The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,146
Mitigations16,140
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
@dynatrace-oss/dynatrace-mcp-server<= 1.8.7
NPM: `@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation
7.5
39 minutes ago
@dynatrace-oss/dynatrace-mcp-server< 2.0.0
NPM: @dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification
4.2
44 minutes ago
@dynatrace-oss/dynatrace-mcp-server< 2.1.1
NPM: @dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL
4.3
49 minutes ago
Simply Poll <= 1.4.1
Unauthenticated SQL Injection vulnerability
9.3
7 hours ago
UsersWP< 1.2.67
Two-Factor Authentication Bypass vulnerability
7.1
7 hours ago
Meta Box AIO<= 3.8.0
Missing Authorization to Unauthenticated Arbitrary Post Deletion vulnerability
9.1
7 hours ago
WP Fast Total Search<= 1.80.280
Unauthenticated SQL Injection vulnerability
9.3
7 hours ago
Plugin Organizer<= 10.2.4
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
7 hours ago
Fluent Forms Pro Add On Pack<= 6.2.6
Authenticated (Subscriber+) PHP Object Injection to Arbitrary User Password Change vulnerability
8.8
7 hours ago
WPDM – Premium Packages<= 6.2.0
Unauthenticated SQL Injection vulnerability
9.3
8 hours ago
TrueBooker<= 1.2.2
Unauthenticated SQL Injection vulnerability
9.3
8 hours ago
Taskbuilder<= 5.0.9
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
8 hours ago
Web Directory Free<= 1.7.13
Unauthenticated SQL Injection vulnerability
9.3
9 hours ago
Demi &#8211; One Click Demo Import, Backup &amp; Site Migration<= 0.0.7
Unauthenticated Arbitrary Directory Deletion vulnerability
7.5
9 hours ago
ProfileGrid < 5.9.9.8
Unauthenticated Privilege Escalation vulnerability
9.8
9 hours ago
Customer Switching< 2.1.3
Customer+ Privilege Escalation to Administrator vulnerability
8.8
9 hours ago
@aws-amplify/codegen-ui-react<= 2.20.2
NPM: AWS Amplify Studio UI Component Properties Has an Input Validation Issue
9.5
19 hours ago
MailerPress<= 1.5.0
Missing Authorization to Unauthenticated Contact Updates vulnerability
5.3
20 hours ago
dssrf<= 1.0.3
NPM: dssrf has an SSRF bypass with remove_at_symbol_in_string
8.7
1 day ago
Uncanny Automator<= 7.3.2
Missing Authorization to Authenticated (Subscriber+) Sensitive Integration Metadata Disclosure vulnerability
7.5
1 day ago