The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total49,760
Mitigations16,024
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
tar<= 7.5.20
NPM: node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
5.3
9 minutes ago
postcss<= 8.5.17
NPM: PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
7.5
10 minutes ago
@prompty/core<= 0.1.4
NPM: Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
10
11 minutes ago
mongoose< 6.13.10
NPM: Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
6.5
12 minutes ago
velocityjs<= 2.1.6
NPM: Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
9.8
14 minutes ago
@backstage/plugin-auth-backend<= 0.29.1
NPM: @backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass
4.7
14 minutes ago
trix< 2.1.18
NPM: Trix: Stored XSS via HTMLParser attribute injection on paste
4.6
17 minutes ago
valibot<= 1.4.1
NPM: Valibot: record() issue paths can make flatten() throw for inherited Object property names
6.9
20 minutes ago
seroval<= 1.5.2
NPM: seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
9.8
21 minutes ago
@sveltejs/kit<= 2.69.0
NPM: SvelteKit: Prototype pollution in file input deletion path in remote-function forms
4.3
37 minutes ago
@sveltejs/kit<= 2.69.0
NPM: SvelteKit: Big remote form function payloads can cause Node process to crash
5.3
44 minutes ago
better-auth>= 1.1.3, < 1.6.22
NPM: Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
8.3
51 minutes ago
@better-auth/stripe>= 1.4.11, < 1.6.21
NPM: @better-auth/stripe: cross-organization billing tampering in organization subscription actions
7.1
52 minutes ago
@better-auth/scim>= 1.4.0-beta.27, <= 1.6.21
NPM: @better-auth/scim: account takeover and stale access via SCIM provider-id collision
9.9
54 minutes ago
react-router>= 7.0.0, < 7.18.0
NPM: React Router: Unauthenticated Denial of Service via Inefficient Route Matching
8.7
2 hours ago
liquidjs<= 10.27.0
NPM: LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
8.2
2 hours ago
builder-util-runtime< 9.7.0
NPM: electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`
8.2
2 hours ago
app-builder-lib< 26.15.0
NPM: electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`
7.8
2 hours ago
ARForms<= 7.2.1
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
9 hours ago
SUMO Reward Points<= 32.7.0
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
9 hours ago