The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total49,799
Mitigations16,024
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
brace-expansion<= 5.0.7
NPM: brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
7.5
23 minutes ago
sm-crypto< 0.5.0
NPM: sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
9.1
25 minutes ago
@anephenix/hub< 0.2.16
NPM: @anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
7.5
29 minutes ago
@budibase/server<= 3.38.1
NPM: Budibase: SSRF via bare fetch() in uploadUrl during AI table generation
4.9
31 minutes ago
@budibase/server<= 3.38.1
NPM: Budibase: SSRF via DNS rebinding in the REST datasource integration
8.5
32 minutes ago
@budibase/server<= 3.38.1
NPM: Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete
7.1
33 minutes ago
@budibase/server<= 3.38.1
NPM: Budibase: Account Enumeration via Login Lockout Response Differential
5.3
33 minutes ago
@budibase/server<= 3.38.1
NPM: Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
7.7
33 minutes ago
@budibase/server<= 3.38.1
NPM: Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
7.6
50 minutes ago
@budibase/server<= 3.38.1
NPM: Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
8.3
50 minutes ago
@budibase/server<= 3.38.1
NPM: Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders
5.7
51 minutes ago
@budibase/server<= 3.38.1
NPM: Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
7.5
51 minutes ago
@budibase/server<= 3.38.1
NPM: Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
0
53 minutes ago
@budibase/server<= 3.38.1
NPM: Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
9
58 minutes ago
@budibase/server<= 3.38.1
NPM: Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
8.5
59 minutes ago
@budibase/server<= 3.38.1
NPM: Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs
7.7
59 minutes ago
@budibase/server<= 3.38.1
NPM: Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile
7
59 minutes ago
@budibase/server<= 3.38.1
NPM: Budibase: SQL Injection via `multipleStatements: true`
9.6
1 hour ago
@budibase/server<= 3.38.1
NPM: Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
0
1 hour ago
@budibase/server< 3.39.25
NPM: Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
4.9
1 hour ago