Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
53,242
Mitigations
Mitigation rules
17,425
No official patch
13,358
In triage
1,268
Published soon
52
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
DevKit Pro
<= 2.3.0
Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow vulnerability
9.8
51 minutes ago
vm2
>= 3.11.4, <= 3.11.6
NPM: vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks
6.8
1 hour ago
vm2
>= 3.9.6, <= 3.11.6
NPM: vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape
9.9
1 hour ago
vm2
<= 3.11.6
host-realm require() is reachable from sandboxed scripts
8.6
1 hour ago
vm2
>= 3.11.3, <= 3.11.6
NPM: vm2 exposes host HTTPS credentials and TLS traffic through globalAgent
10
1 hour ago
vm2
<= 3.11.6
NPM: vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package
9.9
1 hour ago
vm2
<= 3.11.6
NPM: vm2: NodeVM builtin denylist bypass via fs/promises despite -fs, allowing host filesystem writes
8.5
1 hour ago
vm2
<= 3.11.6
NPM: vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process
9.9
1 hour ago
vm2
>= 3.9.6, <= 3.11.6
NPM: vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor
4
1 hour ago
vm2
>= 3.11.4, <= 3.11.6
NPM: vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE
9
1 hour ago
vm2
3.11.6
NPM: vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection
10
1 hour ago
vm2
>= 3.11.3, <= 3.11.6
NPM: vm2 allows a sandboxed plugin to execute native code through `node:sqlite`
9.9
1 hour ago
vm2
>= 3.11.3, <= 3.11.6
NPM: vm2 crypto builtin loads attacker native code through setEngine
9.9
1 hour ago
vm2
>= 3.10.2, <= 3.11.6
NPM: vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector
9.8
1 hour ago
vm2
>= 3.11.3, <= 3.11.6
NPM: vm2 NodeVM can replace the host process TLS trust store
10
1 hour ago
vm2
<= 3.11.6
NPM: vm2: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted
4.2
1 hour ago
devalue
>= 5.1.0, <= 5.9.2
NPM: devalue: `stringify`/`uneval` serialize shared memory
7.5
1 hour ago
devalue
<= 5.9.2
NPM: devalue: Residual sparse-array CPU amplification in uneval
6.3
1 hour ago
devalue
<= 5.9.2
NPM: devalue: Repeated primitive strings cause quadratic expansion in uneval
8.2
1 hour ago
devalue
>= 1.0.0, <= 5.9.2
NPM: devalue: Sparse arrays emitted by uneval cause eager allocation when evaluated
2.3
1 hour ago
Load more