The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,976
Mitigations17,315
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
adm-zip<= 0.6.0
NPM: adm-zip: Duplicate ZIP entry names: getEntry() and extractAllTo() resolve to different content
5.9
12 minutes ago
adm-zip<= 0.6.0
NPM: adm-zip: getDataAsync() bypasses the maxOutputLength size guard enforced by the synchronous getData() path
5.3
12 minutes ago
adm-zip<= 0.6.0
NPM: adm-zip: Unhandled error event in async DEFLATE decompression crashes Node.js process (DoS)
7.5
13 minutes ago
adm-zip<= 0.6.0
NPM: adm-zip: Decompression-bomb protection (fix for CVE-2026-39244) can be bypassed by declaring uncompressed size as 0
7.5
4 hours ago
adm-zip<= 0.6.0
NPM: adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation
7.1
4 hours ago
nodemailer< 10.0.2
NPM: Nodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS
5.9
4 hours ago
undici>= 7.11.0, < 7.29.1
NPM: undici vulnerable to Denial of Service via orphaned RetryHandler response body
5.9
5 hours ago
undici< 6.28.1
NPM: undici vulnerable to downstream response splitting via retry interceptor
3.7
5 hours ago
undici>= 6.7.0, < 6.28.1
NPM: undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
7.5
5 hours ago
undici>= 7.15.0, < 7.29.1
NPM: undici vulnerable to Denial of Service via unbounded decompression of compressed responses
5.9
5 hours ago
undici>= 7.0.0, < 7.29.1
NPM: undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches
6.5
5 hours ago
undici>= 7.1.0, < 7.29.1
NPM: undici vulnerable to response truncation via oversized chunked responses in the dump interceptor
3.7
5 hours ago
undici>= 7.24.1, < 7.29.1
NPM: undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool
7.4
5 hours ago
undici>= 7.0.0, < 7.29.1
NPM: undici vulnerable to caching and replay of unsafe HTTP method responses
3.7
5 hours ago
undici>= 8.10.0, < 8.10.2
NPM: undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors
7.4
5 hours ago
undici>= 7.0.0, < 7.29.1
NPM: undici vulnerable to Denial of Service via WebSocketStream unclean close
5.9
5 hours ago
joi>= 17.2.0, < 17.13.7
NPM: joi: Quadratic regular-expression backtracking in `Joi.string().isoDate()`
7.5
5 hours ago
electron< 39.8.10
NPM: Electron: Local race condition in Squirrel.Mac update installation on macOS
6.7
5 hours ago
electron< 41.10.4
NPM: Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab
8.2
5 hours ago
electron< 41.10.6
NPM: Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions
8.2
5 hours ago