The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total49,782
Mitigations16,024
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
@budibase/server<= 3.38.1
NPM: Budibase: SQL Injection via `multipleStatements: true`
9.6
10 minutes ago
@budibase/server<= 3.38.1
NPM: Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
0
10 minutes ago
@budibase/server< 3.39.25
NPM: Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
4.9
10 minutes ago
@budibase/server<= 3.38.1
NPM: Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
4.3
12 minutes ago
@budibase/server<= 3.38.1
NPM: Budibase: Privilege escalation via public role assignment API missing app-level authorization
8.8
12 minutes ago
react-server-dom-webpack>= 19.0.0, < 19.0.8
NPM: react-server-dom: Denial of Service in Server Functions
7.5
13 minutes ago
react-server-dom-turbopack>= 19.0.0, < 19.0.8
NPM: react-server-dom: Denial of Service in Server Functions
7.5
13 minutes ago
react-server-dom-parcel>= 19.1.0, < 19.1.9
NPM: react-server-dom: Denial of Service in Server Functions
7.5
13 minutes ago
@anthropic-ai/claude-code>= 2.1.38, < 2.1.163
NPM: Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
7.7
4 hours ago
js-yaml>= 5.0.0, <= 5.2.1
NPM: js-yaml: Exponential parsing time in flow collections leads to denial of service
7.5
4 hours ago
react-router>= 7.12.0, < 8.3.0
NPM: React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
7.1
4 hours ago
aws-cdk-lib< 2.253.0
NPM: AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
4 hours ago
@aws-cdk/aws-codebuild>= 1.75.0, <= 1.204.0
NPM: AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
4 hours ago
@fastify/static<= 10.1.1
NPM: @fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
5.3
4 hours ago
@fastify/static<= 10.1.0
NPM: @fastify/static vulnerable to route guard bypass via path traversal
7.5
4 hours ago
tar<= 7.5.20
NPM: node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
5.3
4 hours ago
postcss<= 8.5.17
NPM: PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
7.5
5 hours ago
@prompty/core<= 0.1.4
NPM: Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
10
5 hours ago
mongoose< 6.13.10
NPM: Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
6.5
5 hours ago
velocityjs<= 2.1.6
NPM: Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
9.8
5 hours ago