Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
49,805
Mitigations
Mitigation rules
16,024
No official patch
13,126
In triage
1,241
Published soon
11
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@frontmcp/adapters
<= 1.5.5
NPM: FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
5.9
23 hours ago
quasar
<= 2.21.4
NPM: Quasar: Prototype pollution in the extend() utility
5.6
23 hours ago
shescape
>= 2.1.11, < 2.1.14
NPM: Shescape: Quadratic-time denial of service in the flag-protection
8.7
23 hours ago
shescape
< 2.1.14
NPM: Shescape: Home-directory disclosure in assignment context on Unix with Dash
6.3
23 hours ago
shescape
< 2.1.14
NPM: Shescape: Shell injection via unescaped parentheses on Windows with CMD
9.2
23 hours ago
shescape
< 2.1.14
NPM: Shescape: Path disclosure on Unix with Zsh
6.3
23 hours ago
brace-expansion
<= 5.0.7
NPM: brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
7.5
23 hours ago
sm-crypto
< 0.5.0
NPM: sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
9.1
23 hours ago
@anephenix/hub
< 0.2.16
NPM: @anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
7.5
1 day ago
@budibase/server
<= 3.38.1
NPM: Budibase: SSRF via bare fetch() in uploadUrl during AI table generation
4.9
1 day ago
@budibase/server
<= 3.38.1
NPM: Budibase: SSRF via DNS rebinding in the REST datasource integration
8.5
1 day ago
@budibase/server
<= 3.38.1
NPM: Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete
7.1
1 day ago
@budibase/server
<= 3.38.1
NPM: Budibase: Account Enumeration via Login Lockout Response Differential
5.3
1 day ago
@budibase/server
<= 3.38.1
NPM: Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
7.7
1 day ago
@budibase/server
<= 3.38.1
NPM: Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
7.6
1 day ago
@budibase/server
<= 3.38.1
NPM: Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
8.3
1 day ago
@budibase/server
<= 3.38.1
NPM: Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders
5.7
1 day ago
@budibase/server
<= 3.38.1
NPM: Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
7.5
1 day ago
@budibase/server
<= 3.38.1
NPM: Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
0
1 day ago
@budibase/server
<= 3.38.1
NPM: Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
9
1 day ago
Load more