The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total53,713
Mitigations17,699
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
@socket.io/cluster-engine< 0.1.1
NPM: Socket.IO: Prototype Pollution via Unsafe Client Session Lookup
7.5
48 minutes ago
dompurify<= 3.4.15
NPM: DOMPurify: IN_PLACE returns a force-removed rawtext root whose text carries attacker markup — pure HTML reparse executes
0
48 minutes ago
smol-toml<= 1.8.0
NPM: smol-toml: Quadratic-time parse() from parseKey rescanning to end of document on each key line
5.3
51 minutes ago
katex>= 0.11.0, < 0.18.2
NPM: KaTeX: Existing prototype pollution can bypass trust restrictions
2.1
51 minutes ago
seroval>= 0.12.0, <= 1.6.0
NPM: Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of GHSA-mv8w-475r-vwqw)
9.8
52 minutes ago
seroval<= 1.6.2
NPM: Seroval: Memory exhaustion via unchecked TypedArray length in JSON deserialization
7.5
52 minutes ago
proxy-addr>= 1.1.0, < 2.0.8
NPM: proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet
9.1
1 hour ago
@nx/docker>= 21.4.0, < 22.7.8
NPM: @nx/docker: OS command injection in the @nx/docker release pipeline
7.3
1 hour ago
nx>= 14.0.0, < 22.7.8
NPM: Nx: OS command injection via git revisions and remote refs
8.5
1 hour ago
nx>= 14.6.0, < 22.7.9
NPM: Nx daemon and plugin worker sockets are accessible to other local users
8.5
1 hour ago
nx>= 13.10.0, < 22.7.10
NPM: Nx: Path traversal in nx migrate package-migrations extraction
5.8
1 hour ago
compression< 1.8.2
NPM: compression vulnerable to Denial of Service via memory leak on premature response close
7.5
1 hour ago
@openclaw/googlechat< 2026.8.1
NPM: OpenClaw: Channel read actions could skip target allowlists
6.5
1 hour ago
@openclaw/matrix< 2026.8.1
NPM: OpenClaw: Channel read actions could skip target allowlists
6.5
1 hour ago
@openclaw/feishu< 2026.8.1
NPM: OpenClaw: Channel read actions could skip target allowlists
6.5
1 hour ago
@openclaw/msteams< 2026.8.1
NPM: OpenClaw: Channel read actions could skip target allowlists
6.5
1 hour ago
vm2<= 3.12.1
NPM: vm2: NodeVM custom resolution bypasses external path boundaries
10
1 hour ago
vm2<= 3.12.1
NPM: vm2: Host Promise rejection from an exposed constructor can terminate the vm2 host process
8.6
1 hour ago
vm2<= 3.12.1
NPM: vm2: NodeVM zlib Buffers expose pooled host memory across the VM boundary
10
1 hour ago
@graphql-tools/executor-legacy-ws<= 1.1.34
NPM: GraphQL Tools: TLS Certificate Validation Disabled in Legacy GraphQL WebSocket Executor
7.4
1 hour ago