The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total49,510
Mitigations15,981
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
svgo>= 1.0.0, < 2.8.3
NPM: SVGO removeScripts plugin leaves some executable scripts intact
8.2
1 hour ago
dompurify<= 3.4.11
NPM: DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
2.1
1 hour ago
@vitest/browser< 3.2.7
NPM: @vitest/browser: Browser Mode provider commands bypass the file-access permission gate
9.4
1 hour ago
@sigstore/oci< 0.7.1
NPM: Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
9.6
1 hour ago
@opentelemetry/propagator-jaeger< 2.9.0
NPM: OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
7.5
2 hours ago
linkify-it<= 5.0.1
NPM: linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
7.5
2 hours ago
aws-cdk-lib< 2.260.0
NPM: aws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling
7.3
2 hours ago
fast-uri>= 2.3.1, < 2.4.2
NPM: fast-uri vulnerable to host confusion via failed IDN canonicalization
7.5
2 hours ago
immutable< 4.3.9
NPM: Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
8.7
2 hours ago
immutable< 4.3.9
NPM: Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
7.5
2 hours ago
hono>= 4.11.8, < 4.12.27
NPM: hono/jsx does not isolate context per request, leading to cross-request data disclosure
6.5
2 hours ago
hono>= 4.0.0, < 4.12.27
NPM: Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
6.1
2 hours ago
hono>= 4.3.3, < 4.12.27
NPM: Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
4.8
3 hours ago
@hono/node-server< 2.0.5
NPM: Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
5.9
3 hours ago
Easy Form Builder<= 4.0.11
Unauthenticated Privilege Escalation to Administrator vulnerability
9.8
14 hours ago
astro>= 7.0.0, < 7.0.6
NPM: Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered
5.1
22 hours ago
@astrojs/netlify< 8.1.2
NPM: @astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
3.7
22 hours ago
body-parser< 1.20.6
NPM: body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
3.7
22 hours ago
@astrojs/node>= 8.1.0, < 11.0.2
NPM: @astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
2.1
22 hours ago
astro< 7.0.6
NPM: Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
5.1
22 hours ago