The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,600
Mitigations17,172
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
unleash-server< 8.0.3
NPM: Unleash: Missing await on permission check + cross-project IDOR in admin API
7.1
2 hours ago
unleash-server< 8.0.3
NPM: Unleash: A project member can reorder activation strategies belonging to any other project / environment (cross-project integrity write), bypassing project RBAC and the audit log
4.3
2 hours ago
unleash-server< 8.0.3
NPM: Unleash: Clone-feature lets a user copy a feature from a project they cannot read
5.3
2 hours ago
unleash-server< 8.0.3
NPM: Unleash: CR-approval email renders user-controlled raw HTML
2.1
2 hours ago
@novu/js<= 3.17.0
NPM: Novu: Stored XSS in In-App Inbox via notification redirect.url javascript: scheme
5.1
2 hours ago
mppx< 0.8.2
NPM: mppx: Gas Draining with access list
6.9
2 hours ago
mppx< 0.8.1
NPM: mppx: Gas Draining with padding
6.9
2 hours ago
@deepstream/server10.1.0
NPM: deepstream: PATCH_MULTI action bypasses Valve permission system allowing unauthorized record writes
8.8
2 hours ago
request-filtering-agent< 3.2.1
NPM: request-filtering-agent: Synchronous throw from createConnection() for literal private-IP hosts bypasses req.on('error'), crashing the Node.js process
7.5
2 hours ago
Advanced Contact form 7 DB<= 2.1.1
Missing Authorization to Authenticated (Contributor+) Information Disclosure vulnerability
6.5
5 hours ago
WP User Manager<= 2.9.19
Broken Access Control vulnerability
5.3
6 hours ago
9router<= 0.5.4
NPM: 9Router has a Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header
5.3
6 hours ago
9router<= 0.5.4
NPM: 9Router has an Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header
7.3
6 hours ago
TrustedLogin Connector<= 2.0.3
Sensitive Data Exposure vulnerability
5.3
6 hours ago
@aborruso/ckan-mcp-server<= 0.4.107
NPM: @aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509
5.7
7 hours ago
@sync-in/server<= 2.4.0
NPM: Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory)
5.3
7 hours ago
@sync-in/server<= 2.3.0
NPM: Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters`
6.5
8 hours ago
@sync-in/server<= 2.3.0
NPM: Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token`
8.1
8 hours ago
@sync-in/server<= 2.3.0
NPM: @sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register`
6.8
8 hours ago
@roomi-fields/notebooklm-mcp>= 1.6.0, < 2.0.3
NPM: @roomi-fields/notebooklm-mcp has a path traversal in vault.batch tool that allows arbitrary file write outside intended vault directory
7.1
8 hours ago