Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,973
Mitigations
Mitigation rules
17,315
No official patch
13,368
In triage
1,425
Published soon
38
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
adm-zip
<= 0.6.0
NPM: adm-zip: Decompression-bomb protection (fix for CVE-2026-39244) can be bypassed by declaring uncompressed size as 0
7.5
24 minutes ago
adm-zip
<= 0.6.0
NPM: adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation
7.1
25 minutes ago
nodemailer
< 10.0.2
NPM: Nodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS
5.9
26 minutes ago
undici
>= 7.11.0, < 7.29.1
NPM: undici vulnerable to Denial of Service via orphaned RetryHandler response body
5.9
27 minutes ago
undici
< 6.28.1
NPM: undici vulnerable to downstream response splitting via retry interceptor
3.7
27 minutes ago
undici
>= 6.7.0, < 6.28.1
NPM: undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
7.5
28 minutes ago
undici
>= 7.15.0, < 7.29.1
NPM: undici vulnerable to Denial of Service via unbounded decompression of compressed responses
5.9
29 minutes ago
undici
>= 7.0.0, < 7.29.1
NPM: undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches
6.5
30 minutes ago
undici
>= 7.1.0, < 7.29.1
NPM: undici vulnerable to response truncation via oversized chunked responses in the dump interceptor
3.7
31 minutes ago
undici
>= 7.24.1, < 7.29.1
NPM: undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool
7.4
32 minutes ago
undici
>= 7.0.0, < 7.29.1
NPM: undici vulnerable to caching and replay of unsafe HTTP method responses
3.7
33 minutes ago
undici
>= 8.10.0, < 8.10.2
NPM: undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors
7.4
34 minutes ago
undici
>= 7.0.0, < 7.29.1
NPM: undici vulnerable to Denial of Service via WebSocketStream unclean close
5.9
39 minutes ago
joi
>= 17.2.0, < 17.13.7
NPM: joi: Quadratic regular-expression backtracking in `Joi.string().isoDate()`
7.5
42 minutes ago
electron
< 39.8.10
NPM: Electron: Local race condition in Squirrel.Mac update installation on macOS
6.7
43 minutes ago
electron
< 41.10.4
NPM: Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab
8.2
44 minutes ago
electron
< 41.10.6
NPM: Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions
8.2
44 minutes ago
electron
< 41.10.6
NPM: Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled
7.4
45 minutes ago
electron
< 41.10.6
NPM: Electron: <webview> can enable Node.js integration in Web Workers despite embedder restrictions
8.3
47 minutes ago
electron
>= 42.3.3, < 42.10.0
NPM: Electron: Sandboxed preload code cache can be poisoned by a compromised renderer
7.8
48 minutes ago
Load more