Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,973
Mitigations
Mitigation rules
17,315
No official patch
13,368
In triage
1,425
Published soon
38
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
adm-zip
<= 0.6.0
NPM: adm-zip: Decompression-bomb protection (fix for CVE-2026-39244) can be bypassed by declaring uncompressed size as 0
7.5
2 hours ago
adm-zip
<= 0.6.0
NPM: adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation
7.1
2 hours ago
nodemailer
< 10.0.2
NPM: Nodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS
5.9
2 hours ago
undici
>= 7.11.0, < 7.29.1
NPM: undici vulnerable to Denial of Service via orphaned RetryHandler response body
5.9
2 hours ago
undici
< 6.28.1
NPM: undici vulnerable to downstream response splitting via retry interceptor
3.7
2 hours ago
undici
>= 6.7.0, < 6.28.1
NPM: undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
7.5
2 hours ago
undici
>= 7.15.0, < 7.29.1
NPM: undici vulnerable to Denial of Service via unbounded decompression of compressed responses
5.9
2 hours ago
undici
>= 7.0.0, < 7.29.1
NPM: undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches
6.5
2 hours ago
undici
>= 7.1.0, < 7.29.1
NPM: undici vulnerable to response truncation via oversized chunked responses in the dump interceptor
3.7
2 hours ago
undici
>= 7.24.1, < 7.29.1
NPM: undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool
7.4
2 hours ago
undici
>= 7.0.0, < 7.29.1
NPM: undici vulnerable to caching and replay of unsafe HTTP method responses
3.7
2 hours ago
undici
>= 8.10.0, < 8.10.2
NPM: undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors
7.4
2 hours ago
undici
>= 7.0.0, < 7.29.1
NPM: undici vulnerable to Denial of Service via WebSocketStream unclean close
5.9
2 hours ago
joi
>= 17.2.0, < 17.13.7
NPM: joi: Quadratic regular-expression backtracking in `Joi.string().isoDate()`
7.5
2 hours ago
electron
< 39.8.10
NPM: Electron: Local race condition in Squirrel.Mac update installation on macOS
6.7
2 hours ago
electron
< 41.10.4
NPM: Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab
8.2
2 hours ago
electron
< 41.10.6
NPM: Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions
8.2
2 hours ago
electron
< 41.10.6
NPM: Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled
7.4
2 hours ago
electron
< 41.10.6
NPM: Electron: <webview> can enable Node.js integration in Web Workers despite embedder restrictions
8.3
2 hours ago
electron
>= 42.3.3, < 42.10.0
NPM: Electron: Sandboxed preload code cache can be poisoned by a compromised renderer
7.8
2 hours ago
Load more