The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total51,584
Mitigations16,860
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
@xmldom/xmldom>= 0.7.0, <= 0.8.14
NPM: xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization
6.3
37 minutes ago
xmldom<= 0.6.0
NPM: xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization
6.3
37 minutes ago
fastify>= 5.8.3, < 5.12.1
NPM: fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count
6.1
41 minutes ago
fastify< 5.12.1
NPM: fastify vulnerable to schema validation bypass via root primitive coercion mismatch
5.4
42 minutes ago
apostrophe<= 4.32.0
NPM: ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS
7.1
42 minutes ago
@apostrophecms/import-export<= 3.6.1
NPM: ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal
6.5
59 minutes ago
orval< 8.22.0
NPM: Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
7.1
1 hour ago
orval< 8.21.0
NPM: Orval: Import-time RCE via query-parameter default -> zod module-level template literal
9.3
1 hour ago
orval< 8.21.0
NPM: Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client
9.3
1 hour ago
@aborruso/ckan-mcp-server< 0.4.112
NPM: CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)
5.3
1 hour ago
qs>= 6.14.2, <= 6.15.3
NPM: qs array-limit bypass via bracket-key comma parsing
3.7
1 hour ago
qs>= 2.2.5, < 6.16.0
NPM: qs: Denial of Service via Attacker Controlled isBuffer
5.3
1 hour ago
@tiptap/core>= 2.0.0-alpha.0, < 3.30.4
NPM: Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes
6.4
1 hour ago
pnpm< 10.34.5
NPM: pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraph
7.1
1 hour ago
pnpm< 10.34.5
NPM: pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install
7.5
1 hour ago
@humanfs/node< 0.16.8
NPM: humanfs: Recursive copy follows symlinked files and copies data from outside the source tree
5.7
1 hour ago
@faker-js/faker<= 10.4.0
NPM: Faker: helpers.fake exploitable into arbritary code execution
7.8
1 hour ago
Classified Listing<= 6.1.1
Broken Access Control vulnerability
5.4
4 hours ago
Rentsyst<= 2.1.2
Broken Access Control vulnerability
5.3
4 hours ago
Grand Tour<= 5.5.1
Cross Site Request Forgery (CSRF) vulnerability
5.4
4 hours ago