The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,961
Mitigations17,315
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
undici>= 7.0.0, < 7.29.1
NPM: undici vulnerable to Denial of Service via WebSocketStream unclean close
5.9
22 minutes ago
joi>= 17.2.0, < 17.13.7
NPM: joi: Quadratic regular-expression backtracking in `Joi.string().isoDate()`
7.5
25 minutes ago
electron< 39.8.10
NPM: Electron: Local race condition in Squirrel.Mac update installation on macOS
6.7
26 minutes ago
electron< 41.10.4
NPM: Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab
8.2
27 minutes ago
electron< 41.10.6
NPM: Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions
8.2
28 minutes ago
electron< 41.10.6
NPM: Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled
7.4
29 minutes ago
electron< 41.10.6
NPM: Electron: <webview> can enable Node.js integration in Web Workers despite embedder restrictions
8.3
31 minutes ago
electron>= 42.3.3, < 42.10.0
NPM: Electron: Sandboxed preload code cache can be poisoned by a compromised renderer
7.8
31 minutes ago
markdown-it< 14.3.1
NPM: markdown-it linkify: true has two quadratic paths, so a few hundred KB of markdown blocks the event loop for tens of seconds
6.3
35 minutes ago
js-yaml>= 5.0.0, <= 5.4.0
NPM: js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
5.3
35 minutes ago
webpack-dev-middleware< 7.4.5
NPM: webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath
7.4
1 hour ago
pixfort Core< 4.3.3
Cross Site Scripting (XSS) vulnerability
5.4
5 hours ago
HT Contact Form 7<= 2.10.2
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
11 hours ago
ConvertPlus<= 3.6.3
Authenticated (Subscriber+) PHP Object Injection vulnerability
8.8
11 hours ago
nodemailer>= 5.0.0, < 10.0.2
NPM: Nodemailer: Process-global DNS cache reuses TLS `servername` across transports, enabling cross-tenant SMTP credential disclosure
5.9
20 hours ago
undici>= 6.25.0, < 6.28.1
NPM: undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression
5.9
20 hours ago
multer>= 2.2.0, < 2.4.0
NPM: multer vulnerable to Denial of Service via orphaned disk writes on aborted uploads
5.3
20 hours ago
morgan< 1.12.1
NPM: morgan vulnerable to Log Injection via unescaped double quote in quoted log fields
5.3
21 hours ago
@angular/platform-server<= 19.2.25
NPM: Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE
8.7
21 hours ago
fast-uri< 2.4.6
NPM: fast-uri vulnerable to authority injection via an unvalidated port in serialize
7.5
21 hours ago