The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total53,009
Mitigations17,321
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Easy Pricing Tables<= 4.1.2
SQL Injection vulnerability
8.5
1 minute ago
Two Factor<= 0.16.0
Denial of Service Attack vulnerability
5.3
5 minutes ago
Prevent files / folders access<= 2.6.7
Broken Access Control vulnerability
4.3
7 minutes ago
Astra WordPress Theme<= 4.13.12
Content Injection vulnerability
2.7
13 minutes ago
Virtue Premium<= 4.10.22
Cross Site Scripting (XSS) vulnerability
6.5
33 minutes ago
Virtue Premium<= 4.10.21
Cross Site Scripting (XSS) vulnerability
6.5
35 minutes ago
ReactPress<= 3.4.0
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
54 minutes ago
Real Estate Manager<= 7.3
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
58 minutes ago
Frontend Post Submission Manager Lite<= 1.3.4
Unauthenticated Stored DOM-Based Cross-Site Scripting vulnerability
7.1
1 hour ago
Post Views Stats Counter<= 1.1.7
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
1 hour ago
Product Designer App<= 1.1.3
Unauthenticated Arbitrary File Read vulnerability
7.5
1 hour ago
Simply Schedule Appointments<= 1.6.12.27
Authenticated (Subscriber+) Local File Inclusion vulnerability
7.5
1 hour ago
@nestjs/microservices< 11.2.4
NPM: Nest: Remote process termination via a deeply nested microservice message pattern
7.5
8 hours ago
fast-uri< 2.4.7
NPM: fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets
4.8
8 hours ago
fast-uri>= 4.1.3, < 4.1.5
NPM: fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization
4.8
8 hours ago
@xhmikosr/decompress<= 10.2.1
NPM: @xhmikosr/decompress: Path traversal via symlink chain
9.1
8 hours ago
decompress<= 4.2.1
NPM: @xhmikosr/decompress: Path traversal via symlink chain
9.1
8 hours ago
ip-address<= 10.7.0
NPM: ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range
6.3
8 hours ago
ip-address<= 10.7.0
NPM: ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process
6.3
8 hours ago
moment>= 2.29.2, < 2.31.0
NPM: moment vulnerable to Path Traversal via crafted non-string locale name
5.9
8 hours ago