The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total49,489
Mitigations15,976
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Easy Form Builder<= 4.0.11
Unauthenticated Privilege Escalation to Administrator vulnerability
9.8
30 minutes ago
astro>= 7.0.0, < 7.0.6
NPM: Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered
5.1
7 hours ago
@astrojs/netlify< 8.1.2
NPM: @astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
3.7
7 hours ago
body-parser< 1.20.6
NPM: body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
3.7
7 hours ago
@astrojs/node>= 8.1.0, < 11.0.2
NPM: @astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
2.1
7 hours ago
astro< 7.0.6
NPM: Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
5.1
7 hours ago
@astrojs/rss>= 1.0.0, < 4.0.19
NPM: @astrojs/rss: XML Injection via Unescaped RSS Feed Fields
4.3
7 hours ago
astro>= 3.10.0, < 7.0.4
NPM: Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
2.1
7 hours ago
axios>= 0.31.1, < 0.33.0
NPM: Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
8.3
8 hours ago
axios>= 0.31.1, < 0.33.0
NPM: Axios form serializer maxDepth bypass via {} metatoken
6.9
8 hours ago
axios>= 0.8.0, < 0.33.0
NPM: Axios: Nested axios option objects can consume polluted prototype values
6.3
8 hours ago
axios>= 1.13.0, < 1.18.0
NPM: Axios: HTTP/2 streamed uploads bypass `maxBodyLength`
6.3
8 hours ago
axios>= 1.7.0, < 1.18.0
NPM: Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
6.3
8 hours ago
axios< 0.33.0
NPM: Axios: Prototype pollution gadgets can alter axios request construction
6.3
8 hours ago
axios>= 0.31.0, < 0.33.0
NPM: Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
6.9
8 hours ago
protobufjs>= 8.2.0, <= 8.6.4
NPM: protobufjs: Text Format string map parsing can mutate returned map object prototype
4.8
9 hours ago
protobufjs>= 7.5.0, <= 7.6.4
NPM: protobufjs: Denial of Service via infinite loop in .proto option parsing
5.3
9 hours ago
webpack-dev-server<= 5.2.5
NPM: webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
5.3
9 hours ago
webpack-dev-server<= 5.2.5
NPM: webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
4.7
9 hours ago
astro>= 6.4.7, < 6.4.8
NPM: Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
8.2
9 hours ago