The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total49,468
Mitigations15,973
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
astro>= 6.4.7, < 6.4.8
NPM: Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
8.2
9 minutes ago
tar<= 7.5.17
NPM: node-tar: Process crash via PAX numeric path type confusion
5.3
14 minutes ago
tar<= 7.5.18
NPM: node-tar: Decompression/parse DoS via unlimited input
7.5
15 minutes ago
tar<= 7.5.17
NPM: node-tar: Negative tar entry size causes infinite loop in archive replace
7.5
16 minutes ago
tar<= 7.5.16
NPM: node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
5.3
16 minutes ago
engine.io>= 4.1.0, < 6.6.7
NPM: Socket.IO: Engine.IO Polling Transport Connection Exhaustion
7.5
17 minutes ago
shell-quote<= 1.8.4
NPM: shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
7.5
18 minutes ago
directus< 12.0.0
NPM: Directus: Authorization-dependent response served from unsegmented cache key
8.6
19 minutes ago
directus< 12.0.0
NPM: Directus: SSRF Protection Bypass via 0.0.0.0 in File Import
7.7
20 minutes ago
js-yaml>= 5.0.0, <= 5.1.0
NPM: js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml
5.3
48 minutes ago
js-yaml>= 3.0.0, < 3.15.0
NPM: js-yaml: YAML merge-key chains can force quadratic CPU consumption
7.5
48 minutes ago
js-yaml>= 5.0.0, <= 5.2.0
NPM: js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA
5.3
48 minutes ago
astro>= 2.9.0, <= 7.0.9
NPM: Astro: Reflected XSS via unescaped View Transition animation properties
5.3
59 minutes ago
@better-auth/sso>= 1.2.10, < 1.6.11
NPM: @better-auth/sso: SSO provider may allow registration for any org member without a checking their role
7.1
1 hour ago
brace-expansion< 1.1.16
NPM: brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
5.3
1 hour ago
Essential Addons for Elementor<= 6.6.11
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
2 hours ago
Tutor LMS Elementor Addons<= 4.0.0
Missing Authorization to Authenticated (Subscriber+) Tutor LMS and Elementor Plugin Activation vulnerability
4.3
2 hours ago
MapSVG<= 8.14.0
Authenticated (Administrator+) Arbitrary File Upload vulnerability
9.1
2 hours ago
axios>= 0.28.0, < 0.33.0
NPM: Axios: Excessive recursion in formDataToJSON can cause denial of service
6.3
4 hours ago
axios>= 1.15.2, < 1.18.0
NPM: Axios: Prototype pollution auth subfields can inject Basic auth
6.3
4 hours ago