Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
53,718
Mitigations
Mitigation rules
17,699
No official patch
13,474
In triage
1,070
Published soon
143
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@simple-git/argv-parser
< 2.0.1
NPM: simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection
9.2
3 hours ago
simple-git
>= 3.15.0, < 4.0.1
NPM: simple-git unsafe-operation guard does not block trailer command configuration
9.2
3 hours ago
simple-git
<= 3.36.0
NPM: simple-git allows command execution through unblocked Git configuration includes
8.1
3 hours ago
simple-git
<= 3.36.0
NPM: simple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/--exe) -> command execution (residual of CVE-2026-28291)
8.1
3 hours ago
@socket.io/cluster-engine
< 0.1.1
NPM: Socket.IO: Prototype Pollution via Unsafe Client Session Lookup
7.5
4 hours ago
dompurify
<= 3.4.15
NPM: DOMPurify: IN_PLACE returns a force-removed rawtext root whose text carries attacker markup — pure HTML reparse executes
0
4 hours ago
smol-toml
<= 1.8.0
NPM: smol-toml: Quadratic-time parse() from parseKey rescanning to end of document on each key line
5.3
4 hours ago
katex
>= 0.11.0, < 0.18.2
NPM: KaTeX: Existing prototype pollution can bypass trust restrictions
2.1
4 hours ago
seroval
>= 0.12.0, <= 1.6.0
NPM: Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of GHSA-mv8w-475r-vwqw)
9.8
4 hours ago
seroval
<= 1.6.2
NPM: Seroval: Memory exhaustion via unchecked TypedArray length in JSON deserialization
7.5
4 hours ago
proxy-addr
>= 1.1.0, < 2.0.8
NPM: proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet
9.1
4 hours ago
@nx/docker
>= 21.4.0, < 22.7.8
NPM: @nx/docker: OS command injection in the @nx/docker release pipeline
7.3
4 hours ago
nx
>= 14.0.0, < 22.7.8
NPM: Nx: OS command injection via git revisions and remote refs
8.5
4 hours ago
nx
>= 14.6.0, < 22.7.9
NPM: Nx daemon and plugin worker sockets are accessible to other local users
8.5
4 hours ago
nx
>= 13.10.0, < 22.7.10
NPM: Nx: Path traversal in nx migrate package-migrations extraction
5.8
4 hours ago
compression
< 1.8.2
NPM: compression vulnerable to Denial of Service via memory leak on premature response close
7.5
4 hours ago
@openclaw/googlechat
< 2026.8.1
NPM: OpenClaw: Channel read actions could skip target allowlists
6.5
4 hours ago
@openclaw/matrix
< 2026.8.1
NPM: OpenClaw: Channel read actions could skip target allowlists
6.5
4 hours ago
@openclaw/feishu
< 2026.8.1
NPM: OpenClaw: Channel read actions could skip target allowlists
6.5
4 hours ago
@openclaw/msteams
< 2026.8.1
NPM: OpenClaw: Channel read actions could skip target allowlists
6.5
4 hours ago
Load more