The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total53,407
Mitigations17,499
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
probe-image-size<= 7.3.0
NPM: probe-image-size: Quadratic-time Denial of Service in the SVG Parser
7.5
27 minutes ago
@fastify/busboy>= 1.0.0, < 3.2.1
NPM: @fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header
7.5
28 minutes ago
@fastify/busboy>= 3.1.0, < 3.2.1
NPM: @fastify/busboy vulnerable to Denial of Service via oversized multipart boundary
7.5
29 minutes ago
@a2ui/web_core>= 0.9.0, < 0.10.2
NPM: @a2ui/web_core: `openUrl` permits `javascript:` URI execution via agent-supplied button actions
9.3
49 minutes ago
trigger.dev<= 4.5.8
NPM: Trigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values
5.5
1 hour ago
trigger.dev<= 4.5.5
NPM: Trigger.dev: Cross-environment deployment cancel
5.4
1 hour ago
trigger.dev<= 4.5.5
NPM: Trigger.dev: Cross-tenant SQL injection in the TSQL query compiler (POST /api/v1/query) via unsanitized window-function name
7.7
1 hour ago
trigger.dev<= 4.5.4
NPM: Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId
5.3
1 hour ago
trigger.dev<= 4.5.5
NPM: Trigger.dev Self-Hosted Deployment: Default Secrets allow Unauthenticated Infrastructure Compromise
8.1
1 hour ago
figlet< 1.11.3
NPM: figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width
8.2
1 hour ago
trigger.dev< 4.5.4
NPM: Trigger.dev: V1 coordinator default-secret unauth Socket.IO
9.2
1 hour ago
trigger.dev<= 4.5.1
NPM: Trigger.dev: Blind SSRF via alert-channel webhook
5.4
1 hour ago
trigger.dev<= 4.5.1
NPM: Trigger.dev: Missing Authentication in Run Replay Action Allows Cross-Organization Task Execution (IDOR)
7.1
1 hour ago
Real Cookie Banner<= 5.3.5
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
3 hours ago
Wp Social<= 3.2.1
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
3 hours ago
ProfilePress<= 4.17.4
Authenticated (Subscriber+) Sensitive Information Exposure vulnerability
4.3
3 hours ago
ProfilePress<= 4.17.4
Reflected Cross-Site Scripting vulnerability
7.1
3 hours ago
Jeg Kit for Elementor<= 3.2.19
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
3 hours ago
SEOPress<= 10.2
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
3 hours ago
Burst Statistics<= 3.7.1
Improper Authentication to Account Persistence vulnerability
4.3
3 hours ago