Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
49,479
Mitigations
Mitigation rules
15,973
No official patch
13,050
In triage
1,416
Published soon
5
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
axios
>= 0.31.1, < 0.33.0
NPM: Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
8.3
44 minutes ago
axios
>= 0.31.1, < 0.33.0
NPM: Axios form serializer maxDepth bypass via {} metatoken
6.9
46 minutes ago
axios
>= 0.8.0, < 0.33.0
NPM: Axios: Nested axios option objects can consume polluted prototype values
6.3
47 minutes ago
axios
>= 1.13.0, < 1.18.0
NPM: Axios: HTTP/2 streamed uploads bypass `maxBodyLength`
6.3
47 minutes ago
axios
>= 1.7.0, < 1.18.0
NPM: Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
6.3
57 minutes ago
axios
< 0.33.0
NPM: Axios: Prototype pollution gadgets can alter axios request construction
6.3
59 minutes ago
axios
>= 0.31.0, < 0.33.0
NPM: Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
6.9
1 hour ago
protobufjs
>= 8.2.0, <= 8.6.4
NPM: protobufjs: Text Format string map parsing can mutate returned map object prototype
4.8
1 hour ago
protobufjs
>= 7.5.0, <= 7.6.4
NPM: protobufjs: Denial of Service via infinite loop in .proto option parsing
5.3
1 hour ago
webpack-dev-server
<= 5.2.5
NPM: webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
5.3
1 hour ago
webpack-dev-server
<= 5.2.5
NPM: webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
4.7
1 hour ago
astro
>= 6.4.7, < 6.4.8
NPM: Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
8.2
1 hour ago
tar
<= 7.5.17
NPM: node-tar: Process crash via PAX numeric path type confusion
5.3
1 hour ago
tar
<= 7.5.18
NPM: node-tar: Decompression/parse DoS via unlimited input
7.5
1 hour ago
tar
<= 7.5.17
NPM: node-tar: Negative tar entry size causes infinite loop in archive replace
7.5
1 hour ago
tar
<= 7.5.16
NPM: node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
5.3
1 hour ago
engine.io
>= 4.1.0, < 6.6.7
NPM: Socket.IO: Engine.IO Polling Transport Connection Exhaustion
7.5
1 hour ago
shell-quote
<= 1.8.4
NPM: shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
7.5
1 hour ago
directus
< 12.0.0
NPM: Directus: Authorization-dependent response served from unsegmented cache key
8.6
1 hour ago
directus
< 12.0.0
NPM: Directus: SSRF Protection Bypass via 0.0.0.0 in File Import
7.7
1 hour ago
Load more