, < 2.4.2
NPM: fast-uri vulnerable to host confusion via failed IDN canonicalization
7.5
39 minutes ago
immutable< 4.3.9
NPM: Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
8.7
40 minutes ago
immutable< 4.3.9
NPM: Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
7.5
1 hour ago
hono>= 4.11.8, < 4.12.27
NPM: hono/jsx does not isolate context per request, leading to cross-request data disclosure
6.5
1 hour ago
hono>= 4.0.0, < 4.12.27
NPM: Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
6.1
1 hour ago
hono>= 4.3.3, < 4.12.27
NPM: Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
4.8
1 hour ago
@hono/node-server< 2.0.5
NPM: Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
5.9
1 hour ago
Easy Form Builder<= 4.0.11
Unauthenticated Privilege Escalation to Administrator vulnerability
9.8
13 hours ago
astro>= 7.0.0, < 7.0.6
NPM: Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered
5.1
20 hours ago
@astrojs/netlify< 8.1.2
NPM: @astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
3.7
20 hours ago
body-parser< 1.20.6
NPM: body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
3.7
20 hours ago
@astrojs/node>= 8.1.0, < 11.0.2
NPM: @astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
2.1
20 hours ago
astro< 7.0.6
NPM: Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
5.1
20 hours ago
@astrojs/rss>= 1.0.0, < 4.0.19
NPM: @astrojs/rss: XML Injection via Unescaped RSS Feed Fields
4.3
20 hours ago
astro>= 3.10.0, < 7.0.4
NPM: Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
2.1
20 hours ago
axios>= 0.31.1, < 0.33.0
NPM: Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
8.3
21 hours ago
axios>= 0.31.1, < 0.33.0
NPM: Axios form serializer maxDepth bypass via {} metatoken
6.9
21 hours ago