The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total49,708
Mitigations16,012
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
postcss<= 8.5.11
NPM: PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
7.5
54 minutes ago
next-auth>= 5.0.0-beta.0, <= 5.0.0-beta.31
NPM: Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
9.1
1 hour ago
next-auth>= 4.0.6, <= 4.24.14
NPM: Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
7.5
1 hour ago
@auth/core>= 0.1.0, < 0.41.3
NPM: Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
7.5
1 hour ago
next-auth>= 4.10.3, < 4.24.15
NPM: Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
9.1
1 hour ago
@auth/core>= 0.1.0, < 0.41.3
NPM: Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
9.1
1 hour ago
next-auth<= 4.24.14
NPM: Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
6.8
1 hour ago
@auth/core<= 0.41.2
NPM: Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
6.8
1 hour ago
n8n< 1.123.67
NPM: n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
5.3
16 hours ago
n8n< 1.123.67
NPM: n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
5.8
16 hours ago
n8n< 1.123.67
NPM: n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
5.8
16 hours ago
next>= 14.1.1, < 15.5.21
NPM: Next.js: Server-Side Request Forgery in Server Actions on custom servers
8.3
16 hours ago
next>= 13.0.0, < 15.5.21
NPM: Next.js: Cache confusion of response bodies for requests with bodies
6
16 hours ago
next>= 13.0.0, < 15.5.21
NPM: Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
6.3
16 hours ago
next>= 13.0.0, < 15.5.21
NPM: Next.js: Unbounded Server Action payload in Edge runtime
6.3
16 hours ago
next>= 12.0.0, < 15.5.21
NPM: Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
8.3
16 hours ago
next>= 15.5.0, < 15.5.21
NPM: Next.js: Denial of Service in the Image Optimization API using SVGs
6.3
16 hours ago
next>= 13.0.0, < 15.5.21
NPM: Next.js: Unauthenticated disclosure of internal Server Function endpoints
6.3
17 hours ago
next>= 16.0.0, < 16.2.11
NPM: Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
8.3
17 hours ago
next>= 13.0.0, < 15.5.21
NPM: Next.js: Denial of Service in App Router using Server Actions
8.2
17 hours ago