The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,169
Mitigations16,170
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Restrict Content<= 4.0.0
Unauthenticated Password Reset Link Poisoning to Account Takeover vulnerability
9.8
56 minutes ago
FluentSMTP<= 2.2.95
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
57 minutes ago
Popup by Supsystic<= 1.12.0
Unauthenticated Privilege Escalation to Administrator vulnerability
9.8
1 hour ago
nuxt>= 3.1.0, < 3.21.10
NPM: Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
7.5
9 hours ago
nuxt>= 3.4.0, < 3.21.10
NPM: Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
8.1
9 hours ago
@nuxt/devtools< 3.3.1
NPM: Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
9.6
9 hours ago
nuxt>= 3.1.0, < 3.21.10
NPM: Nuxt: Unauthorized Component Instantiation via Server Island Props
4.8
9 hours ago
nuxt>= 4.4.0, <= 4.5.0
NPM: Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
7.5
10 hours ago
nuxt>= 3.21.7, < 3.21.10
NPM: Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
8.2
10 hours ago
nuxt>= 3.1.0, < 3.21.10
NPM: Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
7.5
10 hours ago
electron< 39.8.8
NPM: Electron: Sandboxed iframes can launch external protocol handlers
5.4
13 hours ago
electron< 39.8.9
NPM: Electron: DevTools embedder handler executes arbitrary files via shell open
6.9
13 hours ago
electron< 39.8.9
NPM: Electron: contextBridge object copy honors prototype setters
5.4
13 hours ago
electron< 39.8.7
NPM: Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
5.7
13 hours ago
electron< 39.8.10
NPM: Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
7.2
13 hours ago
Responsive Slider by MetaSlider<= 3.111.0
Authenticated (Author+) Stored Cross-Site Scripting vulnerability
6.5
14 hours ago
electron< 39.8.8
NPM: Electron: window.open features string controls some window options considered privileged
5.3
14 hours ago
electron>= 40.0.0-alpha.1, < 40.10.6
NPM: Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
5.9
15 hours ago
electron< 39.8.8
NPM: Electron: HTTP redirect followed into local file loader
5.9
15 hours ago
electron< 39.8.10
NPM: Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
7.4
15 hours ago