The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,233
Mitigations16,188
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
GiveWP< 4.16.3
Unauthenticated Payment Gateway Restriction Bypass vulnerability
5.3
13 minutes ago
Link Library< 7.9.4
Reflected Cross-Site Scripting vulnerability
7.1
35 minutes ago
Kirki< 6.0.13
Unauthenticated PHP Object Injection vulnerability
9.8
40 minutes ago
Survey Maker< 5.1.7.7
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
45 minutes ago
Realtyna Organic IDX plugin<= 5.3.0
Authenticated (Subscriber+) Arbitrary File Upload vulnerability
8.8
57 minutes ago
WP Go Maps< 10.1.04
Unauthenticated SQL Injection vulnerability
9.3
1 hour ago
FluentCart< 1.5.3
Unauthenticated Order PII Disclosure vulnerability
7.5
1 hour ago
FlxWoo< 3.1.1
Unauthenticated Payment Bypass vulnerability
7.5
1 hour ago
Realtyna Organic IDX plugin<= 5.2.0
Unauthenticated Arbitrary File Upload vulnerability
10
1 hour ago
sequelize< 6.37.4
NPM: Sequelize: SQL Injection (Oracle DB)
9.8
11 hours ago
hono< 4.12.34
NPM: Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
5.3
11 hours ago
ip-address<= 10.3.0
NPM: ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
7.7
11 hours ago
ip-address>= 10.1.1, <= 10.2.1
NPM: ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks
6.9
11 hours ago
ip-address>= 10.1.1, <= 10.2.0
NPM: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
6.9
12 hours ago
undici< 6.28.0
NPM: undici vulnerable to CRLF Injection via blob-like body 'type' property
4.2
12 hours ago
undici>= 7.0.0, < 7.29.0
NPM: undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
5.9
12 hours ago
undici< 6.28.0
NPM: undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
4.8
12 hours ago
undici< 6.28.0
NPM: undici vulnerable to downstream response desynchronization via retry interceptor
4.8
12 hours ago
undici>= 7.0.0, < 7.29.0
NPM: undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
7.4
12 hours ago
fast-uri< 2.4.4
NPM: fast-uri vulnerable to host confusion via backslash authority introducer
7.5
12 hours ago