Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
53,718
Mitigations
Mitigation rules
17,699
No official patch
13,474
In triage
1,070
Published soon
143
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@simple-git/argv-parser
< 2.0.1
NPM: simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection
9.2
1 hour ago
simple-git
>= 3.15.0, < 4.0.1
NPM: simple-git unsafe-operation guard does not block trailer command configuration
9.2
1 hour ago
simple-git
<= 3.36.0
NPM: simple-git allows command execution through unblocked Git configuration includes
8.1
1 hour ago
simple-git
<= 3.36.0
NPM: simple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/--exe) -> command execution (residual of CVE-2026-28291)
8.1
1 hour ago
@socket.io/cluster-engine
< 0.1.1
NPM: Socket.IO: Prototype Pollution via Unsafe Client Session Lookup
7.5
1 hour ago
dompurify
<= 3.4.15
NPM: DOMPurify: IN_PLACE returns a force-removed rawtext root whose text carries attacker markup — pure HTML reparse executes
0
1 hour ago
smol-toml
<= 1.8.0
NPM: smol-toml: Quadratic-time parse() from parseKey rescanning to end of document on each key line
5.3
1 hour ago
katex
>= 0.11.0, < 0.18.2
NPM: KaTeX: Existing prototype pollution can bypass trust restrictions
2.1
1 hour ago
seroval
>= 0.12.0, <= 1.6.0
NPM: Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of GHSA-mv8w-475r-vwqw)
9.8
1 hour ago
seroval
<= 1.6.2
NPM: Seroval: Memory exhaustion via unchecked TypedArray length in JSON deserialization
7.5
1 hour ago
proxy-addr
>= 1.1.0, < 2.0.8
NPM: proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet
9.1
1 hour ago
@nx/docker
>= 21.4.0, < 22.7.8
NPM: @nx/docker: OS command injection in the @nx/docker release pipeline
7.3
1 hour ago
nx
>= 14.0.0, < 22.7.8
NPM: Nx: OS command injection via git revisions and remote refs
8.5
1 hour ago
nx
>= 14.6.0, < 22.7.9
NPM: Nx daemon and plugin worker sockets are accessible to other local users
8.5
1 hour ago
nx
>= 13.10.0, < 22.7.10
NPM: Nx: Path traversal in nx migrate package-migrations extraction
5.8
1 hour ago
compression
< 1.8.2
NPM: compression vulnerable to Denial of Service via memory leak on premature response close
7.5
1 hour ago
@openclaw/googlechat
< 2026.8.1
NPM: OpenClaw: Channel read actions could skip target allowlists
6.5
1 hour ago
@openclaw/matrix
< 2026.8.1
NPM: OpenClaw: Channel read actions could skip target allowlists
6.5
1 hour ago
@openclaw/feishu
< 2026.8.1
NPM: OpenClaw: Channel read actions could skip target allowlists
6.5
1 hour ago
@openclaw/msteams
< 2026.8.1
NPM: OpenClaw: Channel read actions could skip target allowlists
6.5
1 hour ago
Load more