The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total51,643
Mitigations16,875
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
toml< 4.2.0
NPM: toml-node: Uncontrolled Recursion
7.5
1 hour ago
toml< 4.1.2
NPM: toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__proto__` Key-Path Desynchronization
8.2
1 hour ago
phoenix>= 1.2.0-rc.0, < 1.5.15
NPM: Phoenix: Presence keys colliding with `Object.prototype` members break existence checks
6.3
2 hours ago
stream-json<= 3.4.0
NPM: stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — small crafted JSON blocks the event loop for seconds→minutes (DoS)
6.2
2 hours ago
sanitize-html<= 2.17.5
NPM: ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close
6.1
2 hours ago
apostrophe<= 4.31.0
NPM: ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree
6.5
2 hours ago
@toon-format/toon< 2.3.1
NPM: TOON: Prototype pollution when decoding untrusted TOON input
8.3
2 hours ago
claude-code-templates<= 1.29.2
NPM: Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)
8.8
3 hours ago
orval< 8.21.0
NPM: Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)
9.3
3 hours ago
orval< 8.21.0
NPM: Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)
9.3
3 hours ago
orval< 8.21.0
NPM: Orval: Import-time RCE via schema default -> zod module-level template literal
9.3
3 hours ago
orval< 8.21.0
NPM: Orval: Import-time RCE via array-items default -> zod module-level template literal
9.3
4 hours ago
orval< 8.21.0
NPM: Orval: Import-time RCE via header-parameter default -> zod module-level template literal
9.3
4 hours ago
orval< 8.21.0
NPM: Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator
9.3
4 hours ago
orval< 8.21.0
NPM: Orval: Import-time RCE via enum-typed default -> zod module-level template literal
9.3
4 hours ago
orval< 8.21.0
NPM: Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli
9.3
4 hours ago
orval< 8.21.0
NPM: Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client
9.3
4 hours ago
liquidjs>= 10.26.0, < 10.27.1
NPM: LiquidJS has an infinite loop vulnerability in its `strip_html` filter
8.7
5 hours ago
@openclaw/feishu< 2026.6.9-beta.1
NPM: OpenClaw Feishu permission tools could ignore per-account disablement
8.1
5 hours ago
@openclaw/feishu< 2026.6.9-beta.1
NPM: OpenClaw Feishu tools could ignore per-account disablement
8.1
5 hours ago