The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total53,137
Mitigations17,346
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
fastify< 5.12.5
NPM: fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses
5.9
4 hours ago
hono< 4.13.7
NPM: hono/jsx renders plain strings unescaped in boundary components, leading to XSS
4.7
4 hours ago
fastify< 5.12.2
NPM: fastify vulnerable to request body replacement via an async validation result collision
8.1
4 hours ago
fastify>= 4.0.0, < 5.12.2
NPM: fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers
7.5
4 hours ago
fastify< 5.12.2
NPM: fastify vulnerable to request validation bypass via skipped boolean false schemas
7.5
4 hours ago
fastify< 5.12.2
NPM: fastify vulnerable to header validation bypass via incomplete schema case normalization
7.5
4 hours ago
@astrojs/netlify>= 5.2.0, <= 8.2.3
NPM: Astro: Netlify Image CDN allowlist bypass enables SSRF
6.3
4 hours ago
@astrojs/node<= 11.1.2
NPM: Astro: Malformed port in the Host header can crash the Node adapter
8.2
5 hours ago
@angular/router<= 19.2.25
NPM: Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters
8.2
12 hours ago
serialize-javascript>= 7.1.1, < 7.1.2
NPM: Serialize JavaScript: Cross-site scripting (XSS) via unescaped </script> in serialized function bodies
2.3
12 hours ago
Popular Posts<= 7.4.2
Unauthenticated Information Disclosure in 'post_type' and 'context' Parameters vulnerability
5.3
12 hours ago
dompurify>= 3.4.13, <= 3.4.15
NPM: DOMPurify: IN_PLACE: node-removing afterSanitize hook leaves detached subtree event handlers armed, causing DOM XSS
2.3
12 hours ago
@grpc/grpc-js< 1.13.6
NPM: @grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized
7.4
12 hours ago
@grpc/grpc-js< 1.13.6
NPM: @grpc/grpc-js: The server transmits some error messages thrown by method handlers to the client in status messages
3.7
12 hours ago
axios>= 1.0.0, < 1.20.0
NPM: Axios: Header Injection via Inherited headers After Minimal Interceptor
6.9
12 hours ago
axios>= 1.12.0, < 1.20.0
NPM: Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders
6.9
12 hours ago
axios>= 1.15.2, < 1.20.0
NPM: Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection
7.6
13 hours ago
axios>= 1.15.0, < 1.20.0
NPM: Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass for internal IP ranges
6.9
13 hours ago
axios>= 1.17.0, < 1.20.0
NPM: Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF
7
13 hours ago
axios>= 1.7.0, < 1.20.0
NPM: Axios: Prototype pollution gadget in fetch adapter can alter outbound requests
6.9
13 hours ago