The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total53,109
Mitigations17,346
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
axios>= 1.7.0, < 1.20.0
NPM: Axios: Prototype pollution gadget in fetch adapter can alter outbound requests
6.9
17 minutes ago
axios>= 0.27.2, < 0.34.0
NPM: Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototype.method to Override HTTP Method
6.9
17 minutes ago
axios>= 1.16.1, < 1.20.0
NPM: Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS)
8.2
27 minutes ago
axios>= 1.15.0, < 1.20.0
NPM: Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location
8.2
27 minutes ago
axios>= 0.28.0, < 0.34.0
NPM: Axios: Prototype Pollution Gadget in axios toFormData Options
8.3
27 minutes ago
axios>= 1.13.0, < 1.20.0
NPM: Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls
7
28 minutes ago
axios>= 1.13.0, < 1.20.0
NPM: Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization
8.2
29 minutes ago
next>= 16.2.0, < 16.3.6
NPM: Next.js: Remote Code Execution in next/og ImageResponse
9.5
42 minutes ago
@nestjs/microservices< 11.2.5
NPM: Nest: Unbounded memory growth in the NestJS TCP microservice transport
6.5
46 minutes ago
EWWW Image Optimizer8.6.0-8.7.7
WordPress EWWW Image Optimizer plugin 8.6.0 - 8.7.7 - Author+ PHP Object Injection vulnerability
6.6
47 minutes ago
WP User Frontend2.5.8-4.3.11
Unauthenticated Account Creation with Registration Disabled vulnerability
5.3
47 minutes ago
FluentCart< 1.6.5
Unauthenticated Guest Customer Account Takeover vulnerability
6.5
47 minutes ago
Solace Extra< 1.7.2
Unauthenticated Non-Published Post Content Disclosure vulnerability
7.5
48 minutes ago
@nestjs/platform-fastify< 11.2.4
NPM: @nestjs/platform-fastify: Path-scoped middleware bypass via absolute-form request targets
7.4
48 minutes ago
nodemailer>= 9.1.0, <= 10.0.4
NPM: Nodemailer addressparser: O(n^2) on comment-joined addresses enables a remote DoS (reachable via mailparser)
7.5
49 minutes ago
Newsletter<= 9.3.9
Unauthenticated Insufficiently Protected Credentials vulnerability
5.3
1 hour ago
Premium Addons for Elementor<= 4.11.105
Cross Site Scripting (XSS) vulnerability
6.5
4 hours ago
Qi Addons For Elementor<= 1.11
Cross Site Scripting (XSS) vulnerability
6.5
4 hours ago
Happy Addons for Elementor<= 3.23.1
Cross Site Scripting (XSS) vulnerability
6.5
4 hours ago
Flexible PDF Coupons<= 1.14.11
Insecure Direct Object References (IDOR) vulnerability
5.4
4 hours ago