The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,536
Mitigations16,392
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
mlflow< 3.15.0
NPM: MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id
7.1
46 minutes ago
mlflow< 3.15.0
NPM: MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth
6.5
46 minutes ago
9router<= 0.5.4
NPM: 9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint
8.6
46 minutes ago
chrome-devtools-mcp>= 0.24.0, <= 1.0.1
NPM: chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots
6.1
49 minutes ago
Forminator<= 1.56.1
Unauth. Arbitrary File Upload
9.8
4 hours ago
ep_etherpad-lite<= 1.8.14
NPM: Etherpad has stored XSS in HTML export via unescaped attribute-pool values
8.7
4 hours ago
ep_etherpad-lite<= 1.8.14
NPM: Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling
0
4 hours ago
vm2<= 3.11.5
NPM: vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass
7.5
5 hours ago
vm2<= 3.11.5
NPM: vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
10
5 hours ago
vm2<= 3.11.5
NPM: vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
9.8
5 hours ago
vm2<= 3.11.5
NPM: VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE
9.9
5 hours ago
vm2<= 3.11.5
NPM: vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike
8.7
5 hours ago
Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms<= 6.0
Broken Access Control vulnerability
5.4
5 hours ago
RomethemeForm For Elementor<= 1.2.6
Broken Access Control vulnerability
4.3
5 hours ago
WP Table Builder<= 2.2.0
Broken Access Control vulnerability
4.3
5 hours ago
3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery<= 1.16.20
Sensitive Data Exposure vulnerability
5.3
5 hours ago
Shortcodes and extra features for Phlox theme<= 2.17.22
Sensitive Data Exposure vulnerability
5.3
5 hours ago
Razorpay for WooCommerce<= 4.8.7
Insecure Direct Object References (IDOR) vulnerability
5.3
5 hours ago
@medplum/core<= 5.1.5
NPM: Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage
7.1
9 hours ago
deepmerge-ts< 8.0.0
NPM: DeepmergeTS has stack exhaustion when merging recursive object graphs
8.2
9 hours ago