Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
51,688
Mitigations
Mitigation rules
16,877
No official patch
13,323
In triage
1,105
Published soon
15
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
deepseek-tui
>= 0.8.6, < 0.8.41
NPM: CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
7.8
18 minutes ago
codewhale
>= 0.8.41, < 0.8.64
NPM: CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
7.8
18 minutes ago
deepseek-tui
>= 0.8.33, < 0.8.41
NPM: CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
7.8
19 minutes ago
codewhale
>= 0.8.41, < 0.8.64
NPM: CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
7.8
19 minutes ago
deepseek-tui
>= 0.3.27, < 0.8.41
NPM: CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
7.4
20 minutes ago
codewhale
>= 0.8.41, < 0.8.64
NPM: CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
7.4
20 minutes ago
deepseek-tui
>= 0.8.5, < 0.8.41
TOCTOU on DNS failure for DNS pinning
8.6
27 minutes ago
codewhale
>= 0.8.41, < 0.8.64
TOCTOU on DNS failure for DNS pinning
8.6
27 minutes ago
deepseek-tui
>= 0.8.32, < 0.8.41
NPM: CodeWhale: js_execution leaks parent environment to model context via missing env scrub
7.5
29 minutes ago
codewhale
>= 0.8.41, < 0.8.64
NPM: CodeWhale: js_execution leaks parent environment to model context via missing env scrub
7.5
29 minutes ago
deepseek-tui
>= 0.3.27, < 0.8.41
NPM: CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
9.3
29 minutes ago
codewhale
>= 0.8.41, < 0.8.64
NPM: CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
9.3
29 minutes ago
deepseek-tui
>= 0.3.10, < 0.8.41
NPM: CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
7
30 minutes ago
codewhale
>= 0.8.41, < 0.8.64
NPM: CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
7
30 minutes ago
deepseek-tui
>= 0.8.8, < 0.8.41
NPM: CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
7.5
31 minutes ago
codewhale
>= 0.8.41, < 0.8.64
NPM: CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
7.5
31 minutes ago
deepseek-tui
>= 0.8.32, < 0.8.41
NPM: CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
7.5
57 minutes ago
codewhale
>= 0.8.41, < 0.8.64
NPM: CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
7.5
57 minutes ago
@simplewebauthn/server
<= 13.3.1
NPM: SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor
2
58 minutes ago
Restaurant Menu by MotoPress
< 2.4.12
Unauthenticated Payment Bypass vulnerability
5.3
5 hours ago
Load more