The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total49,515
Mitigations15,981
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
fast-uri>= 2.3.1, <= 2.4.2
NPM: fast-uri vulnerable to host confusion via literal backslash authority delimiter
7.5
1 hour ago
sharp< 0.35.0
NPM: sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
7
1 hour ago
fast-xml-parser>= 5.9.3, < 5.10.1
NPM: fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
8.7
1 hour ago
@hono/node-server>= 2.0.0, <= 2.0.9
NPM: Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
5.3
1 hour ago
typeorm< 0.3.31
NPM: TypeORM: migration:generate template-literal code injection
5.7
1 hour ago
svgo>= 1.0.0, < 2.8.3
NPM: SVGO removeScripts plugin leaves some executable scripts intact
8.2
3 hours ago
dompurify<= 3.4.11
NPM: DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
2.1
3 hours ago
@vitest/browser< 3.2.7
NPM: @vitest/browser: Browser Mode provider commands bypass the file-access permission gate
9.4
3 hours ago
@sigstore/oci< 0.7.1
NPM: Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
9.6
3 hours ago
@opentelemetry/propagator-jaeger< 2.9.0
NPM: OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
7.5
4 hours ago
linkify-it<= 5.0.1
NPM: linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
7.5
4 hours ago
aws-cdk-lib< 2.260.0
NPM: aws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling
7.3
4 hours ago
fast-uri>= 2.3.1, < 2.4.2
NPM: fast-uri vulnerable to host confusion via failed IDN canonicalization
7.5
4 hours ago
immutable< 4.3.9
NPM: Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
8.7
4 hours ago
immutable< 4.3.9
NPM: Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
7.5
4 hours ago
hono>= 4.11.8, < 4.12.27
NPM: hono/jsx does not isolate context per request, leading to cross-request data disclosure
6.5
4 hours ago
hono>= 4.0.0, < 4.12.27
NPM: Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
6.1
4 hours ago
hono>= 4.3.3, < 4.12.27
NPM: Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
4.8
5 hours ago
@hono/node-server< 2.0.5
NPM: Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
5.9
5 hours ago
Easy Form Builder<= 4.0.11
Unauthenticated Privilege Escalation to Administrator vulnerability
9.8
16 hours ago