The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total53,756
Mitigations17,716
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
payload>= 3.0.0, < 3.90.0
NPM: Payload: Password hashes use insufficient PBKDF2 iterations
5.7
26 minutes ago
payload< 3.88.0
NPM: Payload: Sort queries could expose protected field information
6.9
26 minutes ago
@modelcontextprotocol/client>= 2.0.0, < 2.2.0
NPM: MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server
7.5
29 minutes ago
@modelcontextprotocol/sdk>= 1.12.0, < 1.31.0
NPM: MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server
7.5
29 minutes ago
i18next-http-backend< 4.0.2
NPM: i18next-http-backend incomplete URL validation permits SSRF
3.7
31 minutes ago
@langchain/redis<= 1.1.0
NPM: LangChain: RediSearch Filter Injection via Unescaped Tag/Text Values
2.3
32 minutes ago
sharp< 0.35.5
NPM: sharp : Vulnerability in librsvg dependency CVE-2026-96889
8.9
2 hours ago
shell-quote>= 1.8.4, < 1.11.0
NPM: shell-quote: `quote()` command injection via a line terminator in a token after a `{ comment }` token
8.1
2 hours ago
pbkdf2<= 3.1.6
NPM: pbkdf2 rehashes long passwords on every iteration, enabling denial of service
3.7
2 hours ago
elegro Crypto Payment<= 1.0.1
Unauthenticated Arbitrary Order Status Change vulnerability
5.3
4 hours ago
Deema Payment Gateway<= 1.1.2
Unauthenticated Payment Confirmation Forgery vulnerability
5.3
6 hours ago
Deema Payment Gateway<= 1.1.2
Unauthenticated Payment Bypass and Order Manipulation vulnerability
5.3
6 hours ago
JetElements For Elementor<= 2.9.2.2
Cross Site Scripting (XSS) vulnerability
6.5
7 hours ago
Slider Pro<= 1.0.0
Unauthenticated Sensitive Data Disclosure vulnerability
5.3
10 hours ago
File Media Renamer<= 1.3
Author+ Arbitrary File Rename vulnerability
6.5
10 hours ago
Fast Courier<= 5.2.3
Unauthenticated Order Fulfillment Update vulnerability
5.3
10 hours ago
@simple-git/argv-parser< 2.0.1
NPM: simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection
9.2
16 hours ago
simple-git>= 3.15.0, < 4.0.1
NPM: simple-git unsafe-operation guard does not block trailer command configuration
9.2
16 hours ago
simple-git<= 3.36.0
NPM: simple-git allows command execution through unblocked Git configuration includes
8.1
16 hours ago
simple-git<= 3.36.0
NPM: simple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/--exe) -> command execution (residual of CVE-2026-28291)
8.1
16 hours ago