The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,256
Mitigations16,235
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
crypto-js< 4.0.0
NPM: crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
9
58 minutes ago
hono>= 3.8.0, < 4.12.34
NPM: Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure
4.8
1 hour ago
hono>= 4.7.0, < 4.12.34
NPM: Hono: Proxy Helper does not remove response headers listed in the `Connection` header
3.7
1 hour ago
hono>= 4.12.0, < 4.12.34
NPM: Hono: Algorithmic Complexity DoS in Language Middleware
5.3
1 hour ago
jsii-diff< 1.131.0
NPM: jsii-diff: Command Injection via npm: package argument
7.8
1 hour ago
@sveltejs/kit<= 2.70.1
NPM: SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
5.3
2 hours ago
nuxt>= 3.21.7, < 3.21.10
NPM: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
5.3
3 hours ago
dompurify<= 3.4.12
NPM: DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
5.1
4 hours ago
WordPress< 7.0.3
SSRF vulnerability
5.4
16 hours ago
WordPress< 7.0.3
CSS Injection vulnerability
5.9
16 hours ago
WordPress< 7.0.3
Sensitive Data Exposure vulnerability
5.3
16 hours ago
WordPress< 7.0.3
Sensitive Data Exposure vulnerability
5.3
17 hours ago
WordPress< 7.0.3
Stored XSS vulnerabiliity
6.5
17 hours ago
WordPress7.0-7.0.2
Unauthenticated Sensitive Data Exposure vulnerability
5.3
21 hours ago
WordPress< 7.0.3
Multiple Contributor+ Stored XSS vulnerabilities
6.5
21 hours ago
re2<= 1.26.0
NPM: node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript
5.1
22 hours ago
re2<= 1.25.0
NPM: node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length
6.2
22 hours ago
ngx-extended-pdf-viewer>= 27.0.0-rc.0, < 29.0.0-rc.3
NPM: ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633
8.6
22 hours ago
pdfjs-dist>= 5.6.83, < 6.2.108
NPM: PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF
8.6
22 hours ago
WordPress< 7.0.3
Subscriber+ Site Creation vulnerability
7.1
22 hours ago